US2015019730A1PendingUtilityA1

Method for Managing Computer Network Access

Assignee: HELIOS SOFTWARE LLCPriority: Jan 23, 2001Filed: Sep 30, 2014Published: Jan 15, 2015
Est. expiryJan 23, 2021(expired)· nominal 20-yr term from priority
H04L 67/14H04L 67/34H04L 43/06H04L 41/20H04L 47/803H04L 61/00H04L 65/40H04L 67/535
56
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A client computer initiates a first communication session at a first network address and receives therefrom a second network address. The client computer then initiates a second communication session at the second network address and receives therefrom an access configuration including a control setting for a communication protocol capable of being utilized during a third communication session. Concurrent with the second communication session, the client computer initiates a third communication session at a third network address whereupon the conveyance of data to or from an instantiated process on the client computer via the third communication session is controlled based on the control setting for the communication protocol.

Claims

exact text as granted — not AI-modified
1 . A method of controlling computer network access comprising:
 (a) receiving an access configuration at an endpoint of a computer network;   (b) determining at the endpoint whether access to a network address is permitted by the access configuration; and   (c) either allowing or denying the endpoint access to the network address based on the determination in step (b).   
     
     
         2 . The method of  claim 1 , wherein, in step (a), the endpoint receives the access configuration in response to a polling request by the endpoint. 
     
     
         3 . The method of  claim 1 , further including controlling the endpoint's allowed access to data conveyed via the computer network based upon control data, content data, or both control data and content data. 
     
     
         4 . The method of  claim 1 , wherein in step (c) allowing or denying the endpoint access is based on at least one of the following: a content of conveyed data or a communication protocol being used to convey data. 
     
     
         5 . A method of controlling computer network access comprising:
 (a) an endpoint computer of a computer network accessing a first network address on the computer network;   (b) the endpoint computer analyzing data received in real-time from the first network address based on an access configuration received at the endpoint computer from a second network address of the computer network;   (c) the endpoint computer either blocking or conveying the data received in real-time from the first network address based on the analysis in step (b); and   (d) in response to the analysis in step (b), the endpoint computer dispatching to the second network address data associated with the data received in real-time from the first network address.   
     
     
         6 . The method of  claim 5 , wherein the notification in step (d) includes at least one of the following: a protocol of the blocked data; the first network address; a subject of the blocked data; a date the blocked data was received; a time the blocked data was received; a control applied to the blocked data; an identifier of the endpoint computer; or a user name of a user of the endpoint computer. 
     
     
         7 . The method of  claim 6 , further including causing at least some of the data dispatched in step (d) to be displayed on a display not associated with the endpoint computer. 
     
     
         8 . A method of controlling computer network access comprising:
 (a) a server computer receiving via a computer network from an endpoint computer of the computer network a request for an access configuration file;   (b) the server computer dispatching to said endpoint computer an access configuration file; and   (c) following step (b), the server computer dispatching to said endpoint computer an update to the access configuration file dispatched in step (b) or another access configuration file.   
     
     
         9 . The method of  claim 8 , further including:
 (d) the server computer storing data received from said endpoint computer regarding a violation of at least one policy included in the access configuration file, the updated access configuration file, or the other access configuration file.   
     
     
         10 . A method of controlling computer network access comprising:
 (a) a server computer receiving via a computer network from endpoint computers of the computer network requests for access configuration files;   (b) the server computer dispatching a unique access configuration file to each endpoint computer for which a unique access configuration file was prepared; and   (c) the server computer dispatching a generic access configuration file to each endpoint computer for which a unique access configuration file was not prepared.   
     
     
         11 . The method of  claim 10 , further including:
 (d) the server computer controlling storage of data received from one or more endpoint computers regarding violations of policies included in the dispatched access configuration files.   
     
     
         12 . A computer network access control system comprising:
 client control manager software (CCM); and   server control manager software (SCM), wherein:   the CCM and SCM are operative for causing an access configuration to be received by a first computing device that hosts the CCM from a second computing device that hosts the SCM; and   the CCM is operative for controlling computer network access based on the received access configuration, and transmitting to the second computing device data related to said controlling of the computer network access.   
     
     
         13 . The computer network access control system of  claim 12 , wherein the CCM is further operative for:
 storing at the first computing device user data associated with a computer network transaction and dispatching said stored user data to the second computing device in real time, in batched intervals or in response to a request from the second computing device; and   at least one of the following:   setting a notice in the user data dispatched to the second computing device in response to a violation of the access configuration; or   detecting tampering or absence of the access configuration and performing at least one of the following: dispatching an indication of said tampering to the second computing device, allowing full access to the computer network, blocking all access to the computer network, or controlling access to the computer network based on the access configuration prior to tampering.   
     
     
         14 . The system of  claim 12 , wherein the second computing device is comprised of two or more computing devices which co-act to perform the function of a server. 
     
     
         15 . The system of  claim 12 , wherein the SCM includes an access manager operative for at least one of the following:
 defining, modifying, or viewing one or more access configuration settings to be applied at the first computing device;   viewing, sorting, or analyzing data regarding usage at the first computing device;   defining an allow or block list to control network transactions at the first computing device;   generating a report based on data regarding usage at the first computing device, wherein said report is generated ad hoc, or is generated according to a schedule, or is based on a location of the first computing device in the computer network;   managing messages to be displayed via popup or URL at the first computing device based upon at least one of the access configuration settings;   defining information or network addresses in an allow list that are not monitored or recorded for a protocol capable of accommodating transactions involving privileged information;   identifying at least one control code corresponding to at least one application of the access configuration settings and, issuing a notification, highlighting a network transaction on an activity log, or adapting at least one of the access configuration settings in response to said control code;   modifying at least one of the access configuration settings based upon usage patterns or the location of the first computing device in the computer network;   sending a message to the first computing device based upon usage pattern or the location of the first computing device in the computer network; or   decoding encoded user data for viewing and analysis.   
     
     
         16 . The system of  claim 12 , wherein the CCM is further operative for:
 controlling by monitoring the network access of the first computing device when the first computing device is not in communication with the second computing device;   causing the first computing device to store the data related to said controlling of the network access of the first computing device when the first computing device is not in communication with the second computing device; and   upon establishing communication with the second computing device, the first computing device transmitting the stored data related to said controlling of the network access of the first computing device.   
     
     
         17 . The system of  claim 12 , wherein the SCM is operative for:
 causing the second computing device to dispatch the access configuration to the first computing device in response to a request for the access configuration; and   causing the second computing device to receive the data related to said controlling of the network access of the first computing device.   
     
     
         18 . The system of  12 , wherein the access configuration includes at least one network access control setting that is at least one of the following:
 specific to an individual or group of user(s) or a subgroup of the user(s), a plurality of first computing devices, or location(s) of the plurality of first computing devices in the computer network;   operative for defining a level of monitoring including no, partial or full monitoring based upon content, protocol, address or day/time;   operative for restricting or allowing a network transaction based upon: entries in a block or allow list, a network protocol, content including category, rating or character pattern, time of day, day of week or allocation of time, location, behind the scenes data or content protection level, or allocation of bandwidth or data transfer amount;   operative for defining audit screenshot trigger, frequency, or duration;   operative for blocking predetermined protocol transactions to allow another protocol transaction to proceed with priority;   operative for specifying messages to be displayed via popup or URL or notification address to send alerts; or   operative for specifying server network addresses.   
     
     
         19 . The system of  claim 12 , wherein the SCM is operative for causing the second computing device to display at least part of the data related to the controlling of the network access of the first computing device transmitted to the second computing device. 
     
     
         20 . The system of  claim 19 , wherein the SCM is operative for causing the data to be displayed by user name. 
     
     
         21 . The system of  claim 12 , further including at least one of the following:
 the first computing device hosts the CCM;   the network access of the first computing device is controlled; and   the data transmitted to the second computing device is related to the controlling of the network access of the first computing device.   
     
     
         22 . The system of  claim 12 , wherein the access configuration is requested by the first computing device from the second computing device. 
     
     
         23 . A data network access control method comprising:
 (a) initiating on a first computing device a first communication session at a first network address;   (b) receiving at the first computing device via the first communication session an access configuration including a control setting for at least one communication protocol;   (c) initiating on the first computing device a second communication session at a second network address; and   (d) in connection with the second communication session, controlling conveyance of data to or from a process running on the first computing device based on the control setting for the at least one communication protocol.   
     
     
         24 . The method of  claim 23 , further including:
 (e) transferring at least part of the conveyed data to or from the first network address via the first communication session.   
     
     
         25 . A data network access control method comprising:
 (a) initiating on a first computing device a first communication session at a first network address;   (b) receiving at the first computing device via the first communication session an access configuration including a control setting for at least one communication protocol for use during a third communication session;   (c) initiating on the first computing device second and third communication sessions at second and third network addresses;   (d) in connection with the third communication session, controlling conveyance of data to or from a process running on the first computing device based on the control setting for the at least one communication protocol; and   (e) transferring at least part of the data conveyed in step (d) via the second communication session.   
     
     
         26 . A data network access control method comprising:
 (a) initiating on a first computing device first and second communication sessions at first and second network addresses;   (b) receiving at the first computing device via the second communication session an access configuration including a control setting for at least one communication protocol for use during a third communication session;   (c) initiating on the first computing device the third communication session at a third network address;   (d) in connection with the third communication session, controlling conveyance of data to or from a process running on the first computing device based on the control setting for the at least one communication protocol; and   (e) transferring at least part of the data conveyed in step (d) via the first communication session.   
     
     
         27 . A data network access control method comprising:
 (a) initiating on a first computing device a first communication session at a first network address;   (b) initiating on the first computing device a process that initiates a second communication session at a second network address concurrent with the first communication session at the first network address; and   (c) transferring at least part of any data conveyed to or from the first second communication session via the first communication session.   
     
     
         28 . The method of  claim 1 , wherein step (c) includes monitoring access and the conveyance of data between the endpoint and the network address. 
     
     
         29 . A data network access control method comprising:
 initiating on a first computing device a first communication session at a first network address;   receiving at the first computing device via the first communication session a control setting for a communication protocol;   initiating on the first computing device a second communication session at a second network address;   in connection with the second communication session, detecting conveyance of data to or from a process running on the first computing device; and   controlling the conveyance of the data to or from the process running on the first computing device based on the control setting for the communication protocol.   
     
     
         30 . The method of  claim 29 , wherein:
 the data is encrypted data; and   the method further includes:
 decrypting the encrypted data; and 
 controlling the conveyance of the data to or from the process running on the first computing device based on the decryption of the encrypted data. 
   
     
     
         31 . The method of  claim 30 , further including:
 re-encrypting the decrypted data; and   conveying the re-encrypted data to or from the second network address.   
     
     
         32 . The method of  claim 29 , wherein:
 the data is encoded data; and   the method further includes:
 decoding the encoded data; and 
 controlling the conveyance of the data to or from the process running on the first computing device based on the decoding of the encoded data. 
   
     
     
         33 . The method of  claim 30 , further including:
 re-encoding the decoded data; and   conveying the re-encoded data to or from the second network address.   
     
     
         34 . The method of  claim 29 , wherein the control setting is included in an access configuration that is received at the first computing device via the first communication session.

Join the waitlist — get patent alerts

Track US2015019730A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.