Computer system with update-based quarantine
    1.
    发明申请
    Computer system with update-based quarantine 审中-公开
    具有基于更新的隔离的计算机系统

    公开(公告)号:US20070198525A1

    公开(公告)日:2007-08-23

    申请号:US11353872

    申请日:2006-02-13

    CPC classification number: G06F21/57 G06F8/60 G06F21/572

    Abstract: A managed network with a quarantine enforcement policy based on the status of installed updates for software on each client seeking access to the managed network. To determine whether a client requesting access has up-to-date software, an access server may communicate directly with an update server to determine the update status of the client requesting access. Information from the update server allows the update server to determine which update the client requesting access is missing. The access server may also receive an indication of the severity of the updates missing from the client requesting access. The access server may use the severity information to apply a quarantine enforcement policy, thereby avoiding the need for either the client or access server to be programmed to identify specific software updates that must be installed for a client to comply with a quarantine enforcement policy. To reduce network congestion and delays seeking access to the network, the quarantine enforcement policy includes a deadline by which updates must be installed. Establishing a deadline allows a grace period during which clients may download new updates and avoids network congestion from multiple clients downloading updates simultaneously.

    Abstract translation: 具有隔离执行策略的受管网络,其基于每个客户端上寻求访问受管网络的软件的已安装更新的状态。 为了确定请求访问的客户端是否具有最新的软件,访问服务器可以直接与更新服务器通信,以确定请求访问的客户端的更新状态。 来自更新服务器的信息允许更新服务器确定客户端请求访问的哪个更新丢失。 访问服务器还可以从请求访问的客户端接收对缺少的更新的严重性的指示。 访问服务器可以使用严重性信息来应用隔离实施策略,从而避免客户端或访问服务器被编程为识别必须为客户端安装以符合隔离执行策略的特定软件更新。 为了减少网络拥塞和寻求访问网络的延迟,隔离实施策略包括必须安装更新的截止日期。 建立最后期限允许客户端下载新更新的宽限期,并避免多个客户端同时下载更新的网络拥塞。

    REGISTRATION AND NETWORK ACCESS CONTROL
    2.
    发明申请
    REGISTRATION AND NETWORK ACCESS CONTROL 有权
    注册和网络访问控制

    公开(公告)号:US20120167185A1

    公开(公告)日:2012-06-28

    申请号:US12978158

    申请日:2010-12-23

    Abstract: In embodiments of registration and network access control, an initially unconfigured network interface device can be registered and configured as an interface to a public network for a client device. In another embodiment, a network interface device can receive a network access request from a client device to access a secure network utilizing extensible authentication protocol (EAP), and the request is communicated to an authentication service to authenticate a user of the client device based on user credentials. In another embodiment, a network interface device can receive a network access request from a client device to access a Web site in a public network utilizing a universal access method (UAM), and the request is redirected to the authentication service to authenticate a user of the client device based on user credentials.

    Abstract translation: 在注册和网络访问控制的实施例中,可以将初始未配置的网络接口设备注册和配置为用于客户端设备的公共网络的接口。 在另一个实施例中,网络接口设备可以接收来自客户端设备的网络访问请求,以利用可扩展认证协议(EAP)来访问安全网络,并且该请求被传送到认证服务以基于客户端设备的用户认证 用户凭据。 在另一个实施例中,网络接口设备可以使用通用接入方法(UAM)从客户端设备接收访问公共网络中的网站的网络接入请求,并且将该请求重定向到认证服务以认证用户的 客户端设备基于用户凭据。

    Registration and network access control
    3.
    发明授权
    Registration and network access control 有权
    注册和网络访问控制

    公开(公告)号:US08713589B2

    公开(公告)日:2014-04-29

    申请号:US12978158

    申请日:2010-12-23

    Abstract: In embodiments of registration and network access control, an initially unconfigured network interface device can be registered and configured as an interface to a public network for a client device. In another embodiment, a network interface device can receive a network access request from a client device to access a secure network utilizing extensible authentication protocol (EAP), and the request is communicated to an authentication service to authenticate a user of the client device based on user credentials. In another embodiment, a network interface device can receive a network access request from a client device to access a Web site in a public network utilizing a universal access method (UAM), and the request is redirected to the authentication service to authenticate a user of the client device based on user credentials.

    Abstract translation: 在注册和网络访问控制的实施例中,可以将初始未配置的网络接口设备注册和配置为用于客户端设备的公共网络的接口。 在另一个实施例中,网络接口设备可以接收来自客户端设备的网络访问请求,以利用可扩展认证协议(EAP)来访问安全网络,并且将该请求传送给认证服务,以基于客户端设备的用户身份认证 用户凭据。 在另一个实施例中,网络接口设备可以使用通用接入方法(UAM)从客户端设备接收访问公共网络中的网站的网络接入请求,并且将该请求重定向到认证服务以认证用户的 客户端设备基于用户凭据。

Patent Agency Ranking