US20170264635A1

Application platform security enforcement in cross device and ownership structures

Claim Score by NHIP

Read claim 10, the broadest

Abstract

Methods and systems provide application platform security enforcement. A distributed system communicates between a plurality of remote devices and at least one secured server to facility providing a secured service. The distributed system may comprise a remote communication server and one or more security layer components where the plurality of remote devices connect through ones of the security layer components. Upon detection of a security breach by a first remote device, the distributed system determines potential devices at risk from the plurality of remote devices, analyzing risk factors for commonalities. A lock down and/or quarantine of the first remote device and the devices at risk is instructed. Risk factors may include whether the remote devices communicate via a same security layer component, are geographically proximate; and/or are associated at the user level, for example are, proximate users in a social network, graph. Reactivation is also provided.

US20170264635A1, drawing sheet 1
Sheet 1 of 9

Term

10.6 yearsto projected expiry

Projected expiry 12 May 2037, counted from filing; an application has no term until it is granted.

  1. Priority
  2. Filed
  3. Published
  4. Today
  5. Projected expiry

20 claims: 3 independent, 17 dependent

  1. 1
    A communication server, comprising:a storage device;andat least one processor coupled to the storage device, the storage device storing software instructions to configure the operation of the at least one processor, when executed to: communicate, via one or more communication networks, between at least one secured server and a plurality of remote devices, including a first remote device, to facilitate a secured service to the plurality of remote devices from the at least one secured server, wherein communications between the communication server and the first remote device are communicated through a first security layer component and communications between the communication server and others of the plurality of remote devices are communicated either through the first security layer component or at least one other security layer component;wherein the communications providing the secured service between the secured server and the plurality of remote devices comprise an in-band communication;andfollowing a locking down or quarantining of the first remote device in which in-band communications by the first remote device for the secure service are at least limited: communicate a reactivation message to the first remote device which comprises an out of band communication;andremove the locking down or quarantining of the first remote device in response to a reactivation by the first remote device to permit the first remote device to communicate for the secured service limited by the locking down or quarantining.
  2. 10
    Broadest claimClaim Score 42, average(NHIP)A computer-implemented method, comprising:communicate, by at least one processor of a communication server, between at least one secured server and a plurality of remote devices, including a first remote device, to facilitate a secured service to the plurality of remote devices from the secured server via one or more communication networks, wherein communications between the communication server and the first remote device are communicated through a first security layer component and communications between the communication server and, others of the plurality of remote devices are communicated either through the first security layer component or at least one other security layer component and wherein the communications providing the secured service between the secured server and the plurality of remote devices comprise an in-band communication;and following a locking down or quarantining of the first remote device in which in-band communications, by the first remote device for the secure service are at least limited: communicate a reactivation message to the first remote device via an out of band communication;andremove the locking down or quarantining of the first remote device in response to a reactivation by the first remote device to permit the first remote device to communicate for the secured service limited by the locking down or quarantining.
  3. 18
    A system for securely communicating a secured service to a plurality of remote communication devices, the system comprising:a plurality of remote communication servers and respective security layer components, each of the remote communication servers comprising: a storage device;andat least one processor coupled to the storage device, the storage device storing software instructions which when executed configures a respective one of the remote communication servers to: communicate, between at least one secured server and some of the plurality of remote devices to facilitate a secured service to the some of the plurality of remote devices via one or more communication networks, wherein communications between the respective one of the remote communication servers and the some of the plurality of remote devices are communicated through the respective security layer component;wherein communications facilitating the secured service comprise in hand communications;andfollowing a locking down or quarantining of the first remote device in which in-band communications by the first remote device for the secure service are at least limited: communicate an out-of-band reactivation message to the first remote device via a second communications band;andremove the locking down or quarantining of the first remote device in response to a reactivation by the first remote device to permit the first remote device to communicate for the secured service limited by the locking down or quarantining.