IP Library Granted Patent US 7,308,702
Granted Patent B1
US 7,308,702 · App. 09/483,164 · Granted Dec 11, 2007

Locally adaptable central security management in a heterogeneous network environment

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,308,702
App. No.
09/483,164
Granted
Dec 11, 2007
Kind
B1
Abstract

A system and method for defining and enforcing a security policy. Security mechanism application specific information for each security mechanism is encapsulated as a key and exported to a semantic layer. Keys are combined to form key chains within the semantic layer. The key chains are in turn encapsulated as keys and passed to another semantic layer. A security policy is defined by forming key chains from keys and associating users with the key chains. The security policy is translated and exported to the security mechanisms. The security policy is then enforced via the security mechanisms.

Claims (92)

1. In a system having a computer and one or more security mechanisms, a computer-implemented method of defining and enforcing a security policy, the method comprising:

encapsulating security mechanism application specific information for each security mechanism, wherein encapsulating includes forming a key for each security mechanism using an application layer;

combining keys to form key chains;

encapsulating key chains as keys and passing the key chain keys to another semantic layer;

defining the security policy, wherein defining includes forming key chains from keys and associating users with key chains;

importing a key from the semantic layer to a local policy layer;

executing, within a computer, translation software, wherein the translation software translates the security policy and exports the translated security policy to the security mechanisms; and

enforcing the security policy via the security mechanisms.

2. The method of claim 1 wherein the security mechanisms are located on one or more distributed computer networks.

3. The method of claim 1 wherein the security mechanisms are heterogeneous.

4. The method of claim 1 , wherein defining the security policy further includes drilling down into a next lower semantic layer to form a new key chain.

5. The method of claim 1 wherein the security policy is defined using a graphical user interface.

6. An article comprising a computer readable medium having instructions thereon, wherein the instructions, when executed in a computer, create a system for executing the method of claim 1 .

7. A computer-based security system for a computer network, the computer-based security system comprising:

a computer;

a plurality of security mechanisms;

a plurality of semantic layers within a model implemented on the computer network, wherein the two or more of the semantic layers include keys combinable into key chains, the key chains are able to be encapsulated as key chain keys, and the key chain keys are exportable to another semantic layer, wherein the model also includes an application layer to encapsulate a security mechanism into a key and a local policy layer to associate a user to a key wherein each key encapsulates security mechanism application specific information for a security mechanism;

a user interface for defining a security policy as a function of keys received from a lower semantic layer; and

a translator, implemented on the computer, for translating the security policy to the security mechanisms.

8. The system according to claim 7 wherein the user interface is a graphical user interface.

9. The system according to claim 7 wherein the security policy is a role-based access control model.

10. The system of claim 7 wherein the semantic layers form a poset.

11. The system of claim 7 wherein the user interface includes means for drilling down into a lower semantic layer to form a new key chain.

12. A computer-based security system for a computer network, the computer-based security system comprising:

a computer;

a model implemented on the computer network, the model comprising semantic layers for defining different security policies and constraints for each type of user, wherein the model comprises a static application policy layer, two or more semantic policy layers, and a dynamic local policy layer;

a tool for manipulating the model, wherein the tool is configured to:

encapsulate security mechanism application specific information for each security mechanism, wherein encapsulating includes forming a key for each security mechanism;

combine keys to form key chains;

encapsulate key chains as key chain keys within two or more semantic layers;

pass the key chain keys to other semantic layers;

form user key chains from the key chain keys; and

associate users with the user key chains; and

a translator, implemented on the computer, for translating security policies from the model to security mechanisms in one or more computer resources.

13. The system of claim 12 wherein the model represents a set of access rights for a computer resource as a key and the model represents a set of keys as a key chain.

14. A computer-implemented method of defining a security policy, the method comprising:

defining an application policy layer and a plurality of semantic policy layers, including a first semantic policy layer and a second semantic layer;

encapsulating a set of access rights for a computer resource as a key;

combining keys to form one or more key chains within the application policy layer;

executing software within a computer to export key chains in the application policy layer as a key;

importing at least one key from the application policy layer into the first semantic policy layer;

combining one or more keys in the first semantic policy layer to form a key chain;

exporting key chains in the first semantic policy layer as keys;

importing at least one key into the second semantic policy layer;

combining one or more keys in the second semantic policy layer to form a key chain;

exporting key chains in the second semantic policy layer as keys;

importing at least one key from the second semantic policy layer to a local policy layer;

combining one or more keys in the local policy layer to form one or more local policy key chains; and

assigning users to local policy key chains in the local policy layer.

15. The method of claim 14 wherein combining one or more keys to form a key chain includes combining a key chain with the one or more keys to form another key chain.

16. The method of claim 14 wherein combining one or more keys in the first semantic layer includes combining a key chain with the one or more keys to form another key chain.

17. The method of claim 14 wherein combining one or more keys to form a key chain includes associating a constraint with the key chain, wherein the constraint must be satisfied before access to a computer resource governed by the key chain is granted.

18. The method of claim 14 wherein encapsulating includes grouping methods into handles and handles into keys.

19. The method of claim 18 wherein each key chain includes handles for different computer resources.

20. The method of claim 14 wherein combining one or more keys to form a key chain includes marking the key chain as abstract, wherein key chains marked as abstract are not exported to other layers.

21. The method of claim 14 further comprising combining one or more keys and key chains in the local policy layer to form a new key chain in the local policy layer.

22. An article comprising a computer readable medium having instructions thereon, wherein the instructions, when executed in a computer, create a system for executing the method of claim 14 .

23. A computer-implemented method of defining a security policy, the method comprising:

defining an application policy layer and a semantic policy layer;

encapsulating a set of access rights for a computer resource as a key;

combining keys to form one or more key chains within the application policy layer;

executing software within a computer to export key chains in the application policy layer as a key;

importing at least one key from the application policy layer into the semantic policy layer;

combining one or more keys in the semantic policy layer to form a key chain;

exporting key chains in the semantic policy layer as keys;

importing at least one key from the semantic policy layer to a local policy layer;

combining one or more keys in the local policy layer to form one or more local policy key chains; and

assigning users to local policy key chains in the local policy layer.

24. The method of claim 23 wherein combining one or more keys in the semantic policy layer to form a key chain includes combining a key chain with the one or more keys to form another key chain.

25. The method of claim 23 wherein combining one or more keys in the local policy layer to form a key chain includes combining a key chain with the one or more keys to form another key chain.

26. The method of claim 23 wherein combining one or more keys in the semantic policy layer to form a key chain includes associating a constraint with the key chain, wherein the constraint must be satisfied before access to a computer resource governed by the key chain is granted.

27. The method of claim 23 wherein combining one or more keys in the local policy layer to form a key chain includes associating a constraint with the key chain, wherein the constraint must be satisfied before access to a computer resource governed by the key chain is granted.

28. The method of claim 23 wherein encapsulating includes grouping methods into handles and handles into keys.

29. The method of claim 28 wherein each key chain includes handles for different computer resources.

30. The method of claim 23 wherein combining one or more keys to form a key chain includes marking the key chain as abstract, wherein key chains marked as abstract are not exported to other layers.

31. The method of claim 23 further comprising combining one or more keys and key chains in the local policy layer to form a new key chain in the local policy layer.

32. An article comprising a computer readable medium having instructions thereon, wherein the instructions, when executed in a computer, create a system for executing the method of claim 23 .

33. A computer-implemented method of modifying a security policy, the method comprising:

defining an application policy layer and a semantic policy layer;

encapsulating a set of access rights for a computer resource as a key;

combining keys to form one or more key chains within the application policy layer;

executing software within a computer to export key chains in the application policy layer as a key;

importing at least one key from the application policy layer into the semantic policy layer;

combining one or more keys in the semantic policy layer to form a key chain;

exporting key chains in the semantic policy layer as keys;

importing at least one key from the semantic policy layer to a local policy layer;

combining one or more keys in the local policy layer to form one or more local policy key chains;

assigning users to local policy key chains in the local policy layer;

constructing a role hierarchy by sorting the key chains into a partial ordering based on set containment;

displaying the partial ordering as a role hierarchy graph; and

adding and deleting keys from the role hierarchy graph.

34. An article comprising a computer readable medium having instructions thereon, wherein the instructions, when executed in a computer, create a system for executing the method of claim 33 .

Assignments (13)
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY NUMBERS PREVIOUSLY RECORDED AT REEL: 021523 FRAME: 0713. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF PATENT SECURITY AGREEMENT. Recorded Apr 11, 2022
From: CITICORP USA, INC.
To: SECURE COMPUTING CORPORATION
Reel/Frame 059690/0187 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 28, 2010
From: SECURE COMPUTING, LLC
To: MCAFEE, INC.
Reel/Frame 024456/0724 →
CHANGE OF NAME Recorded Mar 25, 2010
From: SECURE COMPUTING CORPORATION
To: SECURE COMPUTING, LLC
Reel/Frame 024128/0806 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 12, 2008
From: CITICORP USA, INC.
To: SECURE COMPUTING CORPORATION
Reel/Frame 021523/0713 →
SECURITY AGREEMENT Recorded Sep 14, 2006
From: SECURE COMPUTING CORPORATION; CIPHERTRUST, INC.
To: CITICORP USA, INC. AS ADMINISTRATIVE AGENT
Reel/Frame 018247/0359 →
CONFIRMATORY LICENSE Recorded Oct 4, 2001
From: SECURE COMPUTING CORPORATION
To: AIR FORCE, UNITED STATES
Reel/Frame 012258/0725 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 8, 2000
From: THOMSEN, DANIEL JAY; O'BRIEN, RICHARD; BOGLE, JESSICA; PAYNE, CHARLES
To: SECURE COMPUTING CORPORATION
Reel/Frame 010797/0991 →