IP Library Granted Patent US 7,240,015
Granted Patent B1
US 7,240,015 · App. 09/663,026 · Granted Jul 3, 2007

Policy representations and mechanisms for the control of software

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,240,015
App. No.
09/663,026
Granted
Jul 3, 2007
Kind
B1
Abstract

According to the present invention, an architecture of multiple agents is provided for setting up and enforcing policies within each site of a virtual network. A policy server represents the global policies of the site and each agent manages its own policies. Policies are dynamically downloaded from the policy server into agents that carry the responsibility to enforce them. Agents propagate their policies to the policy server to detect any conflict that may rise between agents during dynamic mapping and resource reservation. A negotiation mechanism is provided to resolve such conflicts. An authorization-based mechanism is also provided such that agents must request authorization before performing any action, in response to which a ticket is delivered to the requesting agent for accountability and security reasons.

Claims (45)

1. A multi-agent for managing system policies on a site operating in one of a plurality of system modes within a virtual network, wherein said system policies include authorization policies for controlling one of either permission or interdiction of actions by an agent, and obligation policies for specifying said actions said agent is responsible for performing, comprising:

a plurality of service and device agents, at least one of which functions as a requester agent defined by at least one obligation policy, and another of which functions as an executor agent for performing an action requested by said requester agent in order to fulfil said at least one obligation policy;

an authorization server operating in accordance with said authorization policies for receiving and authenticating requests from said requester agent and in response returning one of either (i) a permission authorization to said requester agent, which in response forwards said permission authorization to said executor agent for performing said action, or (ii) an interdiction to said requester agent for prohibiting said action;

a policy server for (i) receiving and downloading said obligation policies into said plurality of service and device agents, (ii) for distributing said authorization policies to said authorization server, and (iii) for managing said system policies in accordance with changes in said system modes; and

an event server for effecting shared communication between plurality of service and device agents.

2. The multi-agent system according to claim 1 , wherein said authorization policy is an objection characterized by the following attributes:

a Mode attribute which is one of either said permission authorization or said interdiction;

a Subject attribute which specifies which of said agents said authorization policy applies to;

an Action attribute which specifies a set of operations that said requester agent is authorized to or prohibited from performing, depending on said Mode;

a Target attribute which specifies said executor agent;

a Constraint attribute which prohibits return of said permission authorization unless predetermined conditions are verified;

a Priority attribute which specifies an authority level of said authorization policy relative to other ones of said policies;

a Class attribute which classifies policies according to a plurality of predetermined system activities to which said authorization policy relates;

a System mode attribute which represents a predetermined state of said system modes and;

a Creator attribute which specifies a creator of said authorization responsible for having added said authorization policy to the system.

3. The multi-agent system according to claim 1 , wherein said obligation policy is an object characterized by the following attributes:

a Trigger attribute which specifies one of either an internal or external event for triggering said obligation policy;

a Subject attribute which specifies which of said agents said obligation policy applies to;

an Action attribute which specifies a set of operations that said requester agent is authorized to or prohibited from performing, depending on said Mode;

a Target attribute which specifies said executor agent;

a Constraint attribute which prohibits return of said permission authorization unless predetermined conditions are verified;

a Class attribute which classifies policies according to a plurality of predetermined system activities to which said authorization policy relates;

a System mode attribute which represents a predetermined state of said system modes; and;

an Exception attribute which specifies an action that said Subject must perform in the event said Subject fails to accomplish said Action.

4. The multi-agent system according to either claim 2 or 3 , wherein said plurality of service and device agents further include:

a site logon agent for authenticating users and opening sessions for said users at said site;

a coordinator agent for managing inter-agent communications via said event server;

a site profile agent for mapping user preferences to said obligation policies; and

a resource agent for managing system resources provided by said plurality of service and device agents.

5. The multi-agent system according to claim 4 , wherein said Class attribute defines one of either (i) a class of securities policies which are applied to said coordinator agent, (ii) a class of admission control policies which are applied to said site logon agent, (iii) a class of user profile policies which are applied to said site profile agent, or (iv) a class of resource reservation policies which are applied to said resource agent.

6. The multi-agent system according either one of claim 2 or 3 , wherein said Class attribute defines a plurality of classes of policies which are enabled in response to respective ones of said system modes as defined by said System mode attribute.

7. The multi-agent system according to claim 1 , further comprising:

means within at least one of said requester agent and said executor agent for issuing notifications in response to events relating to at least one of an associated service or device; and

means within said policy server for (i) receiving subscriptions from predetermined ones of said service and device agents to predetermined ones of said events, (ii) receiving said notifications from said at least one of said requester agent and said executor agent, and in response (iii) distributing said notifications to said predetermined ones of said service and device agents.

8. The multi-agent system according to claim 7 , wherein said policy server further includes means for enabling and disabling predetermined ones of said system policies upon receiving said notifications from said at least one of said requester agent and said executor agent.

9. In a multi-agent system having a requester agent defined by at least one obligation policy, an executor defined by at least one authorization policy for performing an action requested by said requester agent in order to fulfil said at least one obligation policy, and an authorization server in communication with said requester agent and said executor agent, an action authorization method comprising the steps of:

sending a request from said requester agent to said authorization server for execution of said action;

receiving and authenticating said request within said authorization server and in response to generating and returning one of either (i) a permission authorization to said requester agent in the event that said obligation policy of said requester agent does not conflict with the authorization policy of said executor agent, or (ii) an interdiction to said requester agent for prohibiting said action in the event that said obligation policy of said requester agent conflicts with the authorization policy of said executor agent; and

modifying said request within said requester and sending a resultant modified request to said authorization server in the event that said authorization server previously returned said interdiction; or

sending said permission authorization to said executor agent for performing said action in the event said authorization server previously returned said permission authorization, and thereafter sending a confirmation from said executor agent to said requester agent confirming execution of said action.

10. The method of claim 9 , further comprising the steps of comparing said request to respective regions of belief of said obligation policy and said authorization policy and in the event that said request is within each of said regions of belief then returning said permission authorization and in the event that said request is outside of as least one of said respective regions of belief then returning said interdiction to said requester along with information indicating reasons for prohibition of said action.

11. The method of claim 10 , wherein said step of modifying said request within said requester further comprises interpreting said information and formulating said modified request to more likely be within each of said regions of belief.

12. The multi-agent system according to claim 1 , wherein said policy server and authorization server are stand-alone servers accessible to each of said agents within said site.

13. The multi-agent system according to claim 1 , wherein each of said agents incorporates its own authorization server and policy server.

14. The multi-agent system of claim 1 , wherein said site is a hotel.

Assignments (28)
RELEASE OF SECURITY INTEREST Recorded Jun 24, 2025
From: ANKURA TRUST COMPANY, LLC
To: MITEL (DELAWARE), INC.; MITEL COMMUNICATIONS, INC.; MITEL CLOUD SERVICES, INC.; MITEL NETWORKS, INC.; MITEL NETWORKS CORPORATION
Reel/Frame 071722/0721 →
SECURITY INTEREST Recorded Feb 14, 2023
From: RINGCENTRAL, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062973/0194 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 6, 2022
From: MITEL CLOUD SERVICES, INC.
To: RINGCENTRAL, INC.
Reel/Frame 058900/0649 →
RELEASE OF SECURITY INTEREST Recorded Jan 19, 2022
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: MITEL CLOUD SERVICES, INC.
Reel/Frame 058698/0162 →
RELEASE OF SECURITY INTEREST Recorded Jan 19, 2022
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: MITEL CLOUD SERVICES, INC.
Reel/Frame 058698/0085 →
SECURITY INTEREST Recorded Dec 13, 2018
From: MITEL CLOUD SERVICES, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 047772/0355 →
SECURITY INTEREST Recorded Dec 13, 2018
From: MITEL CLOUD SERVICES, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 047772/0330 →
CHANGE OF NAME Recorded Dec 6, 2018
From: MLN ACQUISITIONCO ULC
To: MITEL NETWORKS ULC
Reel/Frame 047694/0607 →
MERGER AND CHANGE OF NAME Recorded Dec 6, 2018
From: MITEL NETWORKS CORPORATION; MLN ACQUISITIONCO ULC
To: MLN ACQUISITIONCO ULC
Reel/Frame 047734/0714 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 6, 2018
From: MITEL NETWORKS ULC
To: MITEL CLOUD SERVICES, INC.
Reel/Frame 047694/0721 →
RELEASE OF SECURITY INTEREST Recorded Dec 3, 2018
From: CITIZENS BANK, N.A.
To: MITEL NETWORKS CORPORATION
Reel/Frame 048096/0785 →
SECURITY INTEREST Recorded Mar 23, 2017
From: MITEL NETWORKS CORPORATION
To: CITIZENS BANK, N.A.
Reel/Frame 042107/0378 →
SECURITY INTEREST Recorded May 28, 2015
From: MITEL NETWORKS CORPORATION
To: BANK OF AMERICA, N.A.(ACTING THROUGH ITS CANADA BRANCH), AS CANADIAN COLLATERAL AGENT
Reel/Frame 035783/0540 →
RELEASE OF SECURITY INTEREST Recorded May 1, 2015
From: JEFFERIES FINANCE LLC, AS THE COLLATERAL AGENT
To: MITEL US HOLDINGS, INC.; MITEL NETWORKS CORPORATION; MITEL COMMUNICATIONS INC. FKA AASTRA USA INC.
Reel/Frame 035562/0157 →
SECURITY AGREEMENT Recorded Feb 14, 2014
From: MITEL US HOLDINGS, INC.; MITEL NETWORKS CORPORATION; AASTRA USA INC.
To: JEFFERIES FINANCE LLC, AS THE COLLATERAL AGENT
Reel/Frame 032264/0760 →
RELEASE OF SECURITY INTEREST Recorded Feb 10, 2014
From: BANK OF AMERICA, N.A.
To: MITEL NETWORKS CORPORATION; MITEL US HOLDINGS, INC.
Reel/Frame 032210/0245 →
RELEASE OF SECURITY INTEREST Recorded Feb 6, 2014
From: WILMINGTON TRUST, NATIONAL ASSOCIATION
To: MITEL NETWORKS CORPORATION; MITEL US HOLDINGS, INC.
Reel/Frame 032167/0464 →
RELEASE OF SECURITY INTEREST Recorded Apr 15, 2013
From: BANK OF NEW YORK MELLON, THE; MORGAN STANLEY & CO. INCORPORATED; MORGAN STANLEY SENIOR FUNDING, INC.
To: MITEL NETWORKS CORPORATION
Reel/Frame 030264/0470 →
SECURITY INTEREST Recorded Apr 8, 2013
From: MITEL NETWORKS CORPORATION
To: WILMINGTON TRUST, N.A., AS SECOND COLLATERAL AGENT
Reel/Frame 030201/0743 →
SECURITY AGREEMENT Recorded Apr 8, 2013
From: MITEL NETWORKS CORPORATION
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 030186/0894 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Apr 2, 2013
From: WILMINGTON TRUST, NATIONAL ASSOCIATION FKA WILMINGTON TRUST FSB/MORGAN STANLEY & CO. INCORPORATED
To: MITEL NETWORKS CORPORATION
Reel/Frame 030165/0776 →
SECURITY AGREEMENT Recorded Sep 13, 2007
From: MITEL NETWORKS CORPORATION
To: MORGAN STANLEY & CO. INCORPORATED
Reel/Frame 019817/0881 →
SECURITY AGREEMENT Recorded Sep 13, 2007
From: MITEL NETWORKS CORPORATION
To: MORGAN STANLEY & CO. INCORPORATED
Reel/Frame 019817/0847 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 11, 2007
From: MITEL KNOWLEDGE CORPORATION
To: MITEL NETWORKS CORPORATION
Reel/Frame 019144/0368 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 11, 2007
From: MITEL CORPORATION
To: MITEL KNOWLEDGE CORPORATION
Reel/Frame 019144/0229 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 11, 2001
From: MITEL CORPORATION
To: MITEL KNOWLEDGE CORPORATION
Reel/Frame 011871/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 5, 2001
From: KARMOUCH, AHMED; GRAY, TOM; MANKOVSKII, SERGE; GUENNOUN, MOUHCINE
To: MITEL CORPORATION; OTTAWA, UNIVERSITY OF THE
Reel/Frame 011504/0647 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 15, 2000
From: KARMOUCH, AHMED; GRAY, TOM; MANKOVSKII, SERGE; GUENNOUN, MOUHCINE
To: MITEL CORPORATION
Reel/Frame 011225/0570 →