IP Library Granted Patent US 6,871,284
Granted Patent B2
US 6,871,284 · App. 09/882,570 · Granted Mar 22, 2005

Credential/condition assertion verification optimization

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 6,871,284
App. No.
09/882,570
Granted
Mar 22, 2005
Kind
B2
Abstract

A method and apparatus ascertain which credential and which condition both from a network security policy best describe, respectively, information about initiator and target principals involved in an interaction, and tests performed on a state of an associated protocol event.

Claims (65)

1. A method for performing credential and condition assertion verification corresponding to a policy file, comprising:

during an initialization process, dynamically creating comparing functions for principals, said principals having credentials, said credentials from said policy file, and dynamically creating comparing functions for states of protocol events, said events having conditions, said conditions from said policy file;

during said initialization process, dynamically creating and loading a module, said module containing said comparing functions;

during runtime, ensuring an installed policy file corresponds to said module, and, if not, repeating said initialization process using said installed policy file, thereby dynamically generating an updated module containing updated comparing functions, said updated module and said updated comparing functions corresponding to said installed policy file; and

calling said comparing functions as appropriate.

2. The method of claim 1 , further comprising:

using in a high level language to generate said module.

3. A method for performing credential and condition assertion verification corresponding to a policy file, said policy file comprising credentials, conditions, and a hash value, said method comprising:

loading said policy file into an in-memory representation;

requesting loading an assertion verification dynamically loadable library, herein referred to as DLL, said DLL comprising a predetermined hash return function, principal/credential comparing functions, and protocol/condition comparing functions;

if said DLL exists:

loading said DLL into said memory; and

calling a predetermined function in said DLL for a return value, whereby said loading is complete if said returned value equals said hash value of said policy file;

if said DLL does not exist or if said loading said DLL is not complete:

invoking a code generation function for generating an updated assertion verification DLL from an assertion code file, said generated DLL corresponding to said policy file;

compiling and linking said assertion code file, thereby generating said updated assertion verification DLL corresponding to said policy file;

loading said updated assertion verification DLL into said memory; and

during runtime, calling said comparing functions in said DLL in memory as appropriate.

4. The method of claim 3 , further comprising said code generation function:

adding header information to said assertion code file;

adding a predetermined function that returns said hash value of said policy file;

interating through said credentials of said loaded policy file for generating said principal/credential comparing functions; and

interating through said conditions of said loaded policy file for generating said protocol/condition comparing functions.

5. The method of claim 4 , wherein said principal/credential comparing functions perform:

calling other credential comparison methods for any credentials used in definition of said each credential;

making calls to other comparison operations based on allowable operations of built-in types of a policy language corresponding to said policy file; and

combining results of above comparisons using logical operators.

6. The method of claim 4 , wherein said protocol/condition comparing functions perform:

calling other condition comparison methods for any conditions used in definition of said each condition;

making calls to other comparison operations based on allowable operations of built-in types of a policy language corresponding to said policy file; and

combining results of above comparisons using logical operators.

7. The method of claim 3 , during runtime, further comprising:

each time for deciding if a principal is described by a tested credential, computing a name of a comparison function of said principal/credential comparing functions, said comparison function name based on name of said tested credential;

calling said principal/credential comparison function, said principal/credential comparison function returning a value representing if said tested credential matches said principal;

each time for deciding if a protocol state satisfies a tested condition, computing a name of a comparison function of said protocol/condition comparing functions, said comparison function name based on name of said tested condition; and

calling said protocol/condition comparison function, said protocol/condition comparison function returning a value representing if said tested condition matches said protocol state.

8. An apparatus for performing credential and condition assertion verification corresponding to a policy file, said policy file comprising credentials, conditions, and a hash value, said apparatus comprising:

means for loading said policy file into an in-memory representation;

means for requesting loading an assertion verification dynamically loadable library, herein referred to as DLL, said DLL comprising a predetermined hash return function, principal/credential comparing functions, and protocol/condition comparing functions;

if said DLL exists:

means for loading said DLL into said memory; and

means for calling a predetermined function in said DLL for a return value, whereby said loading is complete if said returned value equals said hash value of said policy file;

if said DLL does not exist or if said loading said DLL is not complete:

means for invoking a code generation function for generating an updated assertion verification DLL from an assertion code file, said generated DLL corresponding to said policy file;

means for compiling and linking said assertion code file, thereby generating said updated assertion verification DLL corresponding to said policy file;

means for loading said updated assertion verification DLL into said memory; and

during runtime, means for calling said comparing functions in said DLL in memory as appropriate.

9. The apparatus of claim 8 , said code generation function further comprising:

means for adding header information to said assertion code file;

means for adding a predetermined function that returns said hash value of said policy file; and

means for interating through said credentials of said loaded policy file for generating said principal/credential comparing functions; and

means for interating through said conditions of said loaded policy file for generating said protocol/condition comparing functions.

10. The apparatus of claim 9 , said principal/credential comparing functions further comprising:

means for calling other credential comparison methods for any credentials used in definition of said each credential;

means for making calls to other comparison operations based on allowable operations of built-in types of a policy language corresponding to said policy file; and

means for combining results of above comparisons using logical operators.

11. The apparatus of claim 9 , said protocol/condition comparing functions further comprising:

means for calling other condition comparison methods for any conditions used in definition of said each condition;

means for making calls to other comparison operations based on allowable operations of built-in types of a policy language corresponding to said policy file; and

means for combining results of above comparisons using logical operators.

12. The apparatus of claim 8 , during runtime, further comprising:

each time for deciding if a principal is described by a tested credential, means for computing a name of a comparison function of said principal/credential comparing functions, said comparison function name based on name of said tested credential;

means for calling said principal/credential comparison function, said principal/credential comparison function returning a value representing if said tested credential matches said principal;

each time for deciding if a protocol state satisfies a tested condition, means for computing a name of a comparison function of said protocol/condition comparing functions, said comparison function name based on name of said tested condition; and

means for calling said protocol/condition comparison function, said protocol/condition comparison function returning a value representing if said tested condition matches said protocol state.

Assignments (13)
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
MERGER Recorded Jul 26, 2010
From: SECURIFY, INC.
To: SECURE COMPUTING CORPORATION
Reel/Frame 024733/0786 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 26, 2010
From: SECURE COMPUTING, LLC
To: MCAFEE, INC.
Reel/Frame 024733/0803 →
CHANGE OF NAME Recorded Jul 26, 2010
From: SECURE COMPUTING CORPORATION
To: SECURE COMPUTING, LLC
Reel/Frame 024733/0792 →
RELEASE OF SECURITY INTEREST Recorded Jun 7, 2002
From: PEQUOT VENTURE PARTNERS II, L.P., AS AGENT
To: SECURIFY, INC.
Reel/Frame 013225/0438 →
SECURITY AGREEMENT Recorded Jan 28, 2002
From: SECURIFY, INC.
To: PEQUOT VENTURE PARTNERS II, L.P.; PEQUOT PRIVATE EQUITY FUND II, L.P.; PVP II SECURITY CONV NOTE GRANTOR TRUST; PEQUOT OFFSHORE PRIVATE EQUITY PARTNERS III, L.P.
Reel/Frame 012553/0182 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 12, 2001
From: COOPER, GEOFFREY; SHERLOCK, KIERAN G.; SHAW, BOB; VALENTE, LUIS
To: SECURIFY, INC.
Reel/Frame 012183/0948 →