IP Library Granted Patent US 7,360,099
Granted Patent B2
US 7,360,099 · App. 10/251,545 · Granted Apr 15, 2008

Computing environment and apparatuses with integrity based fail over

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,360,099
App. No.
10/251,545
Granted
Apr 15, 2008
Kind
B2
Abstract

Computing units of a computing environment are equipped with means to determine their respective integrity. Further, each computing unit is equipped, such that if its integrity is determined to have been compromised, the computing unit automatically takes itself out of service. In one embodiment, prior to the automatically removing itself from service, a degree of compromise is determined. If the degree of compromise is determined to be within an acceptable risk level, the compromised computing unit fails itself over to one or more other computing units in the computing environment.

Claims (39)

1. In a computing environment having a plurality of computing units, a method of operation comprising:

determining whether integrity of a first of the computing units of the computing environment has been compromised;

determining a degree of compromise of the integrity of the first computing unit with respect to a level of risk, if the integrity of the first computing unit is determined to have been compromised; and

soft failing the first computing unit over to one or more of the other computing units, including transferring any active user sessions to the one or more of the other computing units, if the degree of compromise of the integrity of the first computing unit is determined to be below a predetermined threshold with respect to the level of risk.

2. The method of claim 1 , wherein said determining of whether integrity of a first of the computing units of the computing environment has been compromised is performed regularly on a periodic basis.

3. The method of claim 1 , wherein said determining of whether integrity of a first of the computing units of the computing environment has been compromised is performed continuously.

4. The method of claim 1 , wherein said determining of whether integrity of a first of the computing units of the computing environment has been compromised comprises verifying a privileged kernel of an operating system of the first computing unit has not been compromised.

5. The method of claim 1 , wherein said determining of whether integrity of a first of the computing units of the computing environment has been compromised further comprises verifying other privileged software of the first computing unit has not been compromised.

6. The method of claim 5 , wherein said determining of whether integrity of a first of the computing units of the computing environment has been compromised further comprises verifying shared non-privileged software of the first computing unit has not been compromised.

7. The method of claim 6 , wherein said determining of whether integrity of a first of the computing units of the computing environment has been compromised further comprises verifying non-shared and non-privileged software of the first computing unit has not been compromised.

8. The method of claim 1 , wherein said determining of whether integrity of a first of the computing units of the computing environment has been compromised comprises verifying certain designated system data of the first computing unit has not been compromised.

9. The method of claim 1 , wherein said determining of a degree of compromise comprises determining whether any software of the first computing unit with an integrity classification greater than a predetermined level has been compromised.

10. The method of claim 1 , wherein said failing of the first computing unit over to one or more of the other computing units comprises automatically relocating one or more user sessions being hosted on the first computing unit to one or more of the other computing units.

11. The method of claim 10 , wherein said failing over further comprises automatically taking the first computing unit out of service, upon relocating the one or more user sessions being hosted by the first computing unit to one or more of the other computing units.

12. The method of claim 1 , wherein the method further comprises automatically taking the first computing unit out of service.

13. A computing apparatus comprising:

storage medium having stored therein a plurality of programming instructions designed to

determine whether integrity of the computing apparatus has been compromised;

determine a degree of compromise with respect to the integrity of the computing apparatus with respect to a level of risk, if it is determined that the integrity of the computing apparatus has been compromised; and

automatically soft failing the computing apparatus over to one or more of companion computing apparatuses. including transferring any active user sessions to the one or more of companion computing appratuses, if the degree of compromise with respect to the integrity of the first computing unit is determined to be below a predetermined threshold with respect to the level of risk; and

a processor coupled to the storage medium to execute the programming instructions.

14. The computing apparatus of claim 13 , wherein said programming instructions are executed to perform said determining of whether integrity of the computing apparatus has been compromised regularly, on a periodic basis.

15. The computing apparatus of claim 13 , wherein said programming instructions are executed to perform said determining of whether integrity of a first of the computing units of the computing has been compromised continuously.

16. The computing apparatus of claim 14 , wherein said programming instructions are executed to perform said determining of whether integrity of the computing apparatus has been compromised by verifying a privileged kernel of an operating system of the computing apparatus has not been compromised.

17. The computing apparatus of claim 16 , wherein said programming instructions are further executed to perform said determining of whether integrity of the computing apparatus has been compromised by verifying other non-operating system kernel privileged software of the computing apparatus has not been compromised.

18. The computing apparatus of claim 17 , wherein said programming instructions are designed to further perform said determining of whether integrity of the computing apparatus has been compromised by verifying shared non-privileged software has not been compromised.

19. The computing apparatus of claim 18 , wherein said programming instructions are designed to further perform said determining of whether integrity of the computing apparatus has been compromised by verifying other non-shared and non-privileged software has not been compromised.

20. The computing apparatus of claim 13 , wherein said programming instructions are designed to perform said determining of whether integrity of the computing apparatus has been compromised by verifying certain designated system data of the computing apparatus has not been compromised.

21. The computing apparatus of claim 13 , wherein said programming instructions are designed to perform said determining of a degree of compromise by determining whether any software of the computing apparatus with an integrity classification greater than a predetermined level has been compromised.

22. The computing apparatus of claim 13 , wherein said programming instructions are designed to perform said failing of the computing apparatus over to one or more of companion computing apparatuses by automatically relocating one or more user sessions being hosted on the computing apparatus to the one or more companion computing apparatuses.

23. The computing apparatus of claim 22 , wherein said programming instructions are designed to perform said failing over by further automatically taking the computing apparatus out of service, upon relocating the one or more user sessions being hosted by the computing apparatus to the one or more companion computing apparatuses.

24. The computing apparatus of claim 13 , wherein the programming instructions are further designed to automatically take the computing apparatus out of service.

25. An apparatus comprising:

means for determining whether integrity of the apparatus has been compromised;

means for determining a degree of compromise with respect to the integrity of the apparatus with respect to a level of risk, if it is determined that the integrity of the apparatus has been compromised, and

means for soft failing the apparatus over to one or more companion apparatuses, including transferring any active user sessions to the one or more companion apparatuses, if the degree of compromise with respect to the integrity of the apparatus is determined to be below a predetermined threshold with respect to the level of risk.

26. A computing environment, comprising:

a first computing unit equipped to regularly determine whether its integrity has been compromised, and upon determining its integrity has been compromised, determine a degree of compromise with respect to a level of risk, and soft failing it self over to at least a second computing unit, including transferring any active user sessions to the at least a second computing unit, if the degree of compromise is determined to be below a predetermined threshold with respect to the level of risk; and

the second computing unit, with the second computing unit being also equipped to regularly determine whether its integrity has been compromised, and upon determining its integrity has been compromised with respect to a level of risk, determine a degree of compromise, and soft failing itself over to at least the first computing unit, including transferring any active user sessions to the at least the first computing unit, if the degree of compromise is determined to be below a predetermined threshold with respect to the level of risk.

Assignments (14)
TERMINATION AND RELEASE OF SECOND LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 60306/0365 Recorded Nov 24, 2025
From: JEFFERIES FINANCE LLC
To: TRIPWIRE, INC.
Reel/Frame 074023/0235 →
TERMINATION AND RELEASE OF FIRST LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 60306/0555 Recorded Nov 24, 2025
From: JEFFERIES FINANCE LLC
To: TRIPWIRE, INC.
Reel/Frame 074023/0320 →
TERMINATION AND RELEASE OF SECOND LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 60306/0649 Recorded Nov 21, 2025
From: ACQUIOM AGENCY SERVICES LLC
To: TRIPWIRE, INC.
Reel/Frame 073663/0698 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 14, 2025
From: GOLUB CAPITAL MARKETS LLC (AS EXISTING AGENT)
To: ACQUIOM AGENCY SERVICES LLC (AS SUCCESSOR COLLATERAL AGENT)
Reel/Frame 072471/0665 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jun 7, 2022
From: TRIPWIRE, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 060306/0365 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jun 7, 2022
From: TRIPWIRE, INC.
To: GOLUB CAPITAL MARKETS LLC, AS COLLATERAL AGENT
Reel/Frame 060306/0649 →
RELEASE OF SECURITY INTEREST Recorded Feb 2, 2015
From: ARES CAPITAL CORPORATION, AS COLLATERAL AGENT
To: TRIPWIRE, INC.; NCIRCLE NETWORK SECURITY INC.
Reel/Frame 034874/0150 →
SECURITY AGREEMENT Recorded Apr 2, 2013
From: TRIPWIRE, INC.; NCIRCLE NETWORK SECURITY, INC.
To: ARES CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 030132/0101 →
SECURITY AGREEMENT Recorded May 23, 2011
From: TRIPWIRE, INC.
To: ARES CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 026322/0580 →
RELEASE OF SECURITY INTEREST Recorded Mar 6, 2008
From: ORIX VENTURE FINANCE LLC
To: TRIPWIRE, INC.
Reel/Frame 020609/0129 →
RELEASE Recorded Mar 3, 2008
From: SILICON VALLEY BANK
To: TRIPWIRE, INC.
Reel/Frame 020599/0634 →
SECURITY AGREEMENT Recorded Jun 21, 2004
From: TRIPWIRE, INC.
To: SILICON VALLEY BANK
Reel/Frame 015473/0230 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 13, 2003
From: TRIPWIRE, INC.
To: ORIX VENTURE FINANCE LLC
Reel/Frame 013743/0870 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 19, 2002
From: DIFALCO, ROBERT A.; GOOD, THOMAS E.; HO KIM, GENE
To: TRIPWIRE, INC.
Reel/Frame 013321/0929 →