IP Library Granted Patent US 7,389,495
Granted Patent B2
US 7,389,495 · App. 10/452,664 · Granted Jun 17, 2008

Framework to facilitate Java testing in a security constrained environment

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,389,495
App. No.
10/452,664
Granted
Jun 17, 2008
Kind
B2
Abstract

A method for testing an implementation of a specification is provided. The method includes providing a security manager capable of being configured to test compliance of an implementation of a specification, and installing the security manager. The method further includes constructing a security policy corresponding to a desired security environment that a test requires. The method also includes executing the test with the security manager using the security policy.

Claims (28)

1. A method for compliance testing an implementation of a specification, comprising the operations of:

providing a class configured to vary a security environment of the implementation of the specification, the class including a security manager;

installing the class, wherein the installation of the class includes installing the security manager of the class;

configuring the class to vary the security environment corresponding to what a test requires, the configuring including constructing one or more security policies corresponding to the security environment that the test requires;

executing the test with the security manager of the class using the one or more security policies; and

restoring an original security environment after execution of the test,

wherein the configuration of the class varies with the used security policies associated with the security environment requirements of the test, in a single test run.

2. A method for testing an implementation of a specification as recited in claim 1 , wherein the test may be one of a positive test, a negative test, a negative test requiring certain permissions, and a test designed to run positively and negatively.

3. A method for testing an implementation of a specification as recited in claim 2 , wherein for the positive test, the security policy grants only required permissions to tests and grants default permissions to other code source, default permissions being permissions granted by an original security policy that has been replaced by the security policy.

4. A method for testing an implementation of a specification as recited in claim 3 , wherein for the negative test, the security policy denies required permissions to test code source and grants default permissions to other code sources.

5. A method for testing an implementation of a specification as recited in claim 2 , wherein the positive test includes,

if a class cannot be installed,

checking an existing security manager for required permissions,

executing a test under the existing security manager when the existing security manager has required permissions,

reporting a failure when the test throws a security exception, and

returning a result of the test.

6. A method for testing an implementation of a specification as recited in claim 2 , wherein the negative test includes,

installing a security policy that is capable of denying a particular permission to test code source and granting all other code sources.

7. A method for testing an implementation of a specification as recited in claim 2 , wherein the negative test includes,

when the class cannot be installed,

checking an existing security manager to determine whether required permissions are denied,

executing the negative test when the existing security manager denies any of the permissions.

8. A method for compliance testing an implementation of a specification comprising:

providing a test to a framework, the test configured to determine whether an implementation complies with a specification, wherein the framework includes a security manager, the security manager configured to use a particular security policy from a plurality of security policies for executing the test, the plurality of security policies constructed to vary the security environment to what the test requires; and

running the test positively and negatively by changing the security policy defining the security environment for the test without modifying the test,

wherein the security policy varies with the security requirements of the test in a single test run.

9. A method for testing an implementation of a specification as recited in claim 8 , wherein running the test negatively includes denying required permissions to the test.

10. A method for testing an implementation of a specification as recited in claim 8 , wherein running the test positively includes granting all required permissions to the test.

Assignments (3)
CORRECTIVE ASSIGNMENT TO CORRECT THE REPLACE ERRONEOUSLY FILED PATENT #7358718 WITH THE CORRECT PATENT #7358178 PREVIOUSLY RECORDED ON REEL 038669 FRAME 0001. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Jun 8, 2017
From: MICRON TECHNOLOGY, INC.
To: U.S. BANK NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 043079/0001 →
SECURITY INTEREST Recorded May 12, 2016
From: MICRON TECHNOLOGY, INC.
To: U.S. BANK NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 038669/0001 →
MERGER AND CHANGE OF NAME Recorded Dec 16, 2015
From: ORACLE USA, INC.; SUN MICROSYSTEMS, INC.; ORACLE AMERICA, INC.
To: ORACLE AMERICA, INC.
Reel/Frame 037303/0336 →