IP Library Granted Patent US 7,555,552
Granted Patent B2
US 7,555,552 · App. 11/672,497 · Granted Jun 30, 2009

Method and apparatus for policy management in a network device

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,555,552
App. No.
11/672,497
Granted
Jun 30, 2009
Kind
B2
Abstract

A method and apparatus for policy management in a network intermediary device. One embodiment of the invention, includes establishing a session between a client and an intermediary device on a network to enable processing of a communication between the client and the intermediary device. Then, the communication is processed by the intermediary device while maintaining a consistent version of policy throughout the communication. Finally, after the communication is complete, the intermediary terminates the communication. The intermediary device may maintain consistent policy by utilizing a policy ticket upon which transactional information is stored and that references the version of policy that was current when the communication first began. The policy ticket may be transported throughout the intermediary device according to a “checkpoint” scheme, and at each checkpoint, evaluating the policy rules, if necessary, to determine appropriate actions to be taken based on current client and network information as applied to the policy rules.

Claims (13)

1. A method for managing policies within a network intermediary device, comprising:

opening a network connection between a client and the network intermediary device when said connection is permitted by a policy comprising a first rule set relating to network connections;

processing a transaction over the network connection according to at least one additional policy, said additional policy comprising a second rule set for processing data received at the intermediary device for the transaction, said second rule set being different from the first rule set, the transaction comprising a request received from a client over the network connection;

utilizing a policy ticket describing actions and properties to be taken during a communication, said actions and properties corresponding to a version of policy rules current at a beginning of the communication and updated thereafter, as the policy ticket is transported between a plurality of checkpoints defining a flow of the communication and according to determinations, at any of the plurality of checkpoints, of actions to be taken during the communication;

upon completion of the transaction, closing the network connection when an evaluation determines that the connection should be closed, and not closing the connection when an evaluation determines that the connection should not be closed; and

in the event the connection is not closed, reusing, subject to the at least one additional policy, the connection for further transactions with the client.

2. The method of claim 1 , wherein the communication is any one of a connection or a transaction.

3. The method of claim 1 , wherein determinations of actions to be taken during the communications comprise evaluations of the policy rules according to information stored on the policy ticket or other pertinent information available to the network device.

4. The method of claim 1 , further comprising performing operations to the policy ticket in anticipation of evaluation at other checkpoints.

5. The method of claim 4 , wherein performing operations in anticipation of evaluation at other checkpoints includes executing the actions.

6. The method of claim 4 , wherein performing operations in anticipation of evaluation at other checkpoints includes storing on the policy ticket the actions to be subsequently executed by a transactor.

7. The method of claim 4 , wherein performing operations in anticipation of evaluation at other checkpoints includes maintaining evaluation states for the other checkpoints.

8. The method of claim 4 , wherein performing operations in anticipation of evaluation at other checkpoints includes marking the policy ticket for future checkpoints.

Assignments (11)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 21, 2019
From: SYMANTEC CORPORATION
To: CA, INC.
Reel/Frame 051144/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 27, 2016
From: BLUE COAT SYSTEMS, INC.
To: SYMANTEC CORPORATION
Reel/Frame 039851/0044 →
RELEASE OF SECURITY INTEREST Recorded Aug 1, 2016
From: JEFFERIES FINANCE LLC
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 039516/0929 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 30740/0181 Recorded May 29, 2015
From: JEFFERIES FINANCE LLC
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 035797/0280 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 27727/0144 Recorded May 29, 2015
From: JEFFERIES FINANCE LLC
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 035798/0006 →
SECURITY INTEREST Recorded May 22, 2015
From: BLUE COAT SYSTEMS, INC.
To: JEFFERIES FINANCE LLC, AS THE COLLATERAL AGENT
Reel/Frame 035751/0348 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 3, 2013
From: BLUE COAT SYSTEMS, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 030740/0181 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL RECORDED AT R/F 027727/0178 Recorded Oct 16, 2012
From: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 029140/0170 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Feb 16, 2012
From: BLUE COAT SYSTEMS, INC.
To: JEFFERIES FINANCE LLC
Reel/Frame 027727/0144 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Feb 16, 2012
From: BLUE COAT SYSTEMS, INC.
To: JEFFERIES FINANCE LLC
Reel/Frame 027727/0178 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 18, 2007
From: MAXTED, MARK; THURSTON, MATTHEW; PORTER, KEVIN; ZUERCHER, CHRIS; MOEN, DOUG
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 019177/0734 →