IP Library Granted Patent US 7,912,856
Granted Patent B2
US 7,912,856 · App. 11/927,214 · Granted Mar 22, 2011

Adaptive encryption

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,912,856
App. No.
11/927,214
Granted
Mar 22, 2011
Kind
B2
Abstract

A scalable access filter is used in a virtual private network to control access by users at clients in the network to information resources provided by servers in the network. Access is permitted or denied according to access policies which define access in terms of the user groups and information sets. The access filter in the path performs the access check, encrypts and authenticates the request.

Claims (31)

1. An adaptive encryption apparatus, the apparatus comprising:

memory that stores a sensitivity level in association with a data resource, wherein the sensitivity level is further associated with an encryption technique; and

an access filter executable by a processor to:

determine a trust level of a user based on at least an identification technique used to identify the user and a network path used by the user to request the data resource,

authorize the user to access a requested data resource based on at least the determined trust level and the sensitivity level associated with the requested data resource stored in memory, and

encrypt a session for providing the requested data resource, the session being encrypted based on an encryption technique associated with the sensitivity level of the requested data resource.

2. The apparatus of claim 1 , further comprising encryption hardware that determines the physical security of the network path, and wherein the trust level of the user is further based on the physical security of the network path.

3. The apparatus of claim 1 , wherein the processor further executes instructions stored in memory to determine the trust level of the user further based on an access policy, the access policy based on group membership of the user and an information set including the requested data resource.

4. The apparatus of claim 1 , further comprising a database in memory, the database storing information concerning the identification technique in association with a minimum trust level.

5. The apparatus of claim 1 , further comprising a database in memory, the database storing information concerning an order of trust levels ranging from a minimum level to a maximum level as designated by an administrator.

6. A method for adaptive encryption in sessions providing data resources, the method comprising:

assigning a sensitivity level to a data resource in a database in memory, wherein the sensitivity level is further associated with an encryption technique; and

executing instructions stored in memory, wherein execution of the instructions by a processor:

determines a trust level of a user based at least on an identification technique used to identify the user and a network path used by the user to request the data resource, the determination of the trust level taking place at an access filter;

determines authorization of a user to access a requested data resource based on at least the determined trust level and the sensitivity level associated with the requested data resource, the determination of the authorization taking place at the access filter; and

encrypts a session for providing the requested data resource to the authorized user, the session being encrypted based on an encryption technique associated with the sensitivity level of the requested data resource, the encryption taking place at the access filter.

7. The method of claim 6 , wherein determining the trust level of the user is further based on physical security of the network path.

8. The method of claim 6 , wherein determining the trust level of the user is further based on an access policy, the access policy based on group membership of the user and an information set including the requested data resource.

9. The method of claim 6 , further comprising establishing an order of trust levels ranging from a minimum level to a maximum level.

10. The method of claim 9 , further comprising associating the sensitivity level of the requested data resource with a range of trust levels, and wherein determining authorization to access the requested data resource includes determining whether the trust level of the user is within the range of trust levels associated with the sensitivity level of the requested data resource.

11. The method of claim 6 , further comprising establishing an order of encryption levels ranging from a minimum level to a maximum level.

12. The method of claim 11 , further comprising associating the sensitivity level of the requested data resource with a range of encryption levels and wherein permitting the encrypted session for providing the requested data resource includes determining that the encryption technique is within the range of encryption levels associated with the sensitivity level of the requested data resource.

13. The method of claim 6 , further comprising establishing an order of sensitivity levels ranging from a minimum level to a maximum level.

14. The method of claim 12 , further comprising associating the trust level of the user with a range of sensitivity levels and wherein determining authorization to access the requested data resource includes determining whether the sensitivity level of the requested data resource is within the range of sensitivity levels associated with the trust level of the user.

15. A non-transitory computer-readable storage medium, having embodied thereon a program, the program being executable by a processor to perform a method for adaptive encryption in sessions providing data resources, the method comprising:

assigning a sensitivity level to a data resource in a database, wherein the sensitivity level is further associated with an encryption technique;

determining a trust level of a user based at least on an identification technique used to identify the user and a network path used by the user to request the data resource;

determining authorization of a user to access a requested data resource based on at least the determined trust level and the sensitivity level associated with the requested data resource; and

encrypting a session for providing the requested data resource to the authorized user, the session being encrypted based on an encryption technique associated with the sensitivity level of the requested data resource.

16. The non-transitory computer-readable storage medium of claim 15 , wherein the trust level is further based on physical security of the network path.

17. The non-transitory computer-readable storage medium of claim 15 , wherein the program is further executable to determine the trust level of the user further based on an access policy, the access policy based on group membership of the user and an information set including the requested data resource.

Assignments (29)
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS RECORDED AT RF 046321/0393 Recorded Jun 16, 2025
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: SONICWALL US HOLDINGS INC.
Reel/Frame 071625/0887 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 046321/0414 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 046321/0393 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT R/F 040581/0850 Recorded May 22, 2018
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 046211/0735 →
CHANGE OF NAME Recorded May 16, 2018
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 046169/0718 →
CHANGE OF NAME Recorded May 15, 2018
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 046163/0137 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE PREVIOUSLY RECORDED AT REEL: 040587 FRAME: 0624. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Nov 28, 2017
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 044811/0598 →
CORRECTIVE ASSIGNMENT TO CORRECT THE THE NATURE OF CONVEYANCE PREVIOUSLY RECORDED AT REEL: 041073 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE INTELLECTUAL PROPERTY ASSIGNMENT.. Recorded Apr 5, 2017
From: QUEST SOFTWARE INC.
To: SONICWALL US HOLDINGS INC.
Reel/Frame 042168/0114 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 23, 2017
From: QUEST SOFTWARE INC.
To: SONICWALL US HOLDINGS, INC.
Reel/Frame 041073/0001 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 10, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040587/0624 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 9, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040581/0850 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040039/0642) Recorded Oct 31, 2016
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0016 →
RELEASE OF SECURITY INTEREST Recorded Oct 31, 2016
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0467 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040039/0642 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040030/0187 →
MERGER Recorded Jan 4, 2016
From: SONICWALL L.L.C.
To: DELL SOFTWARE INC.
Reel/Frame 037401/0445 →
CONVERSION AND NAME CHANGE Recorded Jan 4, 2016
From: SONICWALL, INC.
To: SONICWALL L.L.C.
Reel/Frame 037425/0816 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORDED ON REEL/FRAME 024776/0337 Recorded May 8, 2012
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; SONICWALL, INC.
Reel/Frame 028177/0115 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORDED ON REEL/FRAME 024823/0280 Recorded May 8, 2012
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; SONICWALL, INC.
Reel/Frame 028177/0126 →
SECURITY AGREEMENT Recorded Aug 3, 2010
From: AVENTAIL LLC; SONICWALL, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 024776/0337 →
PATENT SECURITY AGREEMENT (SECOND LIEN) Recorded Aug 3, 2010
From: AVENTAIL LLC; SONICWALL, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 024823/0280 →
CHANGE OF NAME Recorded Jul 28, 2010
From: PSM MERGER SUB (DELAWARE), INC.
To: SONICWALL, INC.
Reel/Frame 024755/0091 →
MERGER Recorded Jul 28, 2010
From: SONICWALL, INC.
To: PSM MERGER SUB (DELAWARE), INC.
Reel/Frame 024755/0083 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 24, 2009
From: REDLEAF GROUP, INC.
To: SONICWALL, INC.
Reel/Frame 022152/0030 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 24, 2009
From: INTERNET DYNAMICS, INC.
To: REDLEAF GROUP, INC.
Reel/Frame 022152/0023 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 24, 2009
From: HANNEL, CLIFFORD LEE; MAY, ANTHONY
To: INTERNET DYNAMICS, INC.
Reel/Frame 022152/0019 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 24, 2009
From: MARSHMAN RESEARCH LLC
To: KENDALL HOLDINGS LLC
Reel/Frame 022152/0042 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 24, 2009
From: KENDALL HOLDINGS LLC
To: SONICWALL, INC.
Reel/Frame 022152/0049 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 24, 2009
From: REDLEAF GROUP, INC.
To: MARSHMAN RESEARCH LLC
Reel/Frame 022152/0040 →