IP Library Granted Patent US 7,904,727
Granted Patent B2
US 7,904,727 · App. 12/363,945 · Granted Mar 8, 2011

Method to control access between network endpoints based on trust scores calculated from information system component analysis

Assignee: SignaCert, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,904,727
App. No.
12/363,945
Granted
Mar 8, 2011
Kind
B2
Abstract

Signatures are generated for modules in a computer system. The signatures can be assembled into an integrity log. The signatures are compared with signatures in a database in an integrity validator. Once signatures are either validated or invalidated, a trust score can be generated. The trust score can then be used to determine whether the computer system should be granted access to a resource using a policy.

Claims (37)

1. A system, comprising:

a network ( 110 , 135 );

a resource ( 145 ) connected to the network ( 110 , 135 );

a computer ( 105 ) connected to the network ( 110 , 135 ), including an integrity log generator ( 150 ) configured to generate an integrity log including a first plurality of signatures for a first plurality of modules, the integrity log including one signature in the first plurality of signatures for each module in the first plurality of modules; and

an apparatus ( 140 , 160 ) connected to the network ( 110 , 135 ), including:

a first database ( 205 ) configured to store a second plurality of signatures for a second plurality of modules;

a receiver ( 210 ) configured to receive from the computer ( 105 ) the integrity log;

a trust score generator ( 225 ) configured to generate a trust score based on a comparison of the integrity log with the second plurality of signatures; and

a policy ( 230 ) programmed into the apparatus to control access to the resource ( 145 ), the policy ( 230 ) including a threshold score ( 235 , 240 ) for a machine to receive full access to the resource ( 145 );

wherein access to the resource ( 145 ) by the computer ( 105 ) is controlled by the policy ( 230 ).

2. A system according to claim 1 , wherein:

the system includes a second apparatus ( 140 , 160 ), the second apparatus ( 140 , 160 ) including a second database ( 205 ) configured to store a third plurality of signatures for a third plurality of modules and a validator ( 220 ) configured to attempt to validate a subset of the first plurality of modules for which the corresponding signatures are not found in the first database ( 205 ); and

the apparatus ( 140 , 160 ) includes a transmitter ( 215 ) configured to transmit the signatures corresponding to the subset of the first plurality of modules for which the corresponding signatures are not found in the first database ( 205 ) to the second apparatus ( 140 , 160 ).

3. A system according to claim 2 , further comprising a second network ( 110 , 135 ), the apparatus ( 140 , 160 ) and the second apparatus ( 140 , 160 ) connected to the second network ( 110 , 135 ).

4. A system according to claim 1 , wherein the apparatus ( 140 , 160 ) further includes a transmitter ( 215 ) configured to transmit said trust score to the computer ( 105 ).

5. A system according to claim 4 , wherein the computer ( 105 ) further includes a receiver configured to receive said trust score from the apparatus ( 140 , 160 ) so that the computer can determine whether it can access the resource ( 145 ).

6. A system according to claim 1 , wherein said first plurality of modules includes modules that are accessed by the computer ( 105 ).

7. A system according to claim 1 , wherein said first plurality of modules includes all modules on the computer ( 105 ).

8. A system according to claim 1 , wherein said first plurality of modules includes at least one hardware module.

9. A system, comprising:

a network ( 110 , 135 );

a resource ( 145 ) connected to the network ( 110 , 135 );

a computer ( 105 ) connected to the network ( 110 , 135 ), including an integrity log generator ( 150 ) configured to generate an integrity log including a first plurality of signatures for a first plurality of modules, the integrity log including one signature in the first plurality of signatures for each module in the first plurality of modules, the computer including a policy ( 230 ) programmed into the computer to control access to the resource ( 145 ), the policy ( 230 ) including a threshold score ( 235 , 240 ) for a machine to receive full access to the resource ( 145 ); and

an apparatus ( 140 , 160 ) connected to the network ( 110 , 135 ), including:

a first database ( 205 ) configured to store a second plurality of signatures for a second plurality of modules;

a receiver ( 210 ) configured to receive from the computer ( 105 ) the integrity log; and

a trust score generator ( 225 ) configured to generate a trust score based on a comparison of the integrity log with the second plurality of signatures;

wherein access to the resource ( 145 ) by the computer ( 105 ) is controlled by the policy ( 230 ).

10. A system according to claim 9 , wherein:

the system includes a second apparatus ( 140 , 160 ), the second apparatus ( 140 , 160 ) including a second database ( 205 ) configured to store a third plurality of signatures for a third plurality of modules and a validator ( 220 ) configured to attempt to validate a subset of the first plurality of modules for which the corresponding signatures are not found in the first database ( 205 ); and

the apparatus ( 140 , 160 ) includes a transmitter ( 215 ) configured to transmit the signatures corresponding to the subset of the first plurality of modules for which the corresponding signatures are not found in the first database ( 205 ) to the second apparatus ( 140 , 160 ).

11. A system according to claim 10 , further comprising a second network ( 110 , 135 ), the apparatus ( 140 , 160 ) and the second apparatus ( 140 , 160 ) connected to the second network ( 110 , 135 ).

12. A system according to claim 9 , wherein the apparatus ( 140 , 160 ) further includes a transmitter ( 215 ) configured to transmit said trust score to the computer ( 105 ).

13. A system according to claim 12 , wherein the computer ( 105 ) further includes a receiver configured to receive said trust score from the apparatus ( 140 , 160 ) so that the computer can determine whether it can access the resource ( 145 ).

14. A system according to claim 9 , wherein said first plurality of modules includes modules that are accessed by the computer ( 105 ).

15. A system according to claim 9 , wherein said first plurality of modules includes all modules on the computer ( 105 ).

16. A system according to claim 9 , wherein said first plurality of modules includes at least one hardware module.

Assignments (9)
SECURITY INTEREST Recorded Jul 7, 2016
From: FORTRESS CREDIT CO LLC
To: FORTRESS CREDIT OPPORTUNITIES I LP
Reel/Frame 039104/0979 →
SECURITY INTEREST Recorded Jul 7, 2016
From: FORTRESS CREDIT CO LLC
To: FORTRESS CREDIT OPPORTUNITIES I LP
Reel/Frame 039104/0946 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 13, 2015
From: SIGNACERT, INC
To: KIP SIGN P1 LP
Reel/Frame 034700/0842 →
SECURITY INTEREST Recorded Jan 13, 2015
From: KIP SIGN P1 LP
To: FORTRESS CREDIT CO LLC
Reel/Frame 034701/0170 →
SECURITY INTEREST Recorded Jan 13, 2015
From: SIGNACERT, INC
To: FORTRESS CREDIT CO LLC
Reel/Frame 034700/0390 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 13, 2013
From: HARRIS CORPORATION
To: SIGNACERT, INC.
Reel/Frame 029804/0310 →
SECURITY AGREEMENT Recorded Dec 13, 2012
From: SIGNACERT, INC.
To: HARRIS CORPORATION
Reel/Frame 029467/0639 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 28, 2011
From: SIGNACERT, INC.
To: HARRIS CORPORATION
Reel/Frame 026195/0473 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 4, 2009
From: BLECKMAN, DAVID MAURITS; STARNES, WILLIAM WYATT; ANDERSEN, BRADLEY DOUGLAS
To: SIGNACERT, INC.
Reel/Frame 022210/0312 →
Continuity (6)
Continuation 11832781 · Aug 2, 2007
Continuation 11288820 · Nov 28, 2005
Provisional Application 60637066 · Dec 17, 2004
Provisional Application 60631449 · Nov 29, 2004
Provisional Application 60631450 · Nov 29, 2004
Related Publication 20090144813A1 · Jun 4, 2009