IP Library Granted Patent US 8,640,189
Granted Patent B1
US 8,640,189 · App. 13/042,367 · Granted Jan 28, 2014

Communicating results of validation services

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,640,189
App. No.
13/042,367
Granted
Jan 28, 2014
Kind
B1
Abstract

In certain embodiments, a method includes receiving from a validation system a request to apply a first policy service to a message. The validation system determines whether the message may be transmitted to a second network by validating a plurality of tokens associated with the message. The method includes receiving at least one result from a policy service engine of applying the first policy service to the message and determining at least one predefined assertion based on the received at least one result. The message includes generating a first token by encrypting the at least one predefined assertion using a first parameter associated with the first service node and not the second service node. The method includes sending the message and the first token to the validation system.

Claims (64)

1. A method comprising:

receiving, at a first service node, from a validation system, a request to apply a first policy service to a message received from a first entity, the validation system residing on a first network, the validation system configured to determine whether the message may be transmitted to a second entity on a second network by validating a plurality of tokens associated with the message, the plurality of tokens being generated based on requests by the validation system and corresponding to the message received from the first entity, the plurality of tokens comprising tokens generated by the first service node applying the first policy service to the message and a second service node applying a second policy service to the message, none of the plurality of tokens being generated based on application of a policy service to the second entity;

receiving, at the first service node, at least one result from a policy service engine of applying the first policy service to the message;

determining, at the first service node, at least one predefined assertion based on the received at least one result;

generating a first token by encrypting the at least one predefined assertion using a first parameter associated with the first service node and not the second service node; and

sending the message and the first token to the validation system.

2. The method of claim 1 , wherein:

the first network comprises a first security level; and

the second network comprises a second security level that is different than the first security level.

3. The method of claim 1 , wherein the first service node resides on a third network different than the first network.

4. The method of claim 1 , wherein the first parameter is a private key associated with the first service node.

5. The method of claim 1 , further comprising:

determining, at the first service node, a set of instructions for the policy service engine in response to receiving the request to apply the first policy service to the message;

sending the set of instructions to the policy service engine; and

wherein the at least one result is received in response to sending the set of instructions to the policy service engine.

6. The method of claim 1 , further comprising sending, by the first service node, a file to the validation system with the message, the file generated by the policy service engine when applying the first policy service to the message.

7. The method of claim 1 , further comprising:

determining, at the first service node, a first hash based on the request;

determining, at the first service node, a second hash based on the at least one result; and

sending the first hash and the second hash with the message to the validation system.

8. The method of claim 1 , wherein the first service node receives the at least one result from the policy service engine asynchronously.

9. An apparatus comprising:

a network interface configured to receive from a validation system a request to apply a first policy service to a message received from a first entity, the validation system residing on a first network, the validation system configured to determine whether the message may be transmitted to a second entity on a second network by validating that the message comprises a plurality of tokens, the plurality of tokens being generated based on requests by the validation system and corresponding to the message received from the first entity, the plurality of tokens comprising tokens generated by the apparatus applying the first policy service to the message and a second service node applying a second policy service to the message, none of the plurality of tokens being generated based on application of a policy service to the second entity;

at least one processor configured to:

receive at least one result from a policy service engine of applying the first policy service to the message;

determine at least one predefined assertion based on the received at least one result;

generate a first token by encrypting the at least one predefined assertion using a first parameter associated with the first service node and not the second service node; and

send the message and the first token to the validation system.

10. The apparatus of claim 9 , wherein:

the first network comprises a first security level; and

the second network comprises a second security level that is different than the first security level.

11. The apparatus of claim 9 , wherein the apparatus resides on a third network different than the first network.

12. The apparatus of claim 9 , wherein the first parameter is a private key associated with the apparatus.

13. The apparatus of claim 9 , wherein the at least one processor is further configured to:

determine a set of instructions for the policy service engine in response to receiving the request to apply the first policy service to the message;

sending the set of instructions to the policy service engine; and

wherein the at least one result is received in response to sending the set of instructions to the policy service engine.

14. The apparatus of claim 9 , wherein the at least one processor is further configured to send a file with the message to the validation system, the file generated by the policy service engine when applying the first policy service to the message.

15. The apparatus of claim 9 , wherein the at least one processor is further configured to:

determine a first hash based on the request;

determine a second hash based on the at least one result; and

send the first hash and the second hash with the message to the validation system.

16. The apparatus of claim 9 , wherein the at least one result is received from the policy service engine asynchronously.

17. At least one non-transitory computer-readable medium comprising software that, when executed by at least one processor, is configured to:

receive, at a first service node, from a validation system, a request to apply a first policy service to a message received from a first entity, the validation system residing on a first network, the validation system configured to determine whether the message may be transmitted to a second entity on a second network by validating that the message comprises a plurality of tokens, the plurality of tokens being generated based on requests by the validation system and corresponding to the message received from the first entity, the plurality of tokens comprising tokens generated by the first service node applying the first policy service to the message and a second service node applying a second policy service to the message, none of the plurality of tokens being generated based on application of a policy service to the second entity;

receive, at the first service node, at least one result from a policy service engine of applying the first policy service to the message;

determine, at the first service node, at least one predefined assertion based on the received at least one result;

generate a first token by encrypting the at least one predefined assertion using a first parameter associated with the first service node and not the second service node; and

send the message and the first token to the validation system.

18. The at least one computer-readable medium of claim 17 , wherein:

the first network comprises a first security level; and

the second network comprises a second security level that is different than the first security level.

19. The at least one computer-readable medium of claim 17 , wherein the first service node resides on a third network different than the first network.

20. The at least one computer-readable medium of claim 17 , wherein the first parameter is a private key associated with the first service node.

21. The at least one computer-readable medium of claim 17 , wherein the software is further configured to:

determine a set of instructions for the policy service engine in response to receiving the request to apply the first policy service to the message;

send the set of instructions to the policy service engine; and

wherein the at least one result is received in response to sending the set of instructions to the policy service engine.

22. The at least one computer-readable medium of claim 17 , wherein the software is further configured to send a file with the message to the validation system, the file generated by the policy service engine when applying the first policy service to the message.

23. The at least one computer-readable medium of claim 17 , wherein the software is further configured to:

determine a first hash based on the request;

determine a second hash based on the at least one result; and

send the first hash and the second hash with the message to the validation system.

24. The at least one computer-readable medium of claim 17 , wherein the at least one result is received from the policy service engine asynchronously.

Assignments (12)
CHANGE OF NAME Recorded Mar 21, 2025
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: EVERFOX HOLDINGS LLC
Reel/Frame 070585/0625 →
PARTIAL PATENT RELEASE AND REASSIGNMENT AT REEL/FRAME 055052/0302 Recorded Oct 3, 2023
From: CREDIT SUISSE, AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: FORCEPOINT FEDERAL HOLDINGS LLC (F/K/A FORCEPOINT LLC)
Reel/Frame 065103/0147 →
SECURITY INTEREST Recorded Sep 29, 2023
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: APOLLO ADMINISTRATIVE AGENCY LLC, AS COLLATERAL AGENT
Reel/Frame 065086/0822 →
CHANGE OF NAME Recorded May 12, 2021
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 056216/0309 →
PATENT SECURITY AGREEMENT Recorded Jan 20, 2021
From: REDOWL ANALYTICS, INC.; FORCEPOINT LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 055052/0302 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: WEBSENSE, INC.; PORTAUTHORITY TECHNOLOGIES, LLC (FKA PORTAUTHORITY TECHNOLOGIES, INC.); RAYTHEON OAKLEY SYSTEMS, LLC; FORCEPOINT FEDERAL LLC (FKA RAYTHEON CYBER PRODUCTS, LLC, FKA RAYTHEON CYBER PRODUCTS, INC.)
Reel/Frame 055492/0146 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 1, 2017
From: FORCEPOINT FEDERAL LLC
To: FORCEPOINT LLC
Reel/Frame 043397/0460 →
CHANGE OF NAME Recorded Feb 16, 2016
From: RAYTHEON CYBER PRODUCTS, LLC
To: FORCEPOINT FEDERAL LLC
Reel/Frame 037821/0818 →
PATENT SECURITY AGREEMENT Recorded Jun 9, 2015
From: WEBSENSE, INC.; RAYTHEON OAKLEY SYSTEMS, LLC; RAYTHEON CYBER PRODUCTS, LLC (FORMERLY KNOWN AS RAYTHEON CYBER PRODUCTS, INC.); PORT AUTHORITY TECHNOLOGIES, INC.
To: RAYTHEON COMPANY
Reel/Frame 035859/0282 →
CHANGE OF NAME Recorded Jun 2, 2015
From: RAYTHEON CYBER PRODUCTS, INC.
To: RAYTHEON CYBER PRODUCTS, LLC
Reel/Frame 035806/0367 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 28, 2015
From: RAYTHEON COMPANY
To: RAYTHEON CYBER PRODUCTS, INC.
Reel/Frame 035774/0322 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 31, 2011
From: ERNST, RICHARD J.; SWEDBERG, JAMES H.; HICKS, MATTHEW J.; RIGGS, HERBERT T., III; POWERS, MATT A.; OSTERMANN, JASON E.
To: RAYTHEON COMPANY
Reel/Frame 026359/0650 →