IP Library Granted Patent US 8,914,410
Granted Patent B2
US 8,914,410 · App. 13/053,196 · Granted Dec 16, 2014

Query interface to policy server

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,914,410
App. No.
13/053,196
Granted
Dec 16, 2014
Kind
B2
Abstract

A scalable access filter that is used together with others like it in a virtual private network to control access by users at clients in the network to information resources provided by servers in the network. Each access filter uses a local copy of an access control data base to determine whether an access request is made by a user. Each user belongs to one or more user groups and each information resource belongs to one or more information sets. Access is permitted or denied according to access policies which define access in terms of the user groups and information sets. The first access filter in the path performs the access check, encrypts and authenticates the request; the other access filters in the path do not repeat the access check. The interface used by applications to determine whether a user has access to an entity is now an SQL entity. The policy server assembles the information needed for the response to the query from various information sources, including source external to the policy server.

Claims (52)

1. A method for managing resource access, the method comprising:

storing information in memory regarding a plurality of resources, each resource associated with one or more requirements regarding access;

receiving a request sent over a communication network, the request concerning access by a user to a requested resource;

receiving an indication over the communication network that an identity of the user is valid; and

executing instructions stored in memory, wherein execution of the instructions by a processor:

identifies a path taken by the request through the communication network out of a plurality of possible paths, wherein each path is associated with a trust level,

identifies an identification technique used to identify the user requesting access out of a plurality of possible identification techniques, wherein each identification technique is associated with a trust level,

calculates an overall trust level of the request based on:

the trust level of the identification technique used to identify the user,

the trust level of the path taken by the access request through the network, and

a trust level of an encryption technique used to encrypt the request out of a plurality of possible encryption techniques,

recognizes that the encryption technique has a higher trust level than a trust level of a portion of the path,

increases the overall trust level to the trust level of the encryption technique, and

provides or refuses access to the requested resource based on whether the overall trust level of the request corresponds to requirements for accessing the resource.

2. The method of claim 1 , wherein the communication network is divided into a plurality of components, each component having an associated trust level, and wherein identifying the path includes identifying one or more components in the path.

3. The method of claim 1 , wherein the one or more requirements includes the identity of the user.

4. The method of claim 1 , wherein the one or more requirements includes membership of the user in a group, and wherein the group is associated with a set of identification techniques.

5. The method of claim 1 , further comprising initially determining that the unadjusted overall trust level of the request does not meet the requirements for accessing the resource, and, wherein the adjusted overall trust level meets the requirements for accessing the resource.

6. The method of claim 5 , further comprising selecting the encryption technique from a database concerning the plurality of possible encryption techniques, each associated with a trust level adjustment.

7. The method of claim 6 , wherein selection of the encryption technique is based on a minimum trust level adjustment necessary to meet the requirements for accessing the resource.

8. A system for managing resource access, the system comprising:

memory for storing information regarding a plurality of resources, each resource associated with one or more requirements regarding access;

a communications interface for receiving a request sent over a communication network, the request concerning access by a user to a requested resource and for receiving an indication over the communication network that an identity of the user is valid; and

a processor for executing instructions stored in memory, wherein execution of the instructions by the processor:

identifies a path taken by the request through the communication network out of a plurality of possible paths, wherein each path is associated with a trust level,

identifies an identification technique used to identify the user requesting access out of a plurality of possible identification techniques, wherein each identification technique is associated with a trust level,

calculates an overall trust level of the request based on:

the trust level of the identification technique used to identify the user,

the trust level of the path taken by the access request through the network, and

a trust level of an encryption technique used to encrypt the request out of a plurality of possible encryption techniques,

recognizes that the encryption technique has a higher trust level than a trust level of a portion of the path,

increases the overall trust level to the trust level of the encryption technique, and

provides or refuses access to the requested resource based on whether the overall trust level of the request corresponds to requirements for accessing the resource.

9. The system of claim 8 , wherein the communication network is divided into a plurality of components, each component having an associated trust level, and wherein identifying the path includes identifying one or more components in the path.

10. The system of claim 8 , wherein the one or more requirements includes the identity of the user.

11. The system of claim 8 , wherein the one or more requirements includes membership of the user in a group, and wherein the group is associated with a set of identification techniques.

12. The system of claim 8 , further comprising executing instructions by the processor to initially determine that the unadjusted overall trust level of the request does not meet the requirements for accessing the resource, wherein the adjusted overall trust level meets the requirements for accessing the resource.

13. The system of claim 12 , further comprising selecting the encryption technique from a database concerning the plurality of possible encryption techniques, each associated with a trust level adjustment.

14. The system of claim 13 , wherein selection of the encryption technique is based on a minimum trust level adjustment necessary to meet the requirements for accessing the resource.

15. A non-transitory computer-readable storage medium, having embodied thereon a program executable by a processor to perform a method for managing resource access, the method comprising:

storing information in memory regarding a plurality of resources, each resource associated with one or more requirements regarding access;

receiving a request sent over a communication network, the request concerning access by a user to a requested resource;

receiving an indication over the communication network that an identity of the user is valid;

identifying a path taken by the request through the communication network out of a plurality of possible paths, wherein each path is associated with a trust level;

identifying identification technique used to identify the user requesting access out of a plurality of possible identification techniques, wherein each identification technique is associated with a trust level;

calculating an overall trust level of the request based on:

the trust level of the identification technique used to identify the user,

the trust level of the path taken by the access request through the network, and

a trust level of an encryption technique used to encrypt the request out of a plurality of possible encryption techniques,

recognizing that the encryption technique has a higher trust level than a trust level of a portion of the path;

increasing the overall trust level to the trust level of the encryption technique; and

providing or refusing access to the requested resource based on whether the overall trust level of the request corresponds to requirements for accessing the resource.

Assignments (25)
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS RECORDED AT RF 046321/0393 Recorded Jun 16, 2025
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: SONICWALL US HOLDINGS INC.
Reel/Frame 071625/0887 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 046321/0414 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 046321/0393 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT R/F 040581/0850 Recorded May 22, 2018
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 046211/0735 →
CHANGE OF NAME Recorded May 16, 2018
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 046169/0718 →
CHANGE OF NAME Recorded May 15, 2018
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 046163/0137 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE PREVIOUSLY RECORDED AT REEL: 040587 FRAME: 0624. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Nov 28, 2017
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 044811/0598 →
CORRECTIVE ASSIGNMENT TO CORRECT THE THE NATURE OF CONVEYANCE PREVIOUSLY RECORDED AT REEL: 041073 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE INTELLECTUAL PROPERTY ASSIGNMENT.. Recorded Apr 5, 2017
From: QUEST SOFTWARE INC.
To: SONICWALL US HOLDINGS INC.
Reel/Frame 042168/0114 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 23, 2017
From: QUEST SOFTWARE INC.
To: SONICWALL US HOLDINGS, INC.
Reel/Frame 041073/0001 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 10, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040587/0624 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 9, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040581/0850 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040039/0642) Recorded Oct 31, 2016
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0016 →
RELEASE OF SECURITY INTEREST Recorded Oct 31, 2016
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0467 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040030/0187 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040039/0642 →
CONVERSION AND NAME CHANGE Recorded Jan 4, 2016
From: SONICWALL, INC.
To: SONICWALL L.L.C.
Reel/Frame 037426/0151 →
MERGER Recorded Jan 4, 2016
From: SONICWALL L.L.C.
To: DELL SOFTWARE INC.
Reel/Frame 037402/0974 →
MERGER Recorded Feb 10, 2015
From: SONICWALL, INC.
To: PSM MERGER SUB (DELAWARE), INC. C/O THOMA BRAVO, LLC
Reel/Frame 034928/0961 →
CHANGE OF NAME Recorded Feb 10, 2015
From: PSM MERGER SUB (DELAWARE), INC.
To: SONICWALL, INC.
Reel/Frame 034929/0130 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 6, 2011
From: REDCREEK COMMUNICATIONS, INC.; INTERNET DYNAMICS, INC.
To: REDLEAF GROUP, INC.
Reel/Frame 026394/0306 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 6, 2011
From: HANNEL, CLIFFORD LEE; MAY, ANTHONY
To: INTERNET DYNAMICS, INC.
Reel/Frame 026394/0269 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 6, 2011
From: KENDALL HOLDINGS LLC
To: SONICWALL, INC.
Reel/Frame 026395/0680 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 6, 2011
From: MARSHMAN RESEARCH LLC
To: KENDALL HOLDINGS LLC
Reel/Frame 026395/0624 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 6, 2011
From: REDLEAF GROUP, INC.
To: SONICWALL, INC.
Reel/Frame 026394/0589 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 6, 2011
From: REDLEAF GROUP, INC.
To: MARSHMAN RESEARCH LLC
Reel/Frame 026394/0567 →