IP Library Granted Patent US 8,661,003
Granted Patent B2
US 8,661,003 · App. 13/438,753 · Granted Feb 25, 2014

Policy performance in an information management system

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,661,003
App. No.
13/438,753
Granted
Feb 25, 2014
Kind
B2
Abstract

In an information management system, policies are optimized before they are associated to a device in order to increase evaluation speed or reduce space requirements, or both. Optimization techniques may include common subexpression elimination, constant folding, constant propagation, comparison optimization, dead code or subexpression removal, map or lookup table generation, policy rewriting, redundant policy elimination, heuristic-based policy ordering, or policy-format transformation, and combinations of these.

Claims (41)

1. A method utilizing at least a computer processor for managing information comprising:

providing a plurality of rules and a plurality of abstractions, wherein

each of the plurality of abstractions represents at least one of a class of entities or a class of actions having a role in managing of the information and

each of the plurality of abstractions has a corresponding definition statement stored separately from the plurality of rules, and each of the plurality of rules comprises an expression having a variable;

determining a subset of the plurality of rules and abstractions relevant to a first target;

modifying the subset of rules and abstractions to create a modified subset of rules and abstractions, wherein the modifying comprises:

determining a first rule in the subset of rules and abstractions including first and second comparison operations, wherein

the first comparison operation is associated with a string and the second comparison operation is associated with an integer, and

the first comparison operation is evaluated before the second comparison operation; and

modifying the first rule in the subset of rules and abstractions to create a modified first rule, wherein

when evaluating the modified first rule, the second comparison is evaluated before the first comparison,

the subset of rules and abstractions is evaluated to generate a first set of results based on the first target and each result of the first set of results comprises an allow or deny decision, and

the modified subset of rules and abstractions is evaluated to generate a second set of results based on the first target wherein each result of the second set of results has a corresponding allow or deny decision from the first set of results;

associating the modified subset of rules and abstractions with the first target; and

for the first target, controlling access to the information based on the modified first rule of the modified subset of rules and abstractions, wherein the controlling comprises evaluating the second comparison operation but not the first comparison operation.

2. The method of claim 1 , wherein the modified subset of rules and abstractions generate a third set of results based on a second target wherein at least one result of the third set of results is different from a corresponding allow or deny decision from the first and second sets of results.

3. The method of claim 1 , wherein the modifying the subset of rules and abstractions to create the modified subset of rules and abstractions further comprises:

receiving information on at least one program executing at the first target; and

modifying a first rule from the plurality of rules in the subset of rules and abstractions based on the at least one program.

4. The method of claim 3 , wherein the at least one program executing at the first target is an e-mail server software.

5. The method of claim 1 , wherein the modifying the subset of rules and abstractions to create the modified subset of rules and abstractions further comprises:

receiving a list of users associated with the first target; and

modifying a first abstraction associated with a first rule from the plurality of rules in the subset of rules and abstractions based on the list of users.

6. The method of claim 5 , wherein the first abstraction is stored remotely from the first target.

7. The method of claim 6 , wherein the first rule of the subset of rules and abstractions is stored at the first target.

8. The method of claim 1 , wherein the first rule is selected from the modified subset of rules and abstraction based on the information.

9. The method of claim 5 , wherein the first abstraction corresponds to a listing of persons.

10. The method of claim 9 , wherein modifying the first abstraction does not modify the first rule.

11. The method of claim 9 , wherein modifying the first abstraction does not modify the modified first rule.

12. The method of claim 1 , wherein the controlling access to the information based on the modified subset of rules and abstractions further comprises:

transferring the modified subset of rules to the first target;

evaluating the first rule of the modified subset of rules stored at the first target; and

based on the first rule of the modified subset of rules, accessing a first abstraction from the modified subset of abstractions stored remotely from the first target.

13. The method of claim 1 , wherein the each result of the second set of results has the corresponding allow or deny decision from the first set of results when a particular result from the second set of results and a particular result from the first set of results share a first set of input from the first target.

14. The method of claim 1 , wherein the first comparison operation associated with the string comprises alpha numeric characters.

15. The method of claim 1 , wherein when evaluating the first rule of the subset of rules and abstractions, the first comparison operation is evaluated before the second comparison operation is replaced by when evaluating the first rule of the subset of rules and abstractions the first comparison operation is evaluated after the second comparison operation.

16. The method of claim 1 , wherein the first target is a personal computer.

17. The method of claim 1 , wherein the controlling access to the information comprises attaching a document to an e-mail.

18. The method of claim 1 , wherein the controlling access to the information comprises opening a document at the first target.

19. The method of claim 1 , wherein before evaluating the first rule of the subset of rules and abstractions, abstractions are not transferred to the first target.

20. The method of claim 1 , wherein the subset of rules and abstractions comprises at least two rules.

Assignments (1)
SECURITY AGREEMENT Recorded Jun 30, 2020
From: NEXTLABS, INC
To: ROSEBUD CAPITAL, LLC
Reel/Frame 053095/0330 →