IP Library Granted Patent US 9,172,701
Granted Patent B2
US 9,172,701 · App. 13/728,224 · Granted Oct 27, 2015

Techniques for secure debugging and monitoring

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,172,701
App. No.
13/728,224
Granted
Oct 27, 2015
Kind
B2
Abstract

Techniques for secure debugging and monitoring are presented. An end user requests a secure token for logging information with a remote service. A secure monitoring and debugging token service provides the secure token. The remote service validates the secure token and configures itself for capturing information and reporting the captured information based on the secure token.

Claims (28)

1. A method implemented in a non-transitory machine-readable storage medium and processed by a device configured to perform the method, comprising:

receiving, by a Secure Monitoring and Debugging Token Service (SMDTS) executing on the device, selections for logging information with a remote service, the selections identifying what monitoring information that is to be produced by and retained by the remote service, and the selections made by a principal, the principal desiring interaction with the remote service and the selections for the logging information captured by the remote service during that interaction, wherein the remote service is external to a principal device operated by the principal;

evaluating, by the SMDTS, a policy to determine whether the selections are permissible;

generating, by the SMDTS, a secure token that defines a principal identity for the principal, roles for the principal, and a remote service identity for the remote service, and specific logging levels for the selections as permitted by the policy;

sending, by the SMDTS over a network connection, the secure token to the principal as a signed security assertion token;

receiving, by the SMDTS, the secure token over a secure or non-secure communication channel from the remote service;

validating, by the SMDTS, the secure token; and

returning, by the SMDTS, the specific logging levels permitted by the policy to the remote service based on the validated secure token.

2. The method of claim 1 further comprising, sending, by the SMDTS, the signed and encrypted secure token to the remote service.

3. The method of claim 1 , wherein receiving further includes receiving the selections directly from the principal.

4. The method of claim 1 , wherein receiving further includes receiving the selections from the remote service on behalf of the principal who is interacting with the remote service.

5. The method of claim 1 , wherein evaluating further includes using the principal identity and the remote service identity for the remote service to select the policy.

6. The method of claim 1 , wherein evaluating further includes using the policy to define in the secure token where the logged information defined by the selections is to be sent.

7. The method of claim 6 , wherein using further includes defining an auditing service as one recipient of the logged information and the principal as another recipient of the logged information.

8. A method implemented in a non-transitory machine-readable storage medium and processed by a server configured to perform the method, comprising:

receiving, by a remote network logging service executing on the server, a secure token that defines a logging level for monitoring data to configure for interactions with a principal and defines what information to capture for that logging level, and the secure token defining roles, and a principal identity for the principal, and the secure token produced by the principal making selections, wherein the secure token is an encrypted and signed security assertion token, the principal interacting with the remote network logging service from a principal device operated by the principal and the remote network logging service external to the principal device;

validating, by the remote network logging service, the secure token over a secure communication channel by sending the secure token to a remote service and receiving from the remote service the logging level with an indication that the secure token is validated;

configuring, by the remote network logging service, the logging level for capturing the monitoring data during the interactions with the principal on the server; and

capturing, by the remote network logging service logging information corresponding with the logging level during the interactions with the principal.

9. The method of claim 8 further comprising, sending the logging information to the principal device of the principal and to an auditing service.

10. The method of claim 8 , wherein receiving further includes acquiring the secure token from the principal.

11. The method of claim 8 , wherein receiving further includes interacting with a secure monitoring and debugging token service to acquire the secure token on behalf of the principal.

12. The method of claim 8 , wherein validating further includes interacting with a secure monitoring and debugging token service to perform the validation, wherein the secure monitoring and debugging token service is the remote service.

13. A system, comprising:

a device having memory configured with a secure monitoring and debugging token service (SMDTS) processing on the target device; and

a server having memory configured with a logging service processing on the server;

wherein the SMDTS is configured to generate a secure token based on a policy evaluation that defines a logging level for the logging service to use when interacting with a principal while the principal interacts with the logging service over a network connection from a principal device operated by the principal, the secure token produced by selections of the principal and identify what information to produce for the logging level and the information produced from the logging level produced by the logging service and retained by the logging service on the server, and the secure token defines a principal identity for the principal and roles, and wherein the SMDTS is configured to validate the secure token for the logging service, and the logging service is configured to capture logging data in accordance with the logging level and report the logging data to an auditing service, and wherein the SMDTS is configured to encrypt the secure token and provide the secure token to the principal as a security assertion token, and wherein the SMDTS is configured to: i) receive the secure token over a secure or non-secure communication channel from the logging service, ii) validate the secure token, and iii) return the logging level permitted by the policy to the logging service based on the validated secure token.

14. The system of claim 13 , wherein the SMDTS is configured to sign the secure token.

Assignments (12)
RELEASE OF SECURITY INTEREST REEL/FRAME 035656/0251 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: BORLAND SOFTWARE CORPORATION; ATTACHMATE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.)
Reel/Frame 062623/0009 →
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0718 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC); BORLAND SOFTWARE CORPORATION; MICRO FOCUS (US), INC.; SERENA SOFTWARE, INC; ATTACHMATE CORPORATION; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.); NETIQ CORPORATION
Reel/Frame 062746/0399 →
CORRECTIVE ASSIGNMENT TO CORRECT THE TO CORRECT TYPO IN APPLICATION NUMBER 10708121 WHICH SHOULD BE 10708021 PREVIOUSLY RECORDED ON REEL 042388 FRAME 0386. ASSIGNOR(S) HEREBY CONFIRMS THE NOTICE OF SUCCESSION OF AGENCY. Recorded Jul 26, 2018
From: BANK OF AMERICA, N.A., AS PRIOR AGENT
To: JPMORGAN CHASE BANK, N.A., AS SUCCESSOR AGENT
Reel/Frame 048793/0832 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ATTACHMATE CORPORATION; BORLAND SOFTWARE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE, INC.; ENTIT SOFTWARE LLC; ARCSIGHT, LLC; SERENA SOFTWARE, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0718 →
NOTICE OF SUCCESSION OF AGENCY Recorded May 2, 2017
From: BANK OF AMERICA, N.A., AS PRIOR AGENT
To: JPMORGAN CHASE BANK, N.A., AS SUCCESSOR AGENT
Reel/Frame 042388/0386 →
SECURITY INTEREST Recorded May 13, 2015
From: MICRO FOCUS (US), INC.; BORLAND SOFTWARE CORPORATION; ATTACHMATE CORPORATION; NETIQ CORPORATION; NOVELL, INC.
To: BANK OF AMERICA, N.A.
Reel/Frame 035656/0251 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 029939/0840 Recorded Nov 24, 2014
From: CREDIT SUISSE AG
To: NOVELL, INC.
Reel/Frame 034446/0312 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 029919/0575 Recorded Nov 24, 2014
From: CREDIT SUISSE AG
To: NOVELL, INC.
Reel/Frame 034446/0255 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 18, 2014
From: NOVELL, INC.
To: NETIQ CORPORATION
Reel/Frame 033553/0379 →
GRANT OF PATENT SECURITY INTEREST (SECOND LIEN) Recorded Mar 6, 2013
From: NOVELL, INC.
To: CREDIT SUISSE AG, AS COLLATERAL AGENT
Reel/Frame 029939/0840 →
GRANT OF PATENT SECURITY INTEREST (FIRST LIEN) Recorded Mar 4, 2013
From: NOVELL, INC.
To: CREDIT SUISSE AG, AS COLLATERAL AGENT
Reel/Frame 029919/0575 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 8, 2013
From: BURCH, LLOYD LEON; MCCLAIN, CAROLYN B.; STILMAR, ROBERT SKOUSEN; CHAKRAVARTY, DIPTO; MASOUD, BAHA; ANGELO, MICHAEL F.
To: NOVELL, INC.
Reel/Frame 029587/0216 →