IP Library Granted Patent US 9,130,847
Granted Patent B2
US 9,130,847 · App. 14/263,699 · Granted Sep 8, 2015

Systems and methods for managing policies on a computer

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,130,847
App. No.
14/263,699
Filed
Apr 28, 2014
Granted
Sep 8, 2015
Kind
B2
Examiner
HO, ANDY
Art Unit
2194
USPC
719/319
Abstract

An apparatus, system, and method are disclosed for managing policies on a computer having a foreign operating system. Policies may specify hardware or software configuration information. Policies on a first computer with a native operating system are translated into configuration information usable on a second computer having a foreign operating system. In an embodiment, a translator manager manages the association between the policy on the first computer and the translator on the second computer. Computer management complexity and information technology management costs are reduced by centralizing computer management on the native operating system. Further reductions in management complexity are realized when the present invention is used in conjunction with network directory services.

Claims (57)

1. A UNIX client computer having a UNIX operating system and configured to extend use of WINDOWS native policies so that an administrator can use WINDOWS native policies to manage and update configuration information on the UNIX client computer, the UNIX client computer comprising:

a UNIX operating system;

computer hardware including at least one computer processor configured to execute computer-executable instructions; and

computer-executable instructions stored in computer storage and configured, when executed by the processor, to cause the computer hardware to perform operations comprising:

a receive policy operation that causes the UNIX client computer to receive a WINDOWS native policy from a centralized policy management server, wherein:

the UNIX client computer and the centralized policy management server are part of a heterogeneous computer network comprising computers having different operating systems that employ different techniques for setting configuration information,

the WINDOWS native policy sets configurable options of an application and is in a WINDOWS native format that can be natively applied by WINDOWS computers to set configuration information on WINDOWS computers but cannot be natively applied by UNIX computers to set configuration information on UNIX computers,

the centralized policy management server has a WINDOWS operating system and maintains centrally managed WINDOWS native policies in a WINDOWS native format and replicates the centrally managed policies to computers of the heterogeneous computer network,

the WINDOWS native policy received by the UNIX client computer in a WINDOWS native format is translated by the UNIX client computer to be usable by the UNIX operating system, and

after translation by the UNIX client computer, the WINDOWS native policy remains centrally managed and updated by the centralized policy management server, and updates to the policy are propagated to the UNIX client computer, such that use of WINDOWS native policies is extended to allow an administrator to use WINDOWS native policies to manage configuration information on the UNIX client computer;

a translate policy operation that causes the UNIX client computer to translate the WINDOWS native policy from the WINDOWS native format to configuration information usable by the UNIX operating system;

an update configuration operation that causes the UNIX client computer to apply the configuration information to the UNIX client computer;

an update on start-up test operation that causes the UNIX client computer to determine whether to update the configuration information on the UNIX client computer at start-up of the UNIX client computer, wherein, if it is determined to update the configuration information on the UNIX client computer at start-up of the UNIX client computer, the UNIX client computer continues with the receive policy operation and performs the update configuration operation at start-up of the UNIX client computer;

an update on login test operation that causes the UNIX client computer to determine whether to update the configuration information on the UNIX client computer upon user login, wherein, if it is determined to update the configuration information on the UNIX client computer upon user login, the UNIX client computer continues with the receive policy operation and performs the update configuration operation at user login;

a refresh time test operation that causes the UNIX client computer to determine when a change has been made to the policy on the centralized policy management server, and, if it is determined that a change has been made to the policy on the centralized policy management server, to continue with the receive policy operation in order to receive the changed policy from the centralized policy management server, such that, after translation of a policy on and before receipt of a changed policy on the UNIX client computer, the policy remains centrally managed and updated by the centralized policy management server, the UNIX client computer maintains an association between the policy and the configuration information, and updates to the policy at the centralized policy management server are propagated to the UNIX client computer.

2. The UNIX client computer of claim 1 , wherein the WINDOWS native policy controls behavior of at least one application for each user within a group.

3. The UNIX client computer of claim 1 , wherein the WINDOWS native policy defines configuration of at least one application for each of a plurality of users within a group.

4. The UNIX client computer of claim 1 , wherein the WINDOWS native policy is a group policy.

5. The UNIX client computer of claim 1 , wherein the refresh time test operation determines when a change has been made to the policy on the centralized policy management server at least by polling the centralized policy management server at periodic intervals.

6. A LINUX client computer having a LINUX operating system and configured to extend use of WINDOWS native policies so that an administrator can use WINDOWS native policies to manage and update configuration information on the LINUX client computer, the LINUX client computer comprising:

a LINUX operating system;

computer hardware including at least one computer processor configured to execute computer-executable instructions; and

computer-executable instructions stored in computer storage and configured, when executed by the processor, to cause the computer hardware to perform operations comprising:

a receive policy operation that causes the LINUX client computer to receive a WINDOWS native policy from a centralized policy management server, wherein:

the LINUX client computer and the centralized policy management server are part of a heterogeneous computer network comprising computers having different operating systems that employ different techniques for setting configuration information,

the WINDOWS native policy sets configurable options of an application and is in a WINDOWS native format that can be natively applied by WINDOWS computers to set configuration information on WINDOWS computers but cannot be natively applied by LINUX computers to set configuration information on LINUX computers,

the centralized policy management server has a WINDOWS operating system and maintains centrally managed WINDOWS native policies in a WINDOWS native format and replicates the centrally managed policies to computers of the heterogeneous computer network,

the WINDOWS native policy received by the LINUX client computer in a WINDOWS native format is translated by the LINUX client computer to be usable by the LINUX operating system, and

after translation by the LINUX client computer, the WINDOWS native policy remains centrally managed and updated by the centralized policy management server, and updates to the policy are propagated to the LINUX client computer, such that use of WINDOWS native policies is extended to allow an administrator to use WINDOWS native policies to manage configuration information on the LINUX client computer;

a translate policy operation that causes the LINUX client computer to translate the WINDOWS native policy from the WINDOWS native format to configuration information usable by the LINUX operating system;

an update configuration operation that causes the LINUX client computer to apply the configuration information to the LINUX client computer;

an update on start-up test operation that causes the LINUX client computer to determine whether to update the configuration information on the LINUX client computer at start-up of the LINUX client computer, wherein, if it is determined to update the configuration information on the LINUX client computer at start-up of the LINUX client computer, the LINUX client computer continues with the receive policy operation and performs the update configuration operation at start-up of the LINUX client computer;

an update on login test operation that causes the LINUX client computer to determine whether to update the configuration information on the LINUX client computer upon user login, wherein, if it is determined to update the configuration information on the LINUX client computer upon user login, the LINUX client computer continues with the receive policy operation and performs the update configuration operation at user login;

a refresh time test operation that causes the LINUX client computer to determine when a change has been made to the policy on the centralized policy management server, and, if it is determined that a change has been made to the policy on the centralized policy management server, to continue with the receive policy operation in order to receive the changed policy from the centralized policy management server, such that, after translation of a policy and before receipt of a changed policy on the LINUX client computer, the policy remains centrally managed and updated by the centralized policy management server, the LINUX client computer maintains an association between the policy and the configuration information, and updates to the policy at the centralized policy management server are propagated to the LINUX client computer.

7. The LINUX client computer of claim 6 , wherein the WINDOWS native policy controls behavior of at least one application for each user within a group.

8. The LINUX client computer of claim 6 , wherein the WINDOWS native policy defines configuration of at least one application for each of a plurality of users within a group.

9. The LINUX client computer of claim 6 , wherein the WINDOWS native policy is a group policy.

10. The LINUX client computer of claim 6 , wherein the refresh time test operation determines when a change has been made to the policy on the centralized policy management server at least by polling the centralized policy management server at periodic intervals.

11. A client computer having a non-WINDOWS operating system and configured to extend use of WINDOWS native policies so that an administrator can use WINDOWS native policies to manage and update configuration information on the client computer, the client computer comprising;

a non-WINDOWS operating system;

computer hardware including at least one computer processor configured to execute computer-executable instructions; and

computer-executable instructions stored in computer storage and configured, when executed by the processor, to cause the computer hardware to perform operations comprising:

a receive policy operation that causes the client computer to receive a WINDOWS native policy from a centralized policy management server, wherein:

the client computer and the centralized policy management server are part of a heterogeneous computer network comprising computers having different operating systems that employ different techniques for setting configuration information,

the WINDOWS native policy sets configurable options of an application and is in a WINDOWS native format that can be natively applied by WINDOWS computers to set configuration information on WINDOWS computers but cannot be natively applied by non-WINDOWS computers to set configuration information on non-WINDOWS computers,

the centralized policy management server has a WINDOWS operating system and maintains centrally managed WINDOWS native policies in a WINDOWS native format and replicates the centrally managed policies to computers of the heterogeneous computer network,

the WINDOWS native policy received by the client computer in a WINDOWS native format is translated by the client computer to be usable by the non-WINDOWS operating system, and

after translation by the client computer, the WINDOWS native policy remains centrally managed and updated by the centralized policy management server, and updates to the policy are propagated to the client computer, such that use of WINDOWS native policies is extended to allow an administrator to use WINDOWS native policies to manage configuration information on the client computer;

a translate policy operation that causes the client computer to translate the WINDOWS native policy from the WINDOWS native format to configuration information usable by the non-WINDOWS operating system;

an update configuration operation that causes the client computer to apply the configuration information to the client computer;

an update on start-up test operation that causes the client computer to determine whether to update the configuration information on the client computer at start-up of the client computer, wherein, if it is determined to update the configuration information on the client computer at start-up of the client computer, the client computer continues with the receive policy operation and performs the update configuration operation at start-up of the client computer;

an update on login test operation that causes the client computer to determine whether to update the configuration information on the client computer upon user login, wherein, if it is determined to update the configuration information on the client computer upon user login, the client computer continues with the receive policy operation and performs the update configuration operation at user login;

a refresh time test operation that causes the client computer to determine when a change has been made to the policy on the centralized policy management server, and, if it is determined that a change has been made to the policy on the centralized policy management server, to continue with the receive policy operation in order to receive the changed policy from the centralized policy management server, such that, after translation of a policy and before receipt of a changed policy on the non-WINDOWS client computer, the policy remains centrally managed and updated by the centralized policy management server, the non-WINDOWS client computer maintains an association between the policy and the configuration information, and updates to the policy at the centralized policy management server are propagated to the non-WINDOWS client computer.

12. The client computer of claim 11 , wherein the WINDOWS native policy controls behavior of at least one application for each user within a group.

13. The client computer of claim 11 , wherein the WINDOWS native policy defines configuration of at least one application for each of a plurality of users within a group.

14. The client computer of claim 11 , wherein the WINDOWS native policy is a group policy.

15. The client computer of claim 11 , wherein the refresh time test operation determines when a change has been made to the policy on the centralized policy management server at least by polling the centralized policy management server at periodic intervals.

Assignments (24)
RELEASE OF SECURITY INTEREST Recorded Nov 19, 2025
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.
Reel/Frame 073606/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 18, 2025
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.
Reel/Frame 073613/0326 →
SECURITY INTEREST Recorded Jun 8, 2025
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; ERWIN, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071527/0001 →
SECURITY INTEREST Recorded Jun 8, 2025
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; ERWIN, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071527/0649 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY DATA PREVIOUSLY RECORDED ON REEL 70194 FRAME 942. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Mar 27, 2025
From: QUEST SOFTWARE INC.
To: ONE IDENTITY LLC
Reel/Frame 070678/0366 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 12, 2025
From: QUEST SOFTWARE INC.
To: ONE IDENTIFY LLC
Reel/Frame 070194/0942 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 2, 2022
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.; ONE IDENTITY LLC; ONELOGIN, INC.; ONE IDENTITY SOFTWARE INTERNATIONAL DESIGNATED ACTIVITY COMPANY
To: GOLDMAN SACHS BANK USA
Reel/Frame 058945/0778 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 2, 2022
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.; ONE IDENTITY LLC; ONELOGIN, INC.; ONE IDENTITY SOFTWARE INTERNATIONAL DESIGNATED ACTIVITY COMPANY
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 058952/0279 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS Recorded Feb 2, 2022
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.
Reel/Frame 059096/0683 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS Recorded Feb 2, 2022
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.
Reel/Frame 059105/0479 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: QUEST SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046327/0486 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: QUEST SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046327/0347 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT R/F 040581/0850 Recorded May 22, 2018
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 046211/0735 →
CHANGE OF NAME Recorded Dec 6, 2017
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 044800/0848 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE PREVIOUSLY RECORDED AT REEL: 040587 FRAME: 0624. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Nov 28, 2017
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 044811/0598 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 10, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040587/0624 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 9, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040581/0850 →
RELEASE OF SECURITY INTEREST Recorded Oct 31, 2016
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0467 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040039/0642) Recorded Oct 31, 2016
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0016 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 21, 2016
From: PETERSON, MATTHEW T.; PETERSON, DANIEL F.
To: VINTELA, INC.
Reel/Frame 040084/0667 →
CHANGE OF NAME Recorded Oct 21, 2016
From: QUEST SOFTWARE, INC.
To: DELL SOFTWARE INC.
Reel/Frame 040462/0631 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 21, 2016
From: VINTELA, INC.
To: QUEST SOFTWARE, INC.
Reel/Frame 040084/0770 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040030/0187 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040039/0642 →