IP Library Granted Patent US 9,881,159
Granted Patent B1
US 9,881,159 · App. 14/541,791 · Granted Jan 30, 2018

Workload execution systems and methods

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,881,159
App. No.
14/541,791
Filed
Nov 14, 2014
Granted
Jan 30, 2018
Kind
B1
Art Unit
2492
USPC
713/175
Abstract

In one embodiment, a method is executed by a computer system. The method includes receiving information related to a platform-portable workload, the information comprising a data security policy expressed as digitally signed metadata. The data security policy specifies one or more data security features that any platform executing the platform-portable workload should implement. The method further includes validating the digitally signed metadata as originating from an issuer of the platform-portable workload. In addition, the method includes, responsive to successful validation of the digitally signed metadata, automatically determining whether a particular platform can satisfy the data security policy based, at least in part, on a comparison of the digitally signed metadata with data security attributes of the particular platform. Further, the method includes, responsive to a determination that the particular platform cannot satisfy the data security policy, automatically preventing execution of the platform-portable workload on the particular platform.

Claims (45)

1. A method comprising, by an information handling system comprising a processor and memory:

receiving information related to a platform-portable workload, the information comprising a data security policy expressed as digitally signed metadata, wherein the data security policy specifies one or more data security features that any platform allowed to execute the platform-portable workload is to implement;

validating the digitally signed metadata as originating from an issuer computer system that issued the platform-portable workload;

responsive to the validating, automatically determining that a particular platform cannot satisfy the data security policy based, at least in part, on a comparison of the digitally signed metadata with data security attributes of the particular platform; and

responsive to the automatically determining, automatically preventing execution of the platform-portable workload on the particular platform,

wherein the automatically preventing comprises:

selecting a second platform that is determined to satisfy the data security policy; and

transmitting the platform-portable workload to the second platform for execution.

2. The method of claim 1 , wherein the information handling system is associated with the particular platform.

3. The method of claim 1 , wherein the automatically preventing further comprises preventing the platform-portable workload from being sent to the particular platform for execution.

4. The method of claim 1 , wherein the selecting comprises selecting the second platform from among a plurality of platforms.

5. The method of claim 1 , wherein:

the information comprises an asserted signature of the issuer computer system and a digital certificate, the digital certificate comprising a public key; and

the validating comprises:

verifying that the digital certificate is from a trusted certificate authority; and

verifying that the asserted signature is valid using the public key.

6. The method of claim 1 , wherein the information related to the platform-portable workload is the platform-portable workload.

7. The method of claim 1 , wherein the digitally signed metadata conforms to a standard implemented by at least the issuer computer system and the information handling system.

8. The method of claim 1 , wherein the one or more data security features are selected from the group consisting of: physical security features, encryption features, user authentication features, virtualization features, network security features, security services offered, audit features, geolocation requirements, operating system version, and security standards supported.

9. An information handling system comprising a hardware processor and physical memory, wherein the hardware processor and physical memory in combination are configured to implement a method comprising:

receiving information related to a platform-portable workload, the information comprising a data security policy expressed as digitally signed metadata, wherein the data security policy specifies one or more data security features that any platform allowed to execute the platform-portable workload is to implement;

validating the digitally signed metadata as originating from an issuer computer system that issued the platform-portable workload;

responsive to the validating, automatically determining that a particular platform cannot satisfy the data security policy based, at least in part, on a comparison of the digitally signed metadata with data security attributes of the particular platform; and

responsive to the automatically determining, automatically preventing execution of the platform-portable workload on the particular platform,

wherein the automatically preventing comprises:

selecting a second platform that is determined to satisfy the data security policy; and

transmitting the platform-portable workload to the second platform for execution.

10. The information handling system of claim 9 , wherein the information handling system is associated with the particular platform.

11. The information handling system of claim 9 , wherein the selecting comprises selecting the second platform from among a plurality of platforms.

12. The information handling system of claim 9 , wherein:

the information comprises an asserted signature of the issuer computer system and a digital certificate, the digital certificate comprising a public key; and

the validating comprises:

verifying that the digital certificate is from a trusted certificate authority; and

verifying that the asserted signature is valid using the public key.

13. The information handling system of claim 9 , wherein the information related to the platform-portable workload is the platform-portable workload.

14. The information handling system of claim 9 , wherein the digitally signed metadata conforms to a standard implemented by at least the issuer computer system and the information handling system.

15. The information handling system of claim 9 , wherein the one or more data security features are selected from the group consisting of: physical security features, encryption features, user authentication features, virtualization features, network security features, security services offered, audit features, geolocation requirements, operating system version, and security standards supported.

16. A computer-program product comprising a non-transitory computer-usable medium having computer-readable program code embodied therein, the computer-readable program code adapted to be executed to implement a method comprising:

receiving information related to a platform-portable workload, the information comprising a data security policy expressed as digitally signed metadata, wherein the data security policy specifies one or more data security features that any platform allowed to execute the platform-portable workload is to implement;

validating the digitally signed metadata as originating from an issuer computer system that issued the platform-portable workload;

responsive to the validating, automatically determining that a particular platform cannot satisfy the data security policy based, at least in part, on a comparison of the digitally signed metadata with data security attributes of the particular platform; and

responsive to the automatically determining, automatically preventing execution of the platform-portable workload on the particular platform,

wherein the automatically preventing comprises:

selecting a second platform that is determined to satisfy the data security policy; and

transmitting the platform-portable workload to the second platform for execution.

Assignments (27)
RELEASE OF SECURITY INTEREST Recorded Nov 19, 2025
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.
Reel/Frame 073606/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 18, 2025
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.
Reel/Frame 073613/0326 →
SECURITY INTEREST Recorded Jun 8, 2025
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; ERWIN, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071527/0649 →
SECURITY INTEREST Recorded Jun 8, 2025
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; ERWIN, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071527/0001 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS Recorded Feb 2, 2022
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.
Reel/Frame 059105/0479 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 2, 2022
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.; ONE IDENTITY LLC; ONELOGIN, INC.; ONE IDENTITY SOFTWARE INTERNATIONAL DESIGNATED ACTIVITY COMPANY
To: GOLDMAN SACHS BANK USA
Reel/Frame 058945/0778 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 2, 2022
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.; ONE IDENTITY LLC; ONELOGIN, INC.; ONE IDENTITY SOFTWARE INTERNATIONAL DESIGNATED ACTIVITY COMPANY
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 058952/0279 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS Recorded Feb 2, 2022
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.
Reel/Frame 059096/0683 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: QUEST SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046327/0486 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: QUEST SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046327/0347 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT R/F 040581/0850 Recorded May 22, 2018
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 046211/0735 →
CHANGE OF NAME Recorded Dec 6, 2017
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 044719/0565 →
CHANGE OF NAME Recorded Nov 28, 2017
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 044822/0810 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE PREVIOUSLY RECORDED AT REEL: 040587 FRAME: 0624. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Nov 28, 2017
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 044811/0598 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 10, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040587/0624 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 9, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040581/0850 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040039/0642) Recorded Oct 31, 2016
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0016 →
RELEASE OF SECURITY INTEREST Recorded Oct 31, 2016
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0467 →
RELEASE OF REEL 035104 FRAME 0043 (NOTE) Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; COMPELLENT TECHNOLOGIES, INC.
Reel/Frame 040027/0123 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040030/0187 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040039/0642 →
RELEASE OF REEL 035103 FRAME 0809 (TL) Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; COMPELLENT TECHNOLOGIES, INC.
Reel/Frame 040027/0934 →
RELEASE OF REEL 035103 FRAME 0536 (ABL) Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; COMPELLENT TECHNOLOGIES, INC.
Reel/Frame 040016/0864 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (TERM LOAN) Recorded Feb 26, 2015
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; COMPELLENT TECHNOLOGIES, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 035103/0809 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (ABL) Recorded Feb 26, 2015
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; COMPELLENT TECHNOLOGIES, INC.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 035103/0536 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (NOTES) Recorded Feb 26, 2015
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; COMPELLENT TECHNOLOGIES, INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 035104/0043 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 17, 2014
From: WILSON, JACQUELINE H.; HAIDER, SAJAWAL; LOWERY, JAMES C.; MORTMAN, DAVID
To: DELL SOFTWARE INC.
Reel/Frame 034183/0346 →