IP Library Granted Patent US 10,135,874
Granted Patent B1
US 10,135,874 · App. 15/353,561 · Granted Nov 20, 2018

Compliance management system and method for an integrated computing system

Inventor: Brian Perry (Murphy, TX)
Assignee: VCE IP Holding Company LLC
H04L63/20H04L41/044H04L67/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,135,874
App. No.
15/353,561
Granted
Nov 20, 2018
Kind
B1
Abstract

A integrated computing system compliance management system includes a computer-based system to obtain an integrated computing system object instance of an integrated computing system that is generated from an object model comprising a unified entity representing the integrated computing system. The integrated computing system object instance has multiple hierarchally arranged sub-object instances representing hierarchally arranged resources of the integrated computing system. The system receive security hardening policies associated with an established security hardening standard, modify those sub-object instances to include the security hardening policies that are associated with those sub-object instances to form a security hardening-based object instance. Using the security hardening-based object instance, the system determines, for each security hardening policy, whether the configuration of the resources meets the security hardening policy using the security hardening-based object instance. Once determined, the system may then output the result of the determination.

Claims (33)

1. An integrated computing system compliance management system comprising:

a computing system comprising at least one memory to store instructions that are executed by at least one processor to:

obtain an integrated computing system object instance of an integrated computing system, the object instance generated from an object model comprising a unified entity representing the integrated computing system, wherein the integrated computing system object instance includes a plurality of hierarchally arranged sub-object instances representing a plurality of hierarchally arranged resources of the integrated computing system;

obtain a plurality of security hardening policies associated with a security hardening standard;

modify one or more of the sub-object instances to include the security hardening policies that are associated with the one or more sub-object instances to form a security hardening-based object instance; and

determine, for each security hardening policy, whether the configuration of the resources represented by the one or more instances meets the security hardening policy using the security hardening-based object instance.

2. The integrated computing system compliance management system of claim 1 , wherein the instructions are further executed to import the security hardening policies from at least one of a database, a persistent data store, and a spreadsheet program.

3. The integrated computing system compliance management system of claim 2 , wherein the instructions are further executed to import the security hardening policies as an extensible markup language (XML) formatted file.

4. The integrated computing system compliance management system of claim 1 , wherein the instructions are further executed to perform a discovery operation to obtain configuration information about the resources in the integrated computing system, and create the integrated computing system object instance using the discovered configuration information.

5. The integrated computing system compliance management system of claim 1 , wherein the instructions are further executed to obtain the configuration information from an integrated computing system management application.

6. The integrated computing system compliance management system of claim 1 , wherein the instructions are further executed to obtain the integrated computing system object instance from an integrated computing system design tool, wherein the integrated computing system has not yet been fabricated.

7. The integrated computing system compliance management system of claim 1 , wherein one or more of the security hardening policies comprise one or more security hardening guidelines obtained from a provider of one or more of the resources, the one or more security hardening guidelines are included in the sub-object instances associated with the one or more resources.

8. The integrated computing system compliance management system of claim 1 , wherein one or more of the security hardening policies are each associated with a structured name having a hierarchal structure based upon one or more criteria associated with a type of the resource.

9. An integrated computing system compliance management method comprising:

obtaining, using executable instructions stored in a non-transitory medium and executed on at least one processor, an integrated computing system object instance of an integrated computing system, the object instance generated from an object model comprising a unified entity representing the integrated computing system, wherein the integrated computing system object instance includes a plurality of hierarchally arranged sub-object instances representing a plurality of hierarchally arranged resources of the integrated computing system;

obtaining, using the instructions, a plurality of security hardening policies associated with an established security hardening standard;

modifying, using the instructions, one or more of the sub-object instances to include the security hardening policies that are associated with those sub-object instances to form a security hardening-based object instance; and

determine, using the instructions, whether the configuration of the resources meets the security hardening policy using the security hardening-based object instance for each security hardening policy.

10. The integrated computing system compliance management method of claim 9 , further comprising importing the security hardening policies from at least one of a database, a persistent data store, and a spreadsheet program.

11. The integrated computing system compliance management method of claim 10 , further comprising importing the security hardening policies as an extensible markup language (XML) formatted file.

12. The integrated computing system compliance management method of claim 9 , further comprising perform a discovery operation to obtain configuration information about the resources in the integrated computing system, and create the integrated computing system object instance using the discovered configuration information.

13. The integrated computing system compliance management method of claim 9 , further comprising obtain the configuration information from an integrated computing system management application.

14. The integrated computing system compliance management method of claim 9 , further comprising obtain the integrated computing system object instance from an integrated computing system design tool, wherein the integrated computing system has not yet been fabricated.

15. The integrated computing system compliance management method of claim 9 , further comprising obtaining one or more of the security hardening policies comprising one or more security hardening guidelines obtained from a provider of one or more of the resources, the one or more security hardening guidelines are included in the sub-object instances associated with the one or more resources.

16. The integrated computing system compliance management method of claim 9 , further comprising generating a structured name for each security hardening policy having a hierarchal structure based upon one or more criteria associated with a type of the resource.

17. Code implemented in a non-transitory, computer readable medium that when executed by at least one processor, is operable to perform at least the following:

obtaining an integrated computing system object instance of an integrated computing system, the object instance generated from an object model comprising a unified entity representing the integrated computing system, wherein the integrated computing system object instance includes a plurality of hierarchally arranged sub-object instances representing a plurality of hierarchally arranged resources of the integrated computing system;

obtaining a plurality of security hardening policies associated with an established security hardening standard;

modifying one or more of the sub-object instances to include the security hardening policies that are associated with those sub-object instances to form a security hardening-based object instance; and

determine whether the configuration of the resources meets the security hardening policy using the security hardening-based object instance for each security hardening policy.

18. The code claim 17 , further operable to perform importing the security hardening policies from a spreadsheet program as an extensible markup language (XML) formatted file.

19. The code of claim 17 , further operable to perform a discovery operation to obtain configuration information about the resources in the integrated computing system, and create the integrated computing system object instance using the discovered configuration information.

20. The code of claim 17 , further operable to perform obtaining one or more of the security hardening policies comprising one or more security hardening guidelines obtained from a provider of one or more of the resources, the one or more security hardening guidelines are included in the sub-object instances associated with the one or more resources.

Assignments (5)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
MERGER Recorded Apr 14, 2020
From: VCE IP HOLDING COMPANY LLC
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 052398/0413 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 16, 2016
From: PERRY, BRIAN
To: VCE IP HOLDING COMPANY LLC
Reel/Frame 040348/0342 →
Cited By (4)
US 12,301,629 US 12,463,822 US 12,493,686 US 12,547,730