IP Library Granted Patent US 10,382,489
Granted Patent B2
US 10,382,489 · App. 15/394,370 · Granted Aug 13, 2019

Technologies for privacy-preserving security policy evaluation

Inventors: Sudeep Das (Cupertino, CA); Rajesh Poornachandran (Portland, OR); Ned M. Smith (Beaverton, OR); Vincent J. Zimmer (Federal Way, WA); Pramod Sharma (Tanakpur, IN); Arthur Zeigler (Salem, OR); Sumant Vashisth (Portland, OR); Simon Hunt (Naples, FL)
Assignee: Mcafee, LLC
H04L63/20H04L63/0227H04L63/0428H04L63/145G06F2221/21
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,382,489
App. No.
15/394,370
Granted
Aug 13, 2019
Kind
B2
Abstract

Technologies for privacy-safe security policy evaluation include a cloud analytics server, a trusted data access mediator (TDAM) device, and one or more client devices. The cloud analytics server curries a security policy function to generate a privacy-safe curried function set. The cloud analytics server requests parameter data from the TDAM device, which collects the parameter data, identifies sensitive parameter data, encrypts the sensitive parameter data, and transmits the encrypted sensitive parameter data to the cloud analytics server. The cloud analytics server evaluates one or more curried functions using non-sensitive parameters to generate one or more sensitive functions that each take a sensitive parameter. The cloud analytics server transmits the sensitive functions and the encrypted sensitive parameters to a client computing device, which decrypts the encrypted sensitive parameters and evaluates the sensitive functions with the sensitive parameters to return a security policy. Other embodiments are described and claimed.

Claims (40)

1. A server for privacy-safe cloud threat analysis, the server comprising:

at least one hardware processor;

a cloud policy curry engine to curry a security policy function to generate a privacy-safe curried function set, the security policy function to generate a security policy based on a plurality of policy parameters, the privacy-safe curried function set including one or more first functions having a respective non-sensitive parameter of the plurality of policy parameters as an argument, and one or more second functions having a respective sensitive parameter of the plurality of policy parameters as an argument, the cloud policy curry engine is to evaluate the first functions of the privacy-safe curried function set with the parameter data to generate the second functions; and

a communication engine to access parameter data that corresponds to one or more non-sensitive parameters of the plurality of policy parameters, the parameter data being unencrypted, the communication engine to transmit the second functions of the privacy-safe curried function set to a client computing device.

2. The server of claim 1 , wherein the cloud policy curry engine is to access a client data classification policy, the client data classification policy to identify the one or more non-sensitive parameters of the plurality of policy parameters and the one or more sensitive parameters of the plurality of policy parameters.

3. The server of claim 1 , further including a security policy engine to determine the security policy function based on the plurality of policy parameters.

4. The server of claim 1 , wherein the communication engine is to access encrypted parameter data corresponding to the one or more sensitive parameters, and transmit the encrypted parameter data to the client computing device.

5. The server of claim 1 , wherein the communication engine is to access the parameter data from a trusted data access mediator device.

6. The server of claim 1 , wherein the communication engine is to access the parameter data from an external data source.

7. The server of claim 1 , wherein the communication engine is to transmit the second function to the client device via a trusted data access mediator device.

8. The server of claim 1 , further including a trusted execution environment to execute the cloud policy curry engine and the communication engine.

9. The server of claim 8 , wherein the trusted execution environment includes a secure enclave established by secure enclave support of a processor of the computing device.

10. One or more computer-readable storage media, excluding propagating signals, comprising instructions that, when executed, cause a processor to:

curry a security policy function to generate a privacy-safe curried function set, the security policy function to generate a security policy as a function of a plurality of policy parameters, the privacy-safe curried function set including one or more first functions taking a respective non-sensitive parameter of the plurality of policy parameters as an argument, and one or more second functions having a respective sensitive parameter of the plurality of policy parameters as an argument the parameter data being unencrypted;

evaluate the one or more first functions of the privacy-safe curried function set with the parameter data corresponding to the non-sensitive parameters to generate the one or more second functions; and

transmit the one or more second functions of the privacy-safe curried function set to a client computing device.

11. The one or more computer-readable storage disks or storage devices of claim 10 , wherein the instructions, when executed, cause the processor to access a client data classification policy, the client data classification policy to identify the one or more non-sensitive parameters of the plurality of policy parameters and the one or more sensitive parameters of the plurality of policy parameters.

12. The one or more computer-readable storage disks or storage devices of claim 10 , wherein the instructions, when executed, cause the processor to determine the security policy function, the security policy function to generate a security policy based on the plurality of policy parameters.

13. The one or more computer-readable storage disks or storage devices of claim 10 , wherein the instructions, when executed, cause the processor to access encrypted parameter data corresponding to the one or more sensitive parameters and transmit the encrypted parameter data to the client computing device.

14. The one or more computer-readable storage disks or storage devices of claim 10 , wherein the instructions, when executed, cause the processor to transmit the one or more second functions to the client device via a trusted data access mediator device.

15. A client computing device for privacy-safe cloud threat analysis, the client computing device comprising:

communication circuitry;

a communication engine to access, from a cloud analytics server via the communication circuitry, one or more functions of a privacy-safe curried function set, the one or more functions to take a respective sensitive parameter of a plurality of policy parameters as an argument, and access encrypted parameter data that corresponds to the one or more sensitive parameters of the plurality of policy parameters; and

a client policy evaluation engine to decrypt the encrypted parameter data to generate the one or more sensitive parameters, and evaluate the one or more functions with the one or more sensitive parameters to generate a security policy.

16. The client computing device of claim 15 , wherein the communication engine is to access the encrypted parameter data from the cloud analytics server.

17. The client computing device of claim 15 , wherein the communication engine is to access the encrypted parameter data from a trusted data access mediator device.

18. The client computing device of claim 15 , further including a security policy engine to negotiate the security policy with the cloud analytics server in response to evaluation of the one or more second functions.

19. The client computing device of claim 15 , further including a security policy engine to enforce the security policy.

20. The client computing device of claim 15 , further including a trusted execution environment to execute at least one of the communication engine, or the client policy evaluation engine.

21. The client computing device of claim 20 , wherein the trusted execution environment includes a secure enclave established by secure enclave support of a processor of the client computing device.

22. One or more computer-readable storage disks or storage devices comprising instructions that, when executed, cause a processor to at least:

access, from a cloud analytics server, one or more functions of a privacy-safe curried function set, the one or more functions including a respective sensitive parameter of a plurality of policy parameters as an argument;

access encrypted parameter data corresponding to the one or more sensitive parameters of the plurality of policy parameters;

decrypt the encrypted parameter data to generate the one or more sensitive parameters; and

evaluate the one or more sensitive functions with the one or more sensitive parameters to generate a security policy.

23. The one or more computer-readable storage disks or storage devices of claim 22 , wherein the instructions, when executed, cause the processor to access the encrypted parameter data from the cloud analytics server.

24. The one or more computer-readable storage disks or storage devices of claim 22 , wherein the instructions, when executed, cause the processor to access the encrypted parameter data from a trusted data access mediator device.

25. The one or more computer-readable storage disks or storage devices of claim 22 , wherein the instructions, when executed, cause the processor to negotiate the security policy with the cloud analytics server in response to evaluating the one or more functions.

26. The server of claim 1 , the one or more second functions of the privacy-safe curried function set to be evaluated at the client computing device.

27. The server of claim 1 , further including a security policy engine to negotiate the security policy with the client computing device in response to (i) evaluation of the one or more first functions by the cloud policy curry engine, and (ii) evaluation of the one or more second functions by the client computing device.

Assignments (21)
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068657/0843 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068657/0764 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068656/0920 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068656/0098 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 056990, FRAME 0960 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0430 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 057453, FRAME 0053 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0413 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 1, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 060561/0466 →
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY NUMBERS PREVIOUSLY RECORDED AT REEL: 057315 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Apr 11, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 060878/0126 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057453/0053 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 056990/0960 →
RELEASE OF SECURITY INTEREST Recorded Jul 26, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: MCAFEE, LLC; SKYHIGH NETWORKS, LLC
Reel/Frame 057620/0102 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Sep 15, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043969/0057 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 28, 2017
From: DAS, SUDEEP; POORNACHANDRAN, RAJESH; SMTH, NED M.; ZIMMER, VINCENT J.; SHARMA, PRAMOD; ZEIGLER, ARTHUR; VASHISTH, SUMANT; HUNT, SIMON
To: MCAFEE, INC.
Reel/Frame 042369/0043 →
Continuity (1)
Related Publication 20180191780A1 · Jul 5, 2018
Cited By (3)
US 12,556,566 US 12,609,969 US 12,719,885