IP Library Granted Patent US 11,909,769
Granted Patent B2
US 11,909,769 · App. 17/153,708 · Granted Feb 20, 2024

Technologies for privacy-preserving security policy evaluation

Inventors: Sudeep Das (Cupertino, CA); Rajesh Poornachandran (Portland, OR); Ned M. Smith (Beaverton, OR); Vincent J. Zimmer (Federal Way, WA); Pramod Sharma (Tanakpur, IN); Arthur Zeigler (Salem, OR); Sumant Vashisth (Portland, OR); Simon Hunt (Naples, FL)
Assignee: MUSARUBRA US LLC
H04L63/20H04L63/0227H04L63/0428H04L63/145G06F2221/21
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,909,769
App. No.
17/153,708
Granted
Feb 20, 2024
Kind
B2
Abstract

Technologies for privacy-safe security policy evaluation are disclosed herein. An example apparatus includes at least one memory, and at least one processor to execute instructions to at least identify one or more non-sensitive parameters of a plurality of policy parameters and one or more sensitive parameters of the plurality of the policy parameters, the plurality of the policy parameters obtained from a computing device in response to a request from a cloud analytics server for the plurality of the policy parameters, encrypt the one or more sensitive parameters to generate encrypted parameter data in response to the identification of the one or more sensitive parameters, and transmit the encrypted parameter data to the cloud analytics server, the cloud analytics server to curry a security policy function based on one or more of the plurality of the policy parameters.

Claims (50)

1. An apparatus for performing privacy-safe cloud threat analysis, the apparatus comprising:

at least one memory; and

at least one processor to execute instructions to at least:

identify one or more non-sensitive parameters of a plurality of policy parameters and one or more sensitive parameters of the plurality of the policy parameters, the plurality of the policy parameters obtained from a computing device in response to a request from a cloud analytics server for the plurality of the policy parameters;

encrypt the one or more sensitive parameters to generate encrypted parameter data in response to the identification of the one or more sensitive parameters;

analyze the encrypted parameter data to determine whether to apply a security policy to the encrypted parameter data;

select a security policy from one or more security policies based on whether to apply the security policy to the encrypted parameter data, the selection of the security policy further based on whether the security policy meets an acceptance threshold;

transmit the encrypted parameter data to the cloud analytics server, the cloud analytics server to curry a security policy function based on one or more of the plurality of the policy parameters; and

request use of the security policy by the cloud analytics server subsequent to the transmission of the encrypted parameter data to the cloud analytics server.

2. The apparatus of claim 1 , wherein the at least one processor is to execute ones of the instructions in a trusted execution environment, the trusted execution environment including a secure enclave established by secure enclave support of the at least one processor.

3. The apparatus of claim 1 , wherein the at least one processor is to transmit the one or more non-sensitive parameters to the cloud analytics server in response to the identification of the one or more non-sensitive parameters.

4. The apparatus of claim 1 , wherein the at least one processor is to generate the one or more security policies for which to select the security policy.

5. The apparatus of claim 1 , wherein the cloud analytics server is a virtual server.

6. The apparatus of claim 1 , wherein the one or more sensitive parameters include data associated with at least one of financial information, protected health information, or individually identifiable information, the individually identifiable information including at least one of a user name or an Internet Protocol address, and the at least one processor is to:

determine a data classification policy based on at least one of the financial information, the protected health information, or the individually identifiable information; and

identify at least one of (i) the one or more non-sensitive parameters or (ii) the one or more sensitive parameters based on the data classification policy.

7. The apparatus of claim 1 , wherein the at least one processor is to:

obtain a privacy-safe curried function set from the cloud analytics server, the privacy-safe curried function set including one or more first functions and one or more second functions, the one or more first functions having a respective non-sensitive parameter of the one or more non-sensitive parameters as respective first arguments, the one or more second functions having a respective sensitive parameter of the one or more sensitive parameters as respective second arguments; and

provide at least one of (i) the one or more first functions or (ii) the one or more second functions to the computing device.

8. The apparatus of claim 7 , wherein the privacy-safe curried function is generated in response to the cloud analytics server currying the security policy function, the cloud analytics server to curry the security policy function in response to obtaining the encrypted parameter data from the at least one processor.

9. A machine readable storage medium comprising instructions that, when executed, cause at least one processor to at least:

identify one or more non-sensitive parameters of a plurality of policy parameters and one or more sensitive parameters of the plurality of the policy parameters, the plurality of the policy parameters obtained from a computing device in response to a request from a cloud analytics server for the plurality of the policy parameters;

encrypt the one or more sensitive parameters to generate encrypted parameter data in response to the identification of the one or more sensitive parameters;

analyze the encrypted parameter data to determine whether to apply a security policy to the encrypted parameter data;

select a security policy from one or more security policies based on whether to apply the security policy to the encrypted parameter data, the selection of the security policy further based on whether the security policy meets an acceptance threshold;

transmit the encrypted parameter data to the cloud analytics server, the cloud analytics server to curry a security policy function based on one or more of the plurality of the policy parameters; and

request use of the security policy by the cloud analytics server subsequent to the transmission of the encrypted parameter data to the cloud analytics server.

10. The machine readable storage medium of claim 9 , wherein the instructions, when executed, cause the at least one processor to execute ones of the instructions in a trusted execution environment, the trusted execution environment including a secure enclave established by secure enclave support of the at least one processor.

11. The machine readable storage medium of claim 9 , wherein the instructions, when executed, cause the at least one processor to transmit the one or more non-sensitive parameters to the cloud analytics server in response to the identification of the one or more non-sensitive parameters.

12. The machine readable storage medium of claim 9 , wherein the instructions, when executed, cause the at least one processor to generate the one or more security policies for which to select the security policy.

13. The machine readable storage medium of claim 9 , wherein the one or more sensitive parameters include data associated with at least one of financial information, protected health information, or individually identifiable information, the individually identifiable information including at least one of a user name or an Internet Protocol address, and the instructions, when executed, cause the at least one processor to:

determine a data classification policy based on at least one of the financial information, the protected health information, or the individually identifiable information; and

identify at least one of (i) the one or more non-sensitive parameters or (ii) the one or more sensitive parameters based on the data classification policy.

14. The machine readable storage medium of claim 9 , wherein the instructions, when executed, cause the at least one processor to:

obtain a privacy-safe curried function set from the cloud analytics server, the privacy-safe curried function set including one or more first functions and one or more second functions, the one or more first functions having a respective non-sensitive parameter of the one or more non-sensitive parameters as respective first arguments, the one or more second functions having a respective sensitive parameter of the one or more sensitive parameters as respective second arguments; and

provide at least one of (i) the one or more first functions or (ii) the one or more second functions to the computing device.

15. The machine readable storage medium of claim 14 , wherein the privacy-safe curried function is generated in response to the cloud analytics server currying the security policy function, the cloud analytics server to curry the security policy function in response to obtaining the encrypted parameter data from the at least one processor.

16. A method for privacy-safe cloud threat analysis, the method comprising:

accessing one or more functions of a privacy-safe curried function set, the one or more functions to take a respective sensitive parameter of a plurality of policy parameters as an argument;

accessing encrypted parameter data that corresponds to one or more sensitive parameters of the plurality of policy parameters;

decrypting the encrypted parameter data to generate the one or more sensitive parameters;

analyzing the encrypted parameter data to determine whether to apply a security policy to the encrypted parameter data;

selecting a security policy from one or more security policies based on whether to apply the security policy to the encrypted parameter data, the selection of the security policy further based on whether the security policy meets an acceptance threshold; and

requesting use of the security policy by a cloud analytics server subsequent to a transmission of the encrypted parameter data to the cloud analytics server.

17. The method of claim 16 , wherein the encrypted parameter data is accessed from at least one of a cloud analytics server or a trusted data access mediator device.

18. The method of claim 16 , further including:

generating the one or more security policies for which to select the security policy; and

enforcing the security policy.

19. The method of claim 16 , wherein at least one of the accessing of the one or more functions, the accessing of the encrypted parameter data, the decrypting of the encrypted parameter data, or evaluating of the one or more functions is executed in a trusted execution environment.

20. The method of claim 19 , wherein the trusted execution environment includes a secure enclave established by secure enclave support of at least one processor.

Assignments (17)
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068657/0843 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068657/0764 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068656/0920 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 056990, FRAME 0960 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0430 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068656/0098 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 057453, FRAME 0053 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0413 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY NUMBERS PREVIOUSLY RECORDED AT REEL: 057315 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Apr 11, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 060878/0126 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 1, 2021
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 057393/0546 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 056990/0960 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057453/0053 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 3, 2021
From: DAS, SUDEEP; POORNACHANDRAN, RAJESH; SMITH, NED M.; ZIMMER, VINCENT J.; SHARMA, PRAMOD; ZEIGLER, ARTHUR; VASHISTH, SUMANT; HUNT, SIMON
To: MCAFEE, INC.
Reel/Frame 055209/0358 →
CHANGE OF NAME Recorded Feb 3, 2021
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 055209/0296 →
Continuity (3)
Continuation 16538434 · Aug 12, 2019
Continuation 15394370 · Dec 29, 2016
Related Publication 20210168176A1 · Jun 3, 2021
Cited By (2)
US 12,314,425 US 12,326,949