IP Library Granted Patent US 11,570,111
Granted Patent B2
US 11,570,111 · App. 17/213,145 · Granted Jan 31, 2023

Enforcing access to endpoint resources

Inventors: Scott Dale Brown (Raleigh, NC); Andrew Keats (Seneca, SC); Matthew Rockey (Raleigh, NC); Jason Estes (Spokane, WA)
Assignee: Itron, Inc.
H04L47/20H04L9/3236H04L9/3263H04L47/125
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,570,111
App. No.
17/213,145
Granted
Jan 31, 2023
Kind
B2
Abstract

Techniques are directed to controlling access to resources on a message bus of a network communication device. The techniques may include, by the network communication device, processing a message bus access policy file uniquely corresponding to a process. The message bus access policy file may include a certificate securely associating the message bus access policy file with the process. The techniques may further include, by the network communication device, based at least in part on the processing the message bus access policy file, exposing one or more resources of the network communication device to the process on the message bus, in a manner corresponding to at least one resource access permission indication contained within the message bus access policy file.

Claims (45)

1. A method to control access to resources on a message bus of a network communication device, comprising:

by the network communication device, processing a message bus access policy file corresponding to a process, the message bus access policy file including a certificate securely associating the message bus access policy file with the process; and

by the network communication device, based at least in part on the processing the message bus access policy file, exposing one or more resources of the network communication device to the process on the message bus, in a manner corresponding to at least one resource access permission indication contained within the message bus access policy file.

2. The method of claim 1 , wherein:

the certificate comprises a digest representing a value achieved by applying a cryptographic algorithm to a binary executable file corresponding to the process.

3. The method of claim 2 , wherein the cryptographic algorithm is a secure hash algorithm.

4. The method of claim 1 , wherein:

the one or more resources of the network communication device include at least one of data generated by the network communication device and network communication resources of the network communication device.

5. The method of claim 1 , wherein:

the at least one resource access permission indication indicates an absence of a resource access permission corresponding to a resource access request by the process; and

the manner corresponding to the at least one resource access permission indication contained within the message bus access policy file includes a default manner associated with the one or more resources of the network communication device.

6. The method of claim 5 , wherein:

the default manner associated with the one or more resources of the network communication device includes denying access to the one or more resources of the network communication device.

7. The method of claim 1 , wherein:

the at least one resource access permission indication is at least one policy and/or permission corresponding to the one or more resources of the network communication device and affirmatively stated in the message bus access policy file.

8. The method of claim 1 , further comprising:

by the network communication device, receiving an agent package including a binary executable file corresponding to the process and a certificate securely associating the message bus access policy file with the process, wherein the certificate comprises a digest representing a value achieved by applying a cryptographic algorithm to the binary executable file.

9. A network communication device for operation in a network, including communicating to one or more other devices in the network, comprising:

one or more processors;

memory coupled to the one or more processors, the memory storing instructions executable by the one or more processors to perform operations to control access to resources on a message bus of the network communication device, the operations comprising:

processing a message bus access policy file corresponding to a process, the message bus access policy file including a certificate securely associating the message bus access policy file with the process; and

based at least in part on the processing the message bus access policy file, exposing one or more resources of the network communication device to the process on the message bus, in a manner corresponding to at least one resource access permission indication contained within the message bus access policy file.

10. The network communication device of claim 9 , wherein:

the certificate comprises a digest representing a value achieved by applying a cryptographic algorithm to a binary executable file corresponding to the process.

11. The network communication device of claim 10 , wherein the cryptographic algorithm is a secure hash algorithm.

12. The network communication device of claim 9 , wherein:

the one or more resources of the network communication device include at least one of data generated by the network communication device and network communication resources of the network communication device.

13. The network communication device of claim 9 , wherein:

the at least one resource access permission indication indicates an absence of a resource access permission corresponding to a resource access request by the process; and

the manner corresponding to the at least one resource access permission indication contained within the message bus access policy file includes a default manner associated with the one or more resources of the network communication device.

14. The network communication device of claim 13 , wherein:

the default manner associated with the one or more resources of the network communication device includes denying access to the one or more resources of the network communication device.

15. The network communication device of claim 9 , wherein:

the at least one resource access permission indication is at least one policy and/or permission corresponding to the one or more resources of the network communication device and affirmatively stated in the message bus access policy file.

16. The network communication device of claim 9 , further comprising:

by the network communication device, receiving an agent package including at least a binary executable file corresponding to the process and a certificate securely associating the message bus access policy file with the process, wherein the certificate comprises a digest representing a value achieved by applying a cryptographic algorithm to the binary executable file.

17. One or more computer-readable storage media storing computer-readable instructions that, when executed, instruct one or more processors of a network communication device in a network to perform operations to control access to resources on a message bus of the network communication device, the operations comprising:

processing a message bus access policy file corresponding to a process, the message bus access policy file including a certificate securely associating the message bus access policy file with the process; and

based at least in part on the processing the message bus access policy file, exposing one or more resources of the network communication device on the message bus, in a manner corresponding to at least one resource access permission indication contained within the message bus access policy file.

18. The one or more computer-readable storage media of claim 17 , wherein:

the certificate comprises a digest representing a value achieved by applying a cryptographic algorithm to a binary executable file corresponding to the process.

19. The one or more computer-readable storage media of claim 17 , wherein:

the one or more resources of the network communication device include at least one of data generated by the network communication device and network communication resources of the network communication device.

20. The one or more computer-readable storage media of claim 17 , the operations further comprising:

receiving an agent package including at least a binary executable file corresponding to the process and the certificate securely associating the message bus access policy file with the process, wherein the certificate comprises a digest representing a value achieved by applying a cryptographic algorithm to the binary executable file.

Assignments (4)
SECURITY INTEREST Recorded Sep 15, 2025
From: ITRON, INC.
To: WELLS FARGO BANK, NATIONAL ASSOCIATION
Reel/Frame 072870/0873 →
SECURITY INTEREST Recorded Nov 30, 2023
From: ITRON, INC.; ITRON NETWORKED SOLUTIONS, INC.
To: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS ADMINISTRATIVE AGENT
Reel/Frame 065727/0302 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 4, 2021
From: BROWN, SCOTT DALE; KEATS, ANDREW; ROCKEY, MATTHEW; ESTES, JASON
To: ITRON, INC.
Reel/Frame 057080/0974 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 4, 2021
From: BROWN, SCOTT DALE; KEATS, ANDREW; ROCKEY, MATTHEW; ESTES, JASON
To: ITRON, INC.
Reel/Frame 057081/0520 →