IP Library Granted Patent US 7,739,735
Granted Patent B2
US 7,739,735 · App. 11/493,010 · Granted Jun 15, 2010

System and method for dynamic optimizations using security assertions

Assignee: Novell, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,739,735
App. No.
11/493,010
Filed
Jul 26, 2006
Granted
Jun 15, 2010
Kind
B2
Art Unit
2436
USPC
726/21
Abstract

The invention relates to a system and method for efficient security runtime. If the same security demand for permissions occurs twice during the same code path (i.e. execution stack) the latter can be automatically turned (optimized) into a security assertion based on the former demand. A security runtime can determine which assertions to establish in a call stack, using declarative security information kept in an assembly metadata and based on execution history to know what has already been demanded for a specific stack frame. If the method being called has been allowed to execute before then a demand may be replaced with an assertion for the same permissions within the call stack. If that frame was executed then it means the security demand was successfully evaluated. Furthermore, if the permission evaluation result is known to be static (e.g., its result will not change) it can be determined that another check on the same permissions is not required higher on the stack, so this demand can safely be replaced by an assertion, which can effectively speed up the code execution without sacrificing security.

Claims (41)

1. A method for dynamic optimizations using security assertions, comprising:

initiating a runtime module on a computer, wherein the runtime module is configured to execute an application that includes a call stack having a plurality of sequential stack frames;

performing, during the execution of the application in the runtime module, a first stack walk in response to a first runtime call into a first one of the plurality of sequential stack frames in the call stack including a first demand that requests at least one permission, wherein the first stack walk includes:

evaluating the plurality of sequential stack frames in the call stack from the first stack frame that includes the first demand to a bottom of the call stack;

granting the first demand for the at least one permission in response to all of the stack frames evaluated in the call first stack satisfying the at least one permission; and

promoting the first demand for the at least one permission into an assertion for the at least one permission in response to granting the first demand and further in response to the at least one permission satisfying one or more predetermined conditions; and

performing, during the execution of the application in the runtime module, a second stack walk in response to a second runtime call into a second one of the plurality of sequential stack frames in the call stack including a second demand that requests the at least one permission, wherein the second stack walk includes:

evaluating the plurality of sequential stack frames in the call stack from the second stack frame that includes the second demand for the at least one permission to the first stack frame that includes the assertion for the at least one permission; and

granting the second demand for the at least one permission in response to all of the stack frames evaluated in the call second stack walk satisfying the at least one permission.

2. The method of claim 1 , wherein promoting the first demand for the at least one permission into the assertion for the at least one permission results in the second stack walk not having to evaluate the stack frames evaluated in the first stack walk.

3. The method of claim 1 , wherein the first stack walk and the second stack walk further include determining that the at least one permission satisfies the one or more predetermined conditions in response to determining that the at least one permission is declarative and static.

4. The method of claim 3 , wherein the first stack walk and the second stack walk further include determining that the at least one permission does not satisfy the one or more predetermined conditions in response to determining that the at least one permission is not declarative or not static.

5. The method of claim 1 , wherein the runtime module executes the application within a virtual machine executing on the computer.

6. The method of claim 1 , wherein the computer receives the application that executes in the runtime module over a network connection that links the computer to an application server.

7. The method of claim 1 , wherein:

the first stack walk further includes creating a first security exception in response to at least one of the stack frames evaluated in the first stack walk not satisfying the at least one permission; and

the second stack walk further includes creating a second security exception in response to at least one of the stack frames evaluated in the second stack walk not satisfying the at least one permission.

8. The method of claim 1 , wherein the second stack walk further includes promoting the second demand for the at least one permission into a second assertion for the at least one permission in response to granting the second demand and further in response to the at least one permission satisfying the one or more predetermined conditions.

9. The method of claim 8 , further comprising performing, during the execution of the application in the runtime module, one or more subsequent stack walks in response to one or more subsequent runtime calls into subsequent ones of the plurality of sequential stack frames in the call stack including subsequent demands that request the at least one permission.

10. The method of claim 9 , wherein promoting the second demand for the at least one permission into the second assertion for the at least one permission results in the subsequent stack walks not having to evaluate the stack frames evaluated in the first stack walk and the second stack walk.

11. A system for dynamic optimizations using security assertions, comprising:

a computer configured to receive a request to execute an application that includes a call stack having a plurality of sequential stack frames;

a runtime module that executes the application on the computer with code access security, wherein the runtime module is configured to:

perform, during the execution of the application in the runtime module, a first stack walk in response to a first runtime call into a first one of the plurality of sequential stack frames in the call stack including a first demand that requests at least one permission, wherein the first stack walk includes:

evaluating the plurality of sequential stack frames in the call stack from the first stack frame that includes the first demand to a bottom of the call stack;

granting the first demand for the at least one permission in response to all of the stack frames evaluated in the call first stack walk satisfying the at least one permission; and

promoting the first demand for the at least one permission into an assertion for the at least one permission in response to granting the first demand and further in response to the at least one permission satisfying one or more predetermined conditions; and

perform, during the execution of the application in the runtime module, a second stack walk in response to a second runtime call into a second one of the plurality of sequential stack frames in the call stack including a second demand that requests the at least one permission, wherein the second stack walk includes:

evaluating the plurality of sequential stack frames in the call stack from the second stack frame that includes the second demand for the at least one permission to the first stack frame that includes the assertion for the at least one permission; and

granting the second demand for the at least one permission in response to all of the stack frames evaluated in the call second stack walk satisfying the at least one permission.

12. The system of claim 11 , wherein promoting the first demand for the at least one permission into the assertion for the at least one permission results in the second stack walk not having to evaluate the stack frames evaluated in the first stack walk.

13. The system of claim 11 , wherein the first stack walk and the second stack walk further include determining that the at least one permission satisfies the one or more predetermined conditions in response to determining that the at least one permission is declarative and static.

14. The system of claim 13 , wherein the first stack walk and the second stack walk further include determining that the at least one permission does not satisfy the one or more predetermined conditions in response to determining that the at least one permission is not declarative or not static.

15. The system of claim 11 , further comprising a virtual machine executing on the computer, wherein the runtime module executes the application within the virtual machine.

16. The system of claim 11 , wherein the computer receives the application that executes in the runtime module over a network connection that links the computer to an application server.

17. The system of claim 11 , wherein:

the first stack walk further includes creating a first security exception in response to at least one of the stack frames evaluated in the first stack walk not satisfying the at least one permission; and

the second stack walk further includes creating a second security exception in response to at least one of the stack frames evaluated in the second stack walk not satisfying the at least one permission.

18. The system of claim 11 , wherein the second stack walk further includes promoting the second demand for the at least one permission into a second assertion for the at least one permission in response to granting the second demand and further in response to the at least one permission satisfying the one or more predetermined conditions.

19. The system of claim 18 , wherein the runtime module is further configured to perform, during the execution of the application in the runtime module, one or more subsequent stack walks in response to one or more subsequent runtime calls into subsequent ones of the plurality of sequential stack frames in the call stack including subsequent demands that request the at least one permission.

20. The system of claim 19 , wherein promoting the second demand for the at least one permission into the second assertion for the at least one permission results in the subsequent stack walks not having to evaluate the stack frames evaluated in the first stack walk and the second stack walk.

Assignments (12)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2016
From: EMC CORPORATION
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 040203/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 6, 2011
From: NOVELL, INC.
To: CPTN HOLDINGS, LLC
Reel/Frame 027169/0200 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 2, 2011
From: CPTN HOLDINGS LLC
To: EMC CORPORATON
Reel/Frame 027016/0160 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 26, 2006
From: POULIOT, SEBASTIEN
To: NOVELL, INC.
Reel/Frame 018092/0349 →
Continuity (1)
Related Publication 20080028461A1 · Jan 31, 2008