IP Library Granted Patent US 8,429,412
Granted Patent B2
US 8,429,412 · App. 12/963,486 · Granted Apr 23, 2013

Method to control access between network endpoints based on trust scores calculated from information system component analysis

Inventors: David Maurits Bleckmann (Portland, OR); William Wyatt Starnes (Portland, OR); Bradley Douglas Andersen (Tigard, OR)
Assignee: SignaCert, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,429,412
App. No.
12/963,486
Granted
Apr 23, 2013
Kind
B2
Abstract

Signatures are generated for modules in a computer system. The signatures can be assembled into an integrity log. The signatures are compared with signatures in a database in an integrity validator. Once signatures are either validated or invalidated, a trust score can be generated. The trust score can then be used to determine whether the computer system should be granted access to a resource using a policy.

Claims (22)

1. An apparatus ( 140 , 160 ), comprising:

a database ( 205 ) storing a plurality of signatures for a plurality of modules;

a receiver ( 210 ) to receive a signature for a module over a network from a separate device; and

a validator ( 220 ) to validate the signature if the signature for said module matches at least one of the plurality of signatures in the database ( 205 ).

2. An apparatus ( 140 , 160 ) according to claim 1 , further comprising a transmitter ( 215 ) to forward the signature to a second apparatus ( 140 , 160 ) for validation by the second apparatus ( 140 , 160 ) if the signature does not match at least one of the plurality of signatures in the database ( 205 ).

3. A method, comprising:

receiving ( 505 ) a signature for a module over a network from a separate device;

comparing ( 510 ) the signature with a plurality of signatures in a database ( 205 ); and

if the signature matches at least one of the plurality of signatures in the database ( 205 ), validating ( 520 ) the signature.

4. A method according to claim 3 , wherein:

receiving ( 505 ) a signature for a module includes receiving ( 505 ) an identifier for the module; and

comparing ( 510 ) the signature with a plurality of signatures in a database ( 205 ) includes:

identifying a first signature in the database ( 205 ) using the identifier for the module; and

comparing ( 510 ) the signature with the first signature.

5. A method according to claim 3 , further comprising, if the signature does not match at least one of the plurality of signatures in the database ( 205 ), forwarding the signature to a second database for validation of the signature.

6. An apparatus according to claim 1 , wherein:

the receiver ( 210 ) is operative to receive at least two signatures for two modules from two computer systems ( 105 ); and

the validator ( 220 ) to validate each of the at least two signatures if each of the at least two signatures for said two modules matches at least one of the plurality of signatures in the database ( 205 ).

7. A method according to claim 3 , wherein:

receiving ( 505 ) a signature for a module over a network from a separate device includes receiving at least two signatures for two modules over the network from two separate devices;

comparing ( 510 ) the signature with a plurality of signatures in a database ( 205 ) includes comparing each of the at least two signatures for the two modules with the plurality of signatures in the database ( 205 ); and

validating ( 520 ) the signature includes, if each of the at least two signatures matches at least one of the plurality of signatures in the database ( 205 ), validating each of the at least two signatures.

Assignments (8)
SECURITY INTEREST Recorded Jul 7, 2016
From: FORTRESS CREDIT CO LLC
To: FORTRESS CREDIT OPPORTUNITIES I LP
Reel/Frame 039104/0979 →
SECURITY INTEREST Recorded Jul 7, 2016
From: FORTRESS CREDIT CO LLC
To: FORTRESS CREDIT OPPORTUNITIES I LP
Reel/Frame 039104/0946 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 13, 2015
From: SIGNACERT, INC
To: KIP SIGN P1 LP
Reel/Frame 034700/0842 →
SECURITY INTEREST Recorded Jan 13, 2015
From: KIP SIGN P1 LP
To: FORTRESS CREDIT CO LLC
Reel/Frame 034701/0170 →
SECURITY INTEREST Recorded Jan 13, 2015
From: SIGNACERT, INC
To: FORTRESS CREDIT CO LLC
Reel/Frame 034700/0390 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 13, 2013
From: HARRIS CORPORATION
To: SIGNACERT, INC.
Reel/Frame 029804/0310 →
SECURITY AGREEMENT Recorded Dec 13, 2012
From: SIGNACERT, INC.
To: HARRIS CORPORATION
Reel/Frame 029467/0639 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 28, 2011
From: SIGNACERT, INC.
To: HARRIS CORPORATION
Reel/Frame 026195/0473 →
Continuity (7)
Continuation 12363945 · Feb 2, 2009
Continuation 11832781 · Aug 2, 2007
Continuation 11288820 · Nov 28, 2005
Provisional Application 60631449 · Nov 29, 2004
Provisional Application 60631450 · Nov 29, 2004
Provisional Application 60637066 · Dec 17, 2004
Related Publication 20110078452A1 · Mar 31, 2011