IP Library Granted Patent US 8,438,610
Granted Patent B2
US 8,438,610 · App. 11/863,392 · Granted May 7, 2013

Identity-based address normalization

Inventors: Jason Allen Sabin (Lehi, UT); Stephen R. Carter (Spanish Fork, UT)
Assignee: EMC Corporation
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,438,610
App. No.
11/863,392
Filed
Sep 28, 2007
Granted
May 7, 2013
Kind
B2
Art Unit
2491
USPC
726/1
Abstract

In various embodiments, techniques for identity-based address normalization are provided. A principal attempts to access a resource via a principal-supplied address. A principal identity for the principal is used to acquire one or more address patterns. The principal-supplied address is compared against the one or more address patterns and when a match is detected, the principal-supplied address is normalized according to policy associated with the matched pattern. Additional access limitations and security restrictions are then enforced in response to the normalized address.

Claims (47)

1. A machine-implemented method residing in a non-transitory machine-readable medium and to execute on a machine, comprising:

receiving, by the machine, an electronic address for accessing a resource, the electronic address is received from a principal for purposes of gaining access to the resource;

resolving, by the machine, a resource identity for the resource and a principal identity for the principal;

determining, by the machine, a set of patterns that the electronic address can be represented as based on the resource identity and the principal identity, the set of patterns are identity-based and determined based on the resource identity and the principal identity, and the set of patterns include constant and hard coded information along with variable and regular expression information, one or more of said patterns being dynamically defined in real time;

attempting, by the machine, to match the electronic address against the set of patterns when policy dictates;

normalizing, by the machine, the electronic address in response to a matched pattern into a normalized address, the normalized address is to a location for the principal to retrieve the resource based on the principal identity and the resource identity;

querying the address pattern repository using the principal identity for the principal and the resource identity for the resource; and

enforcing, by the machine, one or more actions against the principal before directing the principal to the resource for access in response to the normalized address, the normalized address permits designated services to process the one or more actions before the principal accesses the resource via the location identified in the normalized address and the designated services customized based on the principal identity and the resource identity and the one or more actions affect security to access the resource, auditing with respect to accessing the resource, and load balancing for the resource when the resource is accessed at the location.

2. The method of claim 1 , wherein receiving further includes receiving the electronic address via a WWW browser in response to a principal supplied or activated link, within the WWW browser, representing a Uniform Resource Locator (URL) link or Universal Resource Identifier (URI) link.

3. The method of claim 1 , wherein receiving further includes receiving the electronic address in response to a Hypertext Transfer Protocol (HTTP) command or a File Transfer Protocol (FTP) command issued from the principal to access the resource.

4. The method of claim 1 , wherein resolving further includes consulting a remote identity service to supply authentication services or identity-resolution services for resolving the resource identity and the principal identity.

5. The method of claim 1 , wherein said determining comprises dynamically defining said one or more address patterns in real time by an administrator, and further includes accessing a pattern repository with at least one of the resource identity and the principal identity to acquire the set of patterns.

6. The method of claim 1 , wherein attempting further includes bypassing the matching when the policy permits for the principal and in response to the principal identity for the principal and considering the principal supplied electronic address to be matched and the normalized address.

7. The method of claim 1 , wherein attempting further includes bypassing the matching when the policy permits for the resource and in response to the resource identity and considering the principal supplied electronic address to be matched and the normalized address.

8. A machine-implemented method residing in a non-transitory machine-readable medium and to execute on a machine, comprising:

acquiring, by the machine, an address pattern for referencing a resource, wherein the address pattern is tied and customized to a principal identity for a principal attempting to access the resource and tied and customized to a resource identity for the resource and the address pattern includes constant and hard coded information along with variable and regular expression information, said address pattern being dynamically defined in real time;

matching, by the machine, the address pattern to an electronic address supplied by the principal, wherein the principal is attempting to access the resource and the matching to the address pattern occurs based on and customized to the principal identity and the resource identity;

normalizing, by the machine, the electronic address to a normalized address for the resource customized to and based on the principal identity and the resource identity, the normalized address being to a location for the principal to retrieve the resource based on the principal identity and the resource identity;

querying an address pattern repository using the principal identity for the principal and the resource identity for the resource; and

routing, by the machine, the principal to the resource via the normalized address and processing one or more designated services before the principal accesses the resource, the one or more designated services affect security with respect to accessing the resource, auditing with respect to accessing the resource, and load balancing when accessing the resource.

9. The method of claim 8 , wherein acquiring further includes interacting with an administrator via a graphical user interface to receive the address pattern as the regular expression that defines the address pattern, said administrator defining the address pattern in real time.

10. The method of claim 9 further comprising, dynamically updating, by the machine, a repository of patterns with the address pattern when the administrator commits the address pattern for update.

11. The method of claim 8 , wherein matching further includes using a set of additional patterns to compare against the electronic address before matching the electronic address to the address pattern.

12. The method of claim 8 , wherein normalizing further includes receiving the modification instructions for producing the normalized address from the resource.

13. The method of claim 8 , wherein normalizing further includes receiving modification instructions for producing the normalized address from a policy decision point service.

14. The method of claim 8 , wherein normalizing further includes altering, modifying, or editing a path associated with the electronic address to produce the normalized address.

15. A machine-implemented method residing in a non-transitory machine-readable medium and to execute on a machine, comprising:

intercepting, by the machine, a Uniform Resource Locator (URL) address supplied by a principal and directed to a resource;

acquiring, by the machine, a principal identity for the principal and a resource identity for the resource that the principal is attempting to access via the URL address;

normalizing the URL address to a normalized address for the principal to retrieve the resource based upon the principal identity and the resource identity;

querying an address pattern repository using the principal identity for the principal and the resource identity for the resource;

accessing, by the machine, the address pattern repository in response to the principal identity and the resource identity to acquire a set of candidate patterns for references made to the resource, the candidate patterns being customized based on the principal identity and the resource identity and each of the candidate patterns includes constant and hard coded information along with variable and regular expression information, one or more of said candidate patterns being dynamically defined in real time;

comparing, by the machine, the set of candidate patterns against the URL address supplied by the principal;

matching, by the machine, a particular pattern to the URL address, the particular pattern being customized based on the principal identity and the resource identity;

processing, by the machine, an action in response to the particular pattern matched, the action processed when the principal uses the particular pattern to access the resource and before the principal is given access to the resource and the action affects security when accessing the resource.

16. The method of claim 15 further comprising, processing, by the machine, the method as a reverse proxy service for the resource.

17. The method of claim 15 , wherein acquiring further includes asking an identity service to supply and verify the principal identity and the resource identity.

18. The method of claim 15 , wherein accessing further includes dynamically obtaining at least one pattern in the set of patterns from an administrator in real-time, and wherein said administrator defines said one or more address patterns.

19. The method of claim 15 , wherein processing further includes normalizing the URL address and enforcing access restrictions in response to a normalized URL address.

20. The method of claim 15 , wherein processing further includes assigning access privileges to the resource in response to the principal identity.

21. A machine-implemented system, comprising:

an address pattern repository implemented in a non-transitory machine-accessible and readable medium and accessible to an address normalization service that processes address patterns included in the address pattern repository, the address patterns including constant and hard coded information along with variable and regular expression information, one or more of said address patterns being dynamically defined in real time; and

the address normalization service implemented in a non-transitory machine-accessible and readable medium to process on a machine, wherein the address normalization service is to process principal supplied addresses for resources by querying the address pattern repository using principal identities for the principals and resource identities for the resources to acquire selective and customized address patterns based on the principal identities and the resource identities, the customized address patterns are then attempted to be matched to the principal supplied addresses and when matches occur the principal supplied addresses are normalized into normalized addresses and policies applied before the principals are forwarded to the resources associated with the normalized addresses, the normalized addresses being to locations for a principal to retrieve a resource based on the principal identity and the resource identity, the normalized addresses and policies are customized based on the principal identities and the resource identities and when a particular principal uses a particular normalized address to access a particular resource a particular policy is enforced and one or more designated services are processed before access is given to the particular resource.

22. The system of claim 21 further comprising, an identity service that supplies or verifies the principal identities on behalf of the address normalization service, the identity service implemented and residing in a non-transitory machine-readable medium and to execute on the machine.

23. The system of claim 21 , wherein at least some of said one or more address patterns are dynamically defined in real time by an administrator via a graphical user interface and dynamically updated to the address pattern repository and dynamically made available to the address normalization service.

24. The system of claim 21 , wherein at least one policy assigns access rights to the resources or assigns roles to the principals for accessing the resources.

25. The system of claim 21 , wherein the principal supplied addresses are received via a World-Wide Web (WWW) browser as Uniform Resource Locator (URL) references or Universal Resource Identifier (URI) references.

Assignments (12)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2016
From: EMC CORPORATION
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 040203/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 6, 2011
From: NOVELL, INC.
To: CPTN HOLDINGS, LLC
Reel/Frame 027169/0200 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 2, 2011
From: CPTN HOLDINGS LLC
To: EMC CORPORATON
Reel/Frame 027016/0160 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 12, 2007
From: SABIN, JASON ALLEN; CARTER, STEPHEN R
To: NOVELL INC
Reel/Frame 019960/0734 →
Continuity (1)
Related Publication 20090089857A1 · Apr 2, 2009