IP Library Granted Patent US 7,487,358
Granted Patent B2
US 7,487,358 · App. 11/832,781 · Granted Feb 3, 2009

Method to control access between network endpoints based on trust scores calculated from information system component analysis

Assignee: SignaCert, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,487,358
App. No.
11/832,781
Granted
Feb 3, 2009
Kind
B2
Abstract

Signatures are generated for modules in a computer system. The signatures can be assembled into an integrity log. The signatures are compared with signatures in a database in an integrity validator. Once signatures are either validated or invalidated, a trust score can be generated. The trust score can then be used to determine whether the computer system should be granted access to a resource using a policy.

Claims (23)

1. A storage medium having stored thereon instructions that, when executed by a machine, result in:

receiving ( 705 ) a first plurality of signatures corresponding to a plurality of modules in a machine;

comparing ( 715 , 720 ) the first plurality of signatures for the plurality of modules with a second plurality of signatures in a database ( 205 );

identifying ( 725 ) a first subset of the plurality of modules for which the corresponding signatures are found in the database ( 205 ) and ( 730 ) a second subset of the plurality of modules for which the corresponding signatures are not found in the database ( 205 ); and

generating ( 740 ) a trust score for the machine based on the first subset of the plurality of modules for which the corresponding signatures are found in the database ( 205 ) and a second subset of the plurality of modules for which the corresponding signatures are not found in the database ( 205 ).

2. A storage medium according to claim 1 , wherein said storage medium has stored thereon further instructions that, when executed by the machine, result in controlling ( 810 , 815 , 820 ) access to a resource ( 145 ) on a network ( 110 , 135 ) based on the trust score.

3. A storage medium according to claim 2 , wherein controlling ( 810 , 815 , 820 ) access to a resource ( 145 ) on a network ( 110 , 135 ) based on the trust score includes:

accessing ( 810 ) a policy ( 230 ) for access to the resource ( 145 ) on the network ( 110 , 135 ); and

using ( 820 ) the policy ( 230 ) to control access to the resource ( 145 ) based on the trust score.

4. A storage medium according to claim 3 , wherein using ( 820 ) the policy ( 230 ) to control access to the resource ( 145 ) based on the trust score includes granting full access to the resource ( 145 ) if the trust score exceeds a threshold score ( 235 , 240 ) according to the policy ( 230 ).

5. A storage medium according to claim 3 , wherein using ( 820 ) the policy ( 230 ) to control access to the resource ( 145 ) based on the trust score includes granting partial access to the resource ( 145 ) if the trust score is higher than a first threshold score ( 235 , 240 ) but lower than a second threshold score ( 235 , 240 ) according to the policy ( 230 ).

6. A storage medium according to claim 3 , wherein using ( 820 ) the policy ( 230 ) to control access to the resource ( 145 ) based on the trust score includes denying access to the resource ( 145 ) if the trust score is lower than a threshold score ( 235 , 240 ) according to the policy ( 230 ).

7. A storage medium according to claim 1 , wherein generating ( 740 ) a trust score includes weighting generating ( 740 ) at least a first module more highly than at least a second module in generating the trust score.

8. A storage medium according to claim 1 , wherein receiving ( 705 ) a first plurality of signatures includes receiving an integrity log including the first plurality of signatures corresponding to the plurality of modules.

9. A storage medium according to claim 1 , wherein:

wherein said storage medium has stored thereon further instructions that, when executed by the machine, result in:

forwarding ( 535 ) the signatures corresponding to the second subset of the plurality of modules for which the corresponding signatures are not found in the database ( 205 ) to a second database ( 205 ) of signatures; and

receiving from the second database ( 205 ) a third subset of the plurality of modules for which the corresponding signatures are found in the second database ( 205 ) and a fourth subset of the plurality of modules for which the corresponding signatures are not found in the second database ( 205 ); and

generating ( 740 ) a trust score includes generating ( 740 ) the trust score based on the first subset of the plurality of modules for which the corresponding signatures are found in the database ( 205 ) and the third subset of the plurality of modules for which the corresponding signatures are found in the third database ( 205 ).

10. A storage medium according to claim 1 , wherein:

receiving ( 705 ) a first plurality of signatures corresponding to a plurality of modules includes receiving ( 705 ) the first plurality of signatures and a plurality of identifiers for the plurality of modules; and

comparing ( 715 , 720 ) the first plurality of signatures for the plurality of modules with a second plurality of signatures in a database ( 205 ) includes comparing ( 715 , 720 ) the first plurality of signatures for the plurality of modules with the second plurality of signatures in the database ( 205 ) using the plurality of identifiers for the plurality of modules.

11. An article according to claim 1 , wherein said storage medium has stored thereon further instructions that, when executed by the machine, result in transmitting the trust score to the machine.

Assignments (9)
SECURITY INTEREST Recorded Jul 7, 2016
From: FORTRESS CREDIT CO LLC
To: FORTRESS CREDIT OPPORTUNITIES I LP
Reel/Frame 039104/0979 →
SECURITY INTEREST Recorded Jul 7, 2016
From: FORTRESS CREDIT CO LLC
To: FORTRESS CREDIT OPPORTUNITIES I LP
Reel/Frame 039104/0946 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 13, 2015
From: SIGNACERT, INC
To: KIP SIGN P1 LP
Reel/Frame 034700/0842 →
SECURITY INTEREST Recorded Jan 13, 2015
From: KIP SIGN P1 LP
To: FORTRESS CREDIT CO LLC
Reel/Frame 034701/0170 →
SECURITY INTEREST Recorded Jan 13, 2015
From: SIGNACERT, INC
To: FORTRESS CREDIT CO LLC
Reel/Frame 034700/0390 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 13, 2013
From: HARRIS CORPORATION
To: SIGNACERT, INC.
Reel/Frame 029804/0310 →
SECURITY AGREEMENT Recorded Dec 13, 2012
From: SIGNACERT, INC.
To: HARRIS CORPORATION
Reel/Frame 029467/0639 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 28, 2011
From: SIGNACERT, INC.
To: HARRIS CORPORATION
Reel/Frame 026195/0473 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 23, 2009
From: BLECKMANN, DAVID MAURITS; STARNES, WILLIAM WYATT; ANDERSEN, BRADLEY DOUGLAS
To: SIGNACERT, INC.
Reel/Frame 023691/0652 →
Continuity (5)
Continuation 1128882000 · Nov 28, 2005
Provisional Application 6063144900 · Nov 29, 2004
Provisional Application 6063145000 · Nov 29, 2004
Provisional Application 6063706600 · Dec 17, 2004
Related Publication 20070271462A1 · Nov 22, 2007