PROCESS FOR TRANSPARENTLY ENFORCING PROTECTION DOMAINS AND ACCESS CONTROL AS WELL AS AUDITING OPERATIONS IN SOFTWARE COMPONENTS
Patent №
US 6,317,868
Granted
2001-11-13
Filed 1998
Owner
WASHINGTON, UNIVERSITY OF
+1 more
Lab
—
AI components
3
kr · planning · hardware
Assignment
Recorded
Dataset
AIPD
2023_r1 edition
Application
09168125
An original software component is modified in accordance with a site's security policy provisions prior to being executed by a component system or computer at the site. The original software component is intercepted by an introspection service running on a server or on the component system prior to execution on the component system. The introspection service analyzes the software component by parsing it, and based on the information it determines, a security policy service instructs an interposition service how to modify the software component so that it conforms to the security policy service requirements. The interposition service thus produces a modified software component by inserting code for security initialization and for imposing security operations on the original component operations. When the modified software component is executed, an enforcement service follows the security operations that were injected into the software component, which instruct the enforcement service on associating component system objects with security identifiers. For example, a security identifier is associated with the software component. In addition, the enforcement service determines when and how to perform access checks, protection domain transfers, and auditing during execution of the modified software component. Any of the services noted above can be executed by the computer intended to execute the software component or by a separate server.
AI classification
Ownership
WASHINGTON, UNIVERSITY OF
assignment · 96750202
UNIVERSITY OF WASHINGTON
assignment · 96750204
Assignors
BERSHAD, BRIAN N.
On an employer assignment, the assignors are typically the inventors.