Patent · US Active

Request context generator for security policy validation service

US10922423B1 · kind B1 · utility

20Cited by
7References
20Claims
0Family size

Assignee

Inventors

Key dates

Filing dateJun 21, 2018
Grant dateFeb 16, 2021
Priority date
Expiry dateApr 20, 2039

Classification

  • Technology area (CPC G)Physics
  • CPC primaryG06F2221/034
  • WIPO fieldComputer technology
  • WIPO sectorElectrical engineering

Abstract

A security policy analyzer service of a computing resource service provider performs evaluations of security policies provided by the service provider's users, to determine whether the security policies are valid, satisfiable, accurate, and/or sufficiently secure. The service may compare the user-provided policy to a stored or best-practices policy to begin the evaluation, translating encoded security permissions into propositional logic formulae that can be compared to determine which policy is more permissive. The service determines values of the parameters in a request for access to a computing resource based on the policy comparison, and generates request contexts using the values. The service uses the request contexts to generate one or more comparative policies that are then used iteratively as the second policy in the comparison to the user-provided policy, in order to produce additional request contexts that represent allow/deny “edge cases” along the borders of policy permission statements.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.