Policy-driven kernel-based security implementation
First Claim
1. A method of improving security processing in a computing network, comprising steps of:
- providing security processing in an operating system kernel;
providing an application program which makes use of the operating system kernel during execution;
providing security policy information;
executing the application program; and
selectably securing at least one communication of the executing application program using the provided security processing in the operating system kernel, under conditions specified by the security policy information.
2 Assignments
0 Petitions
Accused Products
Abstract
Improvements in security processing are disclosed which enable security processing to be transparent to the application. Security processing (such as Secure Sockets Layer, or “SSL”, or Transport Layer Security, or “TLS”) is performed in (or controlled by) the stack. A decision to enable security processing on a connection can be based on configuration data or security policy, and can also be controlled using explicit enablement directives. Directives may also be provided for allowing applications to communicate with the security processing in the stack for other purposes. Functions within the protocol stack that need access to clear text can now be supported without loss of security processing capability. No modifications to application code, or in some cases only minor modifications (such as inclusion of code to invoke directives), are required to provide this security processing. Improved offloading of security processing is also disclosed, which provides processing efficiencies over prior art offloading techniques.
45 Citations
18 Claims
-
1. A method of improving security processing in a computing network, comprising steps of:
-
providing security processing in an operating system kernel;
providing an application program which makes use of the operating system kernel during execution;
providing security policy information;
executing the application program; and
selectably securing at least one communication of the executing application program using the provided security processing in the operating system kernel, under conditions specified by the security policy information. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16)
-
-
17. A system for improving security processing in a computing network, comprising:
-
means for performing security processing in an operating system kernel;
security policy information specifying one or more conditions under which the means for performing security processing is to be activated;
means for executing an application program which makes use of the operating system kernel during execution; and
means for selectably securing, according to the conditions specified by the security policy information, at least one communication of the executing application program using the means for performing security processing.
-
-
18. A computer program product for improving security processing in a computing network, the computer program product embodied on one or more computer-readable media and comprising:
-
computer-readable program code means for performing security processing in an operating system kernel;
computer-readable program code means for accessing security policy information, the security policy information specifying one or more conditions under which the computer-readable program code means for performing security processing is to be activated;
computer-readable program code means for executing an application program which makes use of the operating system kernel during execution; and
computer-readable program code means for selectably securing, according to the conditions specified by the security policy information, at least one communication of the executing application program using the computer-readable program code means for performing security processing.
-
Specification