Patents by Inventor Daniel Kroening
Daniel Kroening has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).
-
Publication number: 20240314134Abstract: Methods, systems, and computer-readable media for analysis of role reachability with transitive tags are disclosed. An access control analyzer determines a graph including nodes and edges. The nodes represent roles in a provider network hosting resources. The roles are associated with access control policies granting or denying access to individual resources. One or more of the access control policies grant or deny access based (at least in part) on key-value attributes. The access control analyzer determines, based (at least in part) on a role reachability analysis of the graph, whether a first role can assume a second role using role assumption steps for a particular state of the attributes. The attributes may include transitive attributes that persist during the role assumption steps.Type: ApplicationFiled: May 24, 2024Publication date: September 19, 2024Applicant: Amazon Technologies, Inc.Inventors: John Byron Cook, Neha Rungta, Carsten Varming, Daniel George Peebles, Daniel Kroening, Alejandro Naser Pastoriza
-
Patent number: 12034727Abstract: Methods, systems, and computer-readable media for analysis of role reachability with transitive tags are disclosed. An access control analyzer determines a graph including nodes and edges. The nodes represent roles in a provider network hosting resources. The roles are associated with access control policies granting or denying access to individual resources. One or more of the access control policies grant or deny access based (at least in part) on key-value attributes. The access control analyzer determines, based (at least in part) on a role reachability analysis of the graph, whether a first role can assume a second role using role assumption steps for a particular state of the attributes. The attributes may include transitive attributes that persist during the role assumption steps.Type: GrantFiled: December 11, 2020Date of Patent: July 9, 2024Assignee: Amazon Technologies, Inc.Inventors: John Byron Cook, Neha Rungta, Carsten Varming, Daniel George Peebles, Daniel Kroening, Alejandro Naser Pastoriza
-
Patent number: 11757886Abstract: Methods, systems, and computer-readable media for analysis of role reachability using policy complements are disclosed. An access control analyzer determines two nodes in a graph that potentially have a common edge. The nodes correspond to roles in a provider network, and the roles are associated with first and second access control policies that grant or deny access to resources. The access control analyzer performs a role reachability analysis that determines whether the first role can assume the second role for a particular state of one or more key-value tags. The role reachability analysis determines a third access control policy authorizing a negation of a role assumption request for the second role. The role reachability analysis performs analysis of the third access control policy with respect to a role assumption policy for the second role for the particular state of the one or more key-value tags.Type: GrantFiled: December 11, 2020Date of Patent: September 12, 2023Assignee: Amazon Technologies, Inc.Inventors: John Byron Cook, Neha Rungta, Carsten Varming, Daniel George Peebles, Daniel Kroening, Alejandro Naser Pastoriza
-
Patent number: 11442845Abstract: A computer-implemented method comprising obtaining a first candidate test associated with a testable component, wherein the first candidate test comprises an input having an input value; generating a second candidate test associated with the testable component by performing a dynamic mutation-based fuzzing of the first candidate test, wherein the second candidate test is based on the first candidate test and comprises a modified input value for the input based on data generated during an execution of the first candidate test or domain knowledge associated with the testable component; and creating a test for the testable component based on the first candidate test or the second candidate test.Type: GrantFiled: December 7, 2020Date of Patent: September 13, 2022Assignee: DIFFBLUE LTDInventors: Peter Schrammel, Daniel Kroening
-
Publication number: 20220191205Abstract: Methods, systems, and computer-readable media for analysis of role reachability with transitive tags are disclosed. An access control analyzer determines a graph comprising a plurality of nodes and one or more edges. The nodes represent roles in a provider network hosting resources. The roles are associated with access control policies granting or denying access to individual resources. One or more of the access control policies grant or deny access based (at least in part) on one or more key-value attributes. The access control analyzer determines, based (at least in part) on a role reachability analysis of the graph, whether a first role can assume a second role using one or more role assumption steps for a particular state of the one or more attributes. The one or more attributes may comprise one or more transitive attributes that persist during the one or more role assumption steps.Type: ApplicationFiled: December 11, 2020Publication date: June 16, 2022Applicant: Amazon Technologies, Inc.Inventors: John Byron Cook, Neha Rungta, Carsten Varming, Daniel George Peebles, Daniel Kroening, Alejandro Naser Pastoriza
-
Publication number: 20220191206Abstract: Methods, systems, and computer-readable media for analysis of role reachability using policy complements are disclosed. An access control analyzer determines two nodes in a graph that potentially have a common edge. The nodes correspond to roles in a provider network, and the roles are associated with first and second access control policies that grant or deny access to resources. The access control analyzer performs a role reachability analysis that determines whether the first role can assume the second role for a particular state of one or more key-value tags. The role reachability analysis determines a third access control policy authorizing a negation of a role assumption request for the second role. The role reachability analysis performs analysis of the third access control policy with respect to a role assumption policy for the second role for the particular state of the one or more key-value tags.Type: ApplicationFiled: December 11, 2020Publication date: June 16, 2022Applicant: Amazon Technologies, Inc.Inventors: John Byron Cook, Neha Rungta, Carsten Varming, Daniel George Peebles, Daniel Kroening, Alejandro Naser Pastoriza
-
Publication number: 20220179776Abstract: A computer-implemented method comprising obtaining a first candidate test associated with a testable component, wherein the first candidate test comprises an input having an input value; generating a second candidate test associated with the testable component by performing a dynamic mutation-based fuzzing of the first candidate test, wherein the second candidate test is based on the first candidate test and comprises a modified input value for the input based on data generated during an execution of the first candidate test or domain knowledge associated with the testable component; and creating a test for the testable component based on the first candidate test or the second candidate test.Type: ApplicationFiled: December 7, 2020Publication date: June 9, 2022Inventors: Peter Schrammel, Daniel Kroening
-
Patent number: 7418680Abstract: A method to check correspondence between different representations of a circuit may include abstracting a first computer language representation of the circuit to form a first abstract model of the circuit and abstracting a second computer language representation of the circuit to form a second abstract model of the circuit. The method may also include forming a product machine using the first and second abstract models. The method may further include checking correspondence between the first and second abstract models using the product machine.Type: GrantFiled: May 6, 2005Date of Patent: August 26, 2008Assignee: Carnegie Mellon UniversityInventors: Edmund M. Clarke, Daniel Kroening
-
Patent number: 7225417Abstract: A method to verify a circuit design may include applying a bounded model checking technique to a first computer language representation of the circuit design and to a second computer language representation of the circuit design. The method may also include determining a behavioral consistency between the first and second computer language representations.Type: GrantFiled: February 5, 2004Date of Patent: May 29, 2007Assignee: Carnegie Mellon UniversityInventors: Edmund M. Clarke, Daniel Kroening, Karen Yorav
-
Publication number: 20050210433Abstract: A method to check correspondence between different representations of a circuit may include abstracting a first computer language representation of the circuit to form a first abstract model of the circuit and abstracting a second computer language representation of the circuit to form a second abstract model of the circuit. The method may also include forming a product machine using the first and second abstract models. The method may further include checking correspondence between the first and second abstract models using the product machine.Type: ApplicationFiled: May 6, 2005Publication date: September 22, 2005Inventors: Edmund Clarke, Daniel Kroening
-
Publication number: 20050071147Abstract: A method to verify a circuit design may include applying a bounded model checking technique to a first computer language representation of the circuit design and to a second computer language representation of the circuit design. The method may also include determining a behavioral consistency between the first and second computer language representations.Type: ApplicationFiled: February 5, 2004Publication date: March 31, 2005Inventors: Edmund Clarke, Daniel Kroening, Karen Yorav