US2008295181A1PendingUtilityA1

Method for protecting computer programs and data from hostile code

Assignee: DOTAN EYALPriority: Jan 19, 2001Filed: Apr 21, 2008Published: Nov 27, 2008
Est. expiryJan 19, 2021(expired)· nominal 20-yr term from priority
Inventors:Eyal Dotan
G06F 21/52G06F 21/54G06F 21/6218G06F 2221/2141G06F 21/57G06F 21/604G06F 2221/2145
51
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method that protects computer data from untrusted programs. Each computer's object and process is assigned with trust attributes, which define the way it can interact with other objects within the system. The trust attributes are defined hierarchically so that processes cannot access objects with higher trust levels than themselves. When accessing objects with lower trust levels, processes can see their trust levels lowered to that of the object accessed. The interaction between processes and objects of different levels is entirely programmable.

Claims

exact text as granted — not AI-modified
1 . A process for protecting a computer from hostile code, comprising the steps of:
 defining at least two trust groups;   assigning objects and processes in the computer to one of said trust groups, irrespective of the rights of a user of said computer;   upon operation of a process over an object or over a second process, comparing a trust group of the process with a trust group of the object or with the trust group of the second process, and   allowing the operation according to the results of said comparing step.   
   
   
       2 . The process of  claim 1  wherein a process is assigned upon creation to the trust group assigned to the passive code starting from which the process is created. 
   
   
       3 . The process of  claim 1  further comprising the step of changing the trust group of said process after said operation. 
   
   
       4 . The process of  claim 1  further comprising the step of changing the trust group of said object or of said second process after said operation. 
   
   
       5 . The process of  claim 1  further comprising, upon creation of an object by a process, the step of assigning said created object to the trust group of said process. 
   
   
       6 . The process of  claim 1  further comprising, when said operation is allowed, the step of assigning said process to the trust group of said object or of said second process. 
   
   
       7 . The process of  claim 1  wherein said trust groups are hierarchically ordered, and wherein the step of allowing further comprises: allowing said operation when the trust group of said process is higher or equal in said hierarchy than the trust group of said object or of said second process; and denying said operation when the trust group of said process is lower in said hierarchy than the trust group of said object or of said second process. 
   
   
       8 . The process of  claim 7  further comprising the step of assigning said process to the trust group of said object or of said second process after the operation is allowed. 
   
   
       9 . The process of  claim 1  further comprising: defining at least two types of objects; assigning objects to one of said types; and wherein the step of allowing operation over an object is further carried out according to the type of said object. 
   
   
       10 . The process of  claim 1  further comprising: defining at least two types of processes; assigning processes to one of said types, and wherein the step of allowing operation of a process is further carried out according to the type of said process. 
   
   
       11 . The process of  claim 1 , further comprising: defining at least two types of operations; and wherein the step of allowing operation of a process over an object or over a second process is further carried out according to the type of said operation. 
   
   
       12 . The process of  claim 1 , further comprising: defining at least two types of storage methods, assigning a trust group to a type of storage methods; and carrying out a storage operation for a process of a trust group according to the storage method assigned to the trust group of said process. 
   
   
       13 . A computer comprising: objects and processes; a table of at least two trust groups, and objects and processes in the computer being assigned to one of said trust groups irrespective of the rights of a user of said computer; and a controller configured to access said table and allow an operation of a process over an object or over a second process according to the results of a comparison of the trust group of said process and the trust group of said object or the trust group of said second process. 
   
   
       14 . The computer of  claim 13  further comprising: a table of types of at least two types of objects, the objects in the computer being assigned one type; and wherein the controller accesses said table for allowing said operation. 
   
   
       15 . The computer of  claim 13 , wherein said table of trust groups is stored in a non-volatile memory. 
   
   
       16 . The computer of  claim 13 , wherein said table of types is stored in a non-volatile memory. 
   
   
       17 . The computer of  claim 13 , further comprising a table of rules, and wherein said controller accesses said table of rules. 
   
   
       18 . The computer of  claim 13 , wherein said table of rules is stored in a non-volatile memory. 
   
   
       19 . The computer of  claim 13 , wherein the computer is operatively coupled to a network, the network including a server, the table of trust groups stored in said server. 
   
   
       20 . A computer according to  claim 19 , wherein said table of types is stored in said server. 
   
   
       21 . A computer according to  claim 19 , wherein said table of rules is stored in said server.

Join the waitlist — get patent alerts

Track US2008295181A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.