US2012131635A1PendingUtilityA1
Method and system for securing data
Est. expiryNov 23, 2030(~4.3 yrs left)· nominal 20-yr term from priority
Inventors:Luis Huapaya
H04L 9/088H04L 9/0894G06F 21/602G06F 21/604
47
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
Disclosed is a method of supporting security policies and security levels associated with processes and applications. A security level is associated with a process independent of a user executing the process. When secure data is to be accessed, the security level of the process is evaluated to determine whether data access is to be granted. Optionally, the security level of a user of the process is also evaluated prior to providing data access.
Claims
exact text as granted — not AI-modified1 . A method comprising:
assigning a first privilege level to a first process, the first process in execution on a processor of a computer system, the first privilege level other than related to a privilege level of a user of the process or a group of the user; storing a first data file in a data store; requesting access to the first data file by the first process; evaluating the first privilege level of the first process by a second process, the second process in execution on the processor of the computer system and the second process for controlling access to file data by the first process; and in dependence upon the first privilege level of the first process, the second process is operable one of to provide access to the first data file stored in the data store to the first process and to deny access to the first data file stored in the data store to the first process.
2 . A method according to claim 1 wherein the data store is in data communication with the processor of the computer system via a communication network and wherein access to the first data file is provided via a communication network.
3 . A method according to claim 1 comprising:
providing access to the first data to the first process.
4 . A method according to claim 3 wherein the access provided is selected from a plurality of types of access supported by the system.
5 . A method according to claim 1 wherein the first data file comprises a system clipboard data file.
6 . A method according to claim 1 wherein the first data file is encrypted and wherein access to the first data file requires access to a decryption key associated with the first data file.
7 . A method according to claim 6 wherein the first data file is encrypted.
8 . A method according to claim 7 wherein access to the decryption key is provided in dependence upon a privilege level of the first process and the encrypted data.
9 . A method according to claim 8 wherein once accessed the decryption key is cached by the process for further use thereby.
10 . A method according to claim 6 wherein the first file is encrypted with a symmetric key and stored in association with the symmetric key, the symmetric key stored in a secure form comprising:
requesting the symmetric key form a key manager;
wherein in dependence upon the first privilege level of the first process, the second process is operable one of to provide access to the first data file stored in the data store to the first process and to deny access to the first data file stored in the data store to the first process comprises when access to the first data file is provided, extracting the symmetric key by a key manager and providing the extracted symmetric key to the first process.
11 . The method according to claim 1 wherein the second process is the computer system's operating system.
12 . A method according to claim 1 wherein the second process is called in response to a hook into the OS APIs.
13 . A method according to claim 1 wherein privilege levels comprise:
Top secret, full trusted, semi-trusted, non-trusted, and banned.
14 . A method according to claim 1 wherein the first data file is stored within a second system and comprises cipher data for accessing first secured data, the first secured data secured with a cipher comprising:
establishing trust between the computer system and the second system;
evaluating by the second system the first privilege level of the first process in execution within the computer system;
when the first privilege level is sufficient to provide access to the cipher data, providing access to at least some of the cipher data; and
when the first privilege level is insufficient to support access to the cipher data, other than providing access to the at least some of the cipher data.
15 . A method comprising:
providing an operating system comprising security for securing data and for providing user access to data based on security policies associated with a user; providing a first application for execution within the operating system; and, assigning to the first application security policies for being applied to restrict access to data accessed within or through the operating system based on the security policies, at least some of the security policies independent of the security policies of both a user of the application and a group of a user of the application.
16 . A method according to claim 15 comprising:
storing first data in a data store;
requesting access to the first data by the first application;
evaluating the first application security policies by a second process in execution on a processor of a computer system and the second process for controlling access by the first application to data; and
in dependence upon the first application security policies, the second process is operable one of to provide access to the first data to the first application and to deny access to the first data to the first application.
17 . A method according to claim 16 wherein the first data comprises data within a clipboard of the operating system.
18 . A method according to claim 16 wherein the first data comprises data accessible via a socket of the operating system.
19 . A method according to claim 16 wherein the first data comprises data accessible from another application in contemporaneous execution on a processor of a computer system wherein access to the first data is provided when the first application security policies is compatible with the security policies of the another application.
20 . A method according to claim 16 wherein the first data comprises data accessible from shared system resources wherein access to the first data is provided when the first application security policies is compatible with the security policies of the shared system resources.
21 . A method according to claim 16 wherein the first data comprises data accessible from shared system resources wherein access to the first data is provided when the first application security policies is compatible with the security policies of an application that stored the first data in association with the shared system resources.
22 . A method according to claim 16 wherein the first data comprises data stored within a persistent data file.
23 . A method according to claim 16 wherein the second process comprises a process forming part of a security controller.
24 . A method comprising:
establishing a level of trust between a first process in execution on a computer system and a second other process in execution on a computer system, the level of trust established in dependence upon security policy data associated with the first process and security policy data associated with the second other process; and, in dependence upon the level of trust established between the first process and the second other process, selectively performing one of providing access to data from the second other process to the first process and denying access to data by the second other process.Join the waitlist — get patent alerts
Track US2012131635A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.