US2013305348A1PendingUtilityA1

Client authentication and data management system

Assignee: PROT IP LLC COMPPriority: Oct 13, 2006Filed: Jun 13, 2013Published: Nov 14, 2013
Est. expiryOct 13, 2026(~0.2 yrs left)· nominal 20-yr term from priority
H04L 63/08G06F 21/575G06F 21/53G06F 9/45558G06F 21/554G06F 21/44G06F 21/602G06F 2009/45587H04L 63/20G06F 2221/033
53
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Methods and systems for performing an authenticated boot ( 310 ); performing a continuous data protection ( 350 ); performing automatic protection and optionally a consolidation; and performing other defenses and protection of a protected computing device ( 110 a, 110 b, 110 c ) (such as a computer system) are provided. The aspects include integrating security mechanisms (which may include a “call home” function ( 330 ), role and rule-based policies ( 225 ), validating technologies, encryption and decryption technologies, data compression technologies, protected and segmented boot technologies, and virtualization technologies. Booting and operating (either fully or in a restricted manner) are permitted only under a control of a specified role-set, rule-set, and/or a controlling supervisory process or server system(s). The methods and systems make advantageous use of hypervisors ( 220 ) and other virtual machine monitors or managers.

Claims

exact text as granted — not AI-modified
1 . A system comprising:
 a virtual machine communicatively coupled with a computing device, the virtual machine designed with at least one of the following capabilities: (a) to cause the computing device to boot, (b) to prevent the computing device from booting, and (c) to boot the computing device but limit memory access, storage access, network access, and/or input/output capability of the computing device, the virtual machine designed to initiate at least one of (a), (b), and (c).   
     
     
         2 . The system of  claim 1 , further comprising an operating system that is communicatively coupled to the computing device and the virtual machine and wherein the virtual machine is designed:
 with respect to (a), to cause the operating system to boot;   with respect to (b), to prevent the operating system from booting; and   with respect to (c), to boot the operating system but limit memory access, storage access, network access, and/or input/output capability of the operating system.   
     
     
         3 . The system of  claim 2 , further comprising a virtual machine manager communicatively coupled with the virtual machine, the virtual machine manager configured to exercise control over the computing device, the virtual machine, and/or the operating system. 
     
     
         4 . The system of  claim 3 , wherein the virtual machine and the virtual machine manager are configured to communicate with each other through a network. 
     
     
         5 . The system of  claim 3 , wherein the virtual machine manager is a hypervisor. 
     
     
         6 . The system of  claim 1 , wherein the virtual machine is designed to cause the computing device and an authentication server to engage in an authentication session in order to authenticate the device to the server and/or to authenticate the server to the computing device and wherein the virtual machine is designed to determine the at least one of the capabilities (a), (b), or (c) to initiate based upon an outcome of the authentication session. 
     
     
         7 . The system of  claim 1 , wherein the virtual machine resides within the computing device. 
     
     
         8 . The system of  claim 1 , wherein the virtual machine is situated remote from the computing device and wherein the computing device and the virtual machine are configured to communicate with each other through a network. 
     
     
         9 . The system of  claim 8 , wherein the network is permanent. 
     
     
         10 . The system of  claim 8 , wherein the network is temporary. 
     
     
         11 . The system of  claim 1 , wherein the virtual machine is configured to change, enable, and/or disable encryption associated with data that is input and/or output within, to, or from the computing device. 
     
     
         12 . The system of  claim 1 , wherein the virtual machine is configured to enable, change, and/or disable encryption associated with data that is stored. 
     
     
         13 . A system comprising:
 a computing device; and   a virtual machine communicatively coupled with an operating system that is communicatively coupled to the computing device, the virtual machine designed to cause the operating system to boot.   
     
     
         14 . The system of  claim 13 , further comprising a virtual machine manager associated with the virtual machine, the virtual machine manager configured to exercise control over the computing device, the virtual machine, and/or the operating system. 
     
     
         15 . The system of  claim 14 , wherein the virtual machine manager is in communication with the virtual machine through a network. 
     
     
         16 . The system of  claim 14 , wherein the virtual machine manager is a hypervisor. 
     
     
         17 . The system of  claim 13 , wherein the virtual machine is designed to cause the computing device and an authentication server to engage in an authentication session in order to authenticate the device to the server and/or to authenticate the server to the device and wherein the virtual machine is designed to cause the operating system to boot based upon an outcome of the authentication session. 
     
     
         18 . The system of  claim 13 , wherein the virtual machine resides within the computing device. 
     
     
         19 . The system of  claim 13 , wherein the virtual machine is situated remote from the computing device and wherein the operating system and the virtual machine are configured to communicate with each other through a network. 
     
     
         20 . The system of  claim 19 , wherein the network is permanent. 
     
     
         21 . The system of  claim 19 , wherein the network is temporary. 
     
     
         22 . The system of  claim 13 , wherein the virtual machine is configured to change, enable, and/or disable encryption associated with data that is input and/or output within, to, or from the computing device. 
     
     
         23 . The system of  claim 13 , wherein the virtual machine is configured to enable, change, and/or disable encryption associated with data that is stored. 
     
     
         24 . A system comprising:
 a computing device; and   a virtual machine communicatively coupled with an operating system that is communicatively coupled with the computing device, the virtual machine designed to prevent the operating system from booting.   
     
     
         25 . The system of  claim 24 , further comprising a virtual machine manager communicatively coupled with the virtual machine, the virtual machine manager configured to exercise control over the computing device, the virtual machine, and/or the operating system. 
     
     
         26 . The system of  claim 25 , wherein the virtual machine and the virtual machine manager are configured to communicate with each other through a network. 
     
     
         27 . The system of  claim 25 , wherein the virtual machine manager is a hypervisor. 
     
     
         28 . The system of  claim 24 , wherein the virtual machine is designed to cause the computing device and an authentication server to engage in an authentication session in order to authenticate the device to the server and/or to authenticate the server to the device and wherein the virtual machine is designed to prevent the operating system from booting based upon an outcome of the authentication session. 
     
     
         29 . The system of  claim 24 , wherein the virtual machine resides within the computing device. 
     
     
         30 . The system of  claim 24 , wherein the virtual machine is situated remote from the computing device and wherein the operating system and the virtual machine are configured to communicate with each other through a network. 
     
     
         31 . The system of  claim 30 , wherein the network is permanent. 
     
     
         32 . The system of  claim 30 , wherein the network is temporary. 
     
     
         33 . The system of  claim 24 , wherein the virtual machine is configured to change, enable, and/or disable encryption associated with data that is input and/or output within, to, or from the computing device. 
     
     
         34 . The system of  claim 24 , wherein the virtual machine is configured to enable, change, and/or disable encryption associated with data that is stored. 
     
     
         35 . A system comprising:
 a computing device; and   a virtual machine is communicatively coupled with an operating system that is communicatively coupled with the computing device, the virtual machine designed to boot the operating system but selectively limit at least one of the following capabilities: memory access, storage access, network access, and/or input/output capability of the operating system.   
     
     
         36 . The system of  claim 35 , further comprising a virtual machine manager communicatively coupled with the virtual machine, the virtual machine manager configured to exercise control over the computing device, the virtual machine, and/or the operating system. 
     
     
         37 . The system of  claim 36 , wherein the virtual machine and the virtual machine manager are configured to communicate with each other through a network. 
     
     
         38 . The system of  claim 36 , wherein the virtual machine manager is a hypervisor. 
     
     
         39 . The system of  claim 35 , wherein the virtual machine is designed to cause the computing device and an authentication server to engage in an authentication session in order to authenticate the device to the server and/or to authenticate the server to the device and wherein the virtual machine is designed to limit the capabilities based upon an outcome of the authentication session. 
     
     
         40 . The system of  claim 35 , wherein the virtual machine resides within the computing device. 
     
     
         41 . The system of  claim 35 , wherein the virtual machine is situated remote from the computing device and wherein the operating system and the virtual machine are configured to communicate with each other through a network. 
     
     
         42 . The system of  claim 41 , wherein the network is permanent. 
     
     
         43 . The system of  claim 41 , wherein the network is temporary. 
     
     
         44 . The system of  claim 35 , wherein the virtual machine is configured to enable and/or disable encryption associated with data that is input and/or output within, to, or from the computing device. 
     
     
         45 . The system of  claim 35 , wherein the virtual machine is configured to enable, change, and/or disable encryption associated with data that is stored. 
     
     
         46 . A system comprising:
 an authentication server; and   a virtual machine communicatively coupled with an operating system that is communicatively coupled with a computing device, the virtual machine designed to cause the computing device and an authentication server to engage in an authentication session to authenticate the device to the server and/or to authenticate the server to the device, the virtual machine designed with at least one of the following capabilities: (a) to cause the operating system to boot, (b) to prevent the operating system from booting, and (c) to boot the operating system but limit at least one of memory access, storage access, network access, or input/output capability of the operating system, the virtual machine designed to initiate at least one of (a), (b), and (c), the virtual machine designed to initiate at least one of (a), (b), or (c) based upon an outcome of the authentication session.   
     
     
         47 . The system of  claim 46 , further comprising a virtual machine manager communicatively coupled with the virtual machine, the virtual machine manager configured to exercise control over the computing device, the virtual machine, and/or the operating system. 
     
     
         48 . The system of  claim 47 , wherein the virtual machine and the virtual machine manager are configured to communicate with each other through a network. 
     
     
         49 . The system of  claim 47 , wherein the virtual machine manager is a hypervisor. 
     
     
         50 . The system of  claim 46 , wherein the virtual machine resides within the computing device. 
     
     
         51 . The system of  claim 46 , wherein the virtual machine is situated remote from the computing device and wherein the operating system and the virtual machine are configured to communicate with each other through a network. 
     
     
         52 . The system of  claim 51 , wherein the network is permanent. 
     
     
         53 . The system of  claim 51 , wherein the network is temporary. 
     
     
         54 . The system of  claim 46 , wherein the virtual machine is configured to change, enable, and/or disable encryption associated with data that is input and/or output within, to, or from the computing device. 
     
     
         55 . The system of  claim 46 , wherein the virtual machine is configured to enable, change, and/or disable encryption associated with data that is stored.

Join the waitlist — get patent alerts

Track US2013305348A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.