Application program launching method and system for improving security of embedded linux kernel
Abstract
Provided is an application program launching method and system for improving security of an embedded Linux kernel by distributing superuser privileges. The method includes: searching security set information on an application program selected by a user; changing a user account for a processor of the application program to a user ID associated with the application program in the security set information; setting a capability for the processor according to setting information for the capability in the security set information; changing a basic directory for the processor according to a basic directory in the security set information; and launching the application program.
Claims
exact text as granted — not AI-modified1 - 17 . (canceled)
18 . A method comprising:
obtaining, at an electronic device, a process corresponding to an application in response to a request for the application; identifying at least one portion of a first user identification assigned to the application; and assigning a second user identification to the process based at least in part on the at least one portion.
19 . The method of claim 18 , further comprising:
assigning the first user identification to the application during installation of the application to the electronic device.
20 . The method of claim 19 , wherein the assigning of the first user identification comprises:
assigning at least one of a permission or a directory to the application.
21 . The method of claim 18 , wherein the identifying comprises:
searching the first user identification from a plurality of user identifications stored at the electronic device, each of the plurality of user identifications assigned to a different application.
22 . The method of claim 18 , wherein the identifying comprises:
identifying at least one of a permission or a directory assigned to the application.
23 . The method of claim 18 , wherein the assigning of the second user identification comprises:
determining a first permission assigned to the application; and assigning a second permission to the process based at least in part on the first permission.
24 . The method of claim 23 , further comprising:
accessing at least one resource using the process based at least in part on the second permission.
25 . The method of claim 18 , further comprising:
executing the application using the process, the executing including accessing at least one resource based at least in part on the second user identification.
26 . The method of claim 18 , further comprising:
assigning a third user identification to another process corresponding to another application based at least in part on a fourth user identification assigned to the other application.
27 . The method of claim 26 , further comprising:
executing the other application using the other process, the executing including accessing at least one resource based at least in part on the third user identification.
28 . An apparatus comprising:
a memory configured to store at least one user identification corresponding to at least one application; and a controller operatively coupled to the memory, the controller configured to:
obtain a process corresponding to an application in response to a request for the application;
identify at least one portion of a first user identification assigned to the application; and
assign a second user identification to the process based at least in part on the at least one portion.
29 . The apparatus of claim 28 , wherein the controller is configured to assign the first user identification to the application during installation of the application to the electronic device.
30 . The apparatus of claim 28 , wherein the controller is configured to assign at least one of a permission or a directory to the application during installation of the application to the electronic device.
31 . The apparatus of claim 28 , wherein the controller is configured to search the first user identification from a plurality of user identifications stored at the apparatus, each of the plurality of user identifications assigned to a different application.
32 . The apparatus of claim 28 , wherein the controller is configured to identify at least one of a permission or a directory assigned to the application.
33 . The apparatus of claim 28 , wherein the controller is configured to:
determine a first permission assigned to the application; and assign a second permission to the process based at least in part on the first permission.
34 . The apparatus of claim 33 , wherein the controller is configured to access at least one resource using the process based at least in part on the second permission.
35 . The apparatus of claim 28 , wherein the controller is configured to execute the application using the process, the executing including accessing at least one resource based at least in part on the second user identification.
36 . The apparatus of claim 28 , wherein the controller is configured to assign a third user identification to another process corresponding to another application based at least in part on a fourth user identification assigned to the other application.
37 . The apparatus of claim 36 , wherein the controller is configured to execute the other application using the other process, the executing including accessing at least one resource based at least in part on the third user identification.
38 . A non-transitory machine-readable storage device storing instructions that, when executed by one or more processors, cause the one or more processors to perform operations comprising:
obtaining, at an electronic device, a process corresponding to an application in response to a request for the application; identifying at least one portion of a first user identification assigned to the application; and assigning a second user identification to the process based at least in part on the at least one portion.Join the waitlist — get patent alerts
Track US2014201830A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.