US2014201830A1PendingUtilityA1

Application program launching method and system for improving security of embedded linux kernel

Assignee: KOREA ELECTRONICS TELECOMMPriority: Dec 5, 2006Filed: Mar 18, 2014Published: Jul 17, 2014
Est. expiryDec 5, 2026(~0.4 yrs left)· nominal 20-yr term from priority
G06F 21/6227G06F 2221/2141G06F 21/31G06F 21/53G06F 15/00G06F 21/00
49
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Provided is an application program launching method and system for improving security of an embedded Linux kernel by distributing superuser privileges. The method includes: searching security set information on an application program selected by a user; changing a user account for a processor of the application program to a user ID associated with the application program in the security set information; setting a capability for the processor according to setting information for the capability in the security set information; changing a basic directory for the processor according to a basic directory in the security set information; and launching the application program.

Claims

exact text as granted — not AI-modified
1 - 17 . (canceled) 
     
     
         18 . A method comprising:
 obtaining, at an electronic device, a process corresponding to an application in response to a request for the application;   identifying at least one portion of a first user identification assigned to the application; and   assigning a second user identification to the process based at least in part on the at least one portion.   
     
     
         19 . The method of  claim 18 , further comprising:
 assigning the first user identification to the application during installation of the application to the electronic device.   
     
     
         20 . The method of  claim 19 , wherein the assigning of the first user identification comprises:
 assigning at least one of a permission or a directory to the application.   
     
     
         21 . The method of  claim 18 , wherein the identifying comprises:
 searching the first user identification from a plurality of user identifications stored at the electronic device, each of the plurality of user identifications assigned to a different application.   
     
     
         22 . The method of  claim 18 , wherein the identifying comprises:
 identifying at least one of a permission or a directory assigned to the application.   
     
     
         23 . The method of  claim 18 , wherein the assigning of the second user identification comprises:
 determining a first permission assigned to the application; and   assigning a second permission to the process based at least in part on the first permission.   
     
     
         24 . The method of  claim 23 , further comprising:
 accessing at least one resource using the process based at least in part on the second permission.   
     
     
         25 . The method of  claim 18 , further comprising:
 executing the application using the process, the executing including accessing at least one resource based at least in part on the second user identification.   
     
     
         26 . The method of  claim 18 , further comprising:
 assigning a third user identification to another process corresponding to another application based at least in part on a fourth user identification assigned to the other application.   
     
     
         27 . The method of  claim 26 , further comprising:
 executing the other application using the other process, the executing including accessing at least one resource based at least in part on the third user identification.   
     
     
         28 . An apparatus comprising:
 a memory configured to store at least one user identification corresponding to at least one application; and   a controller operatively coupled to the memory, the controller configured to:
 obtain a process corresponding to an application in response to a request for the application; 
 identify at least one portion of a first user identification assigned to the application; and 
 assign a second user identification to the process based at least in part on the at least one portion. 
   
     
     
         29 . The apparatus of  claim 28 , wherein the controller is configured to assign the first user identification to the application during installation of the application to the electronic device. 
     
     
         30 . The apparatus of  claim 28 , wherein the controller is configured to assign at least one of a permission or a directory to the application during installation of the application to the electronic device. 
     
     
         31 . The apparatus of  claim 28 , wherein the controller is configured to search the first user identification from a plurality of user identifications stored at the apparatus, each of the plurality of user identifications assigned to a different application. 
     
     
         32 . The apparatus of  claim 28 , wherein the controller is configured to identify at least one of a permission or a directory assigned to the application. 
     
     
         33 . The apparatus of  claim 28 , wherein the controller is configured to:
 determine a first permission assigned to the application; and   assign a second permission to the process based at least in part on the first permission.   
     
     
         34 . The apparatus of  claim 33 , wherein the controller is configured to access at least one resource using the process based at least in part on the second permission. 
     
     
         35 . The apparatus of  claim 28 , wherein the controller is configured to execute the application using the process, the executing including accessing at least one resource based at least in part on the second user identification. 
     
     
         36 . The apparatus of  claim 28 , wherein the controller is configured to assign a third user identification to another process corresponding to another application based at least in part on a fourth user identification assigned to the other application. 
     
     
         37 . The apparatus of  claim 36 , wherein the controller is configured to execute the other application using the other process, the executing including accessing at least one resource based at least in part on the third user identification. 
     
     
         38 . A non-transitory machine-readable storage device storing instructions that, when executed by one or more processors, cause the one or more processors to perform operations comprising:
 obtaining, at an electronic device, a process corresponding to an application in response to a request for the application;   identifying at least one portion of a first user identification assigned to the application; and   assigning a second user identification to the process based at least in part on the at least one portion.

Join the waitlist — get patent alerts

Track US2014201830A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.