US2014317400A1PendingUtilityA1

System and method for validation and enforcement of application security

Assignee: Rockstar ConsortiumPriority: Dec 15, 2005Filed: Jul 2, 2014Published: Oct 23, 2014
Est. expiryDec 15, 2025(expired)· nominal 20-yr term from priority
G06F 21/51H04L 9/3247G06F 21/121
40
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A system and method for validation and enforcement of application security, wherein the user credentials and the integrity of a target application are verified before the target application is permitted to execute.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method of validating a first application in a data network configured to provide applications to client systems, the data network comprising an authentication server system, the method comprising:
 providing an enforcer application to the client system, the enforcer application being configured to:
 execute on the client system, in response to a request to execute client application on the client system, 
 generate a signature for the client application, compare the generated signature with a stored signature and, 
 when the generated signature matches the stored signature, generate and transmit to the authentication server system an encrypted authentication message, the authentication message conveying user credentials, an application identifier associated with the client application and the generated signature; and 
   receiving the authentication message at the authentication server system and, when the authentication server system is able to validate the client application based on the received authentication message, transmitting an authorization from the authentication server system to the client system, the enforcer application being configured, based on receipt of the authorization at the client system, to permit execution of the client application.   
     
     
         2 . The method of  claim 1 , wherein the enforcer application is configured to not permit execution of the client application on the client system when the generated signature does not match the stored signature. 
     
     
         3 . The method of  claim 1 , wherein the enforcer application is configured to not transmit an authentication message to the authentication server system when the generated signature does not match the stored signature. 
     
     
         4 . The method of  claim 1 , wherein the authentication server system does not send an authorization to the client system when the server system is unable to validate the first application based on the received authentication message. 
     
     
         5 . The method of  claim 1 , wherein the enforcer application is configured to not permit execution of the client application on the client system when no authorization has been received from the authentication server system. 
     
     
         6 . The method of  claim 1 , comprising:
 decrypting the received authentication message to determine the generated signature and the user credential at the authentication server system; and   attempting to validate the client application based on the generated signature and the user credentials at the authentication server system.   
     
     
         7 . The method of  claim 1 , comprising:
 downloading the stored signature to the client system.   
     
     
         8 . The method of  claim 7 , wherein the downloaded signature is digitally signed by the authentication server system. 
     
     
         9 . The method of  claim 1 , wherein the generated signature will not match the stored signature if the client application has been modified. 
     
     
         10 . The method of  claim 1 , wherein the enforcer application is configured to encrypt the authentication message such that the authentication server system requires a private cryptographic key to decrypt the authentication message. 
     
     
         11 . The method of  claim 1 , wherein each client application of a plurality of client applications is associated with a respective private cryptographic key. 
     
     
         12 . The method of  claim 10 , wherein the authentication server system stores the private cryptographic key. 
     
     
         13 . The method of  claim 1 , wherein the authentication message comprises data corresponding to the generated signature. 
     
     
         14 . The method of  claim 13 , wherein the authorization indicates validation of the data corresponding to the generated signature. 
     
     
         15 . The method of  claim 1 , wherein the enforcer application manages a process to download and re-install the client application on the client system when the generated signature does not correspond to the stored signature. 
     
     
         16 . The method of  claim 1 , wherein the enforcer application disables the first application when the generated signature does not correspond to the stored signature.

Join the waitlist — get patent alerts

Track US2014317400A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.