US2014317400A1PendingUtilityA1
System and method for validation and enforcement of application security
Est. expiryDec 15, 2025(expired)· nominal 20-yr term from priority
G06F 21/51H04L 9/3247G06F 21/121
40
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
A system and method for validation and enforcement of application security, wherein the user credentials and the integrity of a target application are verified before the target application is permitted to execute.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method of validating a first application in a data network configured to provide applications to client systems, the data network comprising an authentication server system, the method comprising:
providing an enforcer application to the client system, the enforcer application being configured to:
execute on the client system, in response to a request to execute client application on the client system,
generate a signature for the client application, compare the generated signature with a stored signature and,
when the generated signature matches the stored signature, generate and transmit to the authentication server system an encrypted authentication message, the authentication message conveying user credentials, an application identifier associated with the client application and the generated signature; and
receiving the authentication message at the authentication server system and, when the authentication server system is able to validate the client application based on the received authentication message, transmitting an authorization from the authentication server system to the client system, the enforcer application being configured, based on receipt of the authorization at the client system, to permit execution of the client application.
2 . The method of claim 1 , wherein the enforcer application is configured to not permit execution of the client application on the client system when the generated signature does not match the stored signature.
3 . The method of claim 1 , wherein the enforcer application is configured to not transmit an authentication message to the authentication server system when the generated signature does not match the stored signature.
4 . The method of claim 1 , wherein the authentication server system does not send an authorization to the client system when the server system is unable to validate the first application based on the received authentication message.
5 . The method of claim 1 , wherein the enforcer application is configured to not permit execution of the client application on the client system when no authorization has been received from the authentication server system.
6 . The method of claim 1 , comprising:
decrypting the received authentication message to determine the generated signature and the user credential at the authentication server system; and attempting to validate the client application based on the generated signature and the user credentials at the authentication server system.
7 . The method of claim 1 , comprising:
downloading the stored signature to the client system.
8 . The method of claim 7 , wherein the downloaded signature is digitally signed by the authentication server system.
9 . The method of claim 1 , wherein the generated signature will not match the stored signature if the client application has been modified.
10 . The method of claim 1 , wherein the enforcer application is configured to encrypt the authentication message such that the authentication server system requires a private cryptographic key to decrypt the authentication message.
11 . The method of claim 1 , wherein each client application of a plurality of client applications is associated with a respective private cryptographic key.
12 . The method of claim 10 , wherein the authentication server system stores the private cryptographic key.
13 . The method of claim 1 , wherein the authentication message comprises data corresponding to the generated signature.
14 . The method of claim 13 , wherein the authorization indicates validation of the data corresponding to the generated signature.
15 . The method of claim 1 , wherein the enforcer application manages a process to download and re-install the client application on the client system when the generated signature does not correspond to the stored signature.
16 . The method of claim 1 , wherein the enforcer application disables the first application when the generated signature does not correspond to the stored signature.Join the waitlist — get patent alerts
Track US2014317400A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.