US2018285578A1PendingUtilityA1

Temporally isolating data accessed by a computing device

Assignee: REDWALL TECH LLCPriority: Aug 12, 2014Filed: Jun 4, 2018Published: Oct 4, 2018
Est. expiryAug 12, 2034(~8 yrs left)· nominal 20-yr term from priority
G06F 21/6218G06F 21/604G06F 2221/2105
40
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Embodiments of the present invention provide a method to temporally isolate data accessed by a computing device so that the data accessed by the computing device is limited to a single set of data. The method includes removing any data that is accessed by the computing device when operating in different modes so that the data is inaccessible by the computing device when operating in the mode. The method also includes switching to the mode after the data associated with the modes different from the mode have been removed. The method also includes operating in the mode based on a plurality of rules associated with the security policy in temporal isolation from any other mode associated with the computing device. The computing device is limited to operating in the mode and is prevented from accessing any data that is distinct from the single set of data of the mode.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method of authenticating an operator on a computer system including an operating system, the method comprising:
 receiving a request to switch from a first mode to a second mode at the computer system;   in response to receiving the request, unloading the operating system as part of terminating the first mode;   after the operating system has been unloaded, loading the operating system as part of switching to the second mode;   performing authentication of the operator by the computer system before loading of the operating system is completed; and   only allowing loading of the operating system to complete if authentication is successful.   
     
     
         2 . The method of  claim 1  wherein the first mode is associated with a first set of data and further comprising:
 in response to receiving the request to switch from the first mode to the second mode, removing the first set of data from the computer system; and 
 only switching from the first mode to the second mode after the first set of data has been removed from the computer system. 
 
     
     
         3 . The method of  claim 2  wherein removing the first set of data from the computer system includes removing any data from the first set of data from any location that is accessible by the operating system. 
     
     
         4 . The method of  claim 2  wherein the second mode is associated with a second set of data and further comprising:
 in response to the first set of data being removed from the computer system, loading the second set of data into the computer system. 
 
     
     
         5 . The method of  claim 4  wherein the operating system is not launched until after the second set of data is loaded into the computer system. 
     
     
         6 . The method of  claim 1  wherein the first mode and the second mode each include respective security policies, and further comprising:
 in response to switching from the first mode to the second mode, regulating operation of the computer system based on the security policies of the second mode. 
 
     
     
         7 . The method of  claim 1  wherein unloading and loading the operating system comprises rebooting the computer system. 
     
     
         8 . The method of  claim 1  wherein the request to switch from the first mode to the second mode is received in response to a computing device crossing a geographic perimeter. 
     
     
         9 . The method of  claim 8  wherein the request to switch from the first mode to the second mode is issued by the computing device in response to the computing device crossing the geographic perimeter. 
     
     
         10 . The method of  claim 1  wherein the request to switch from the first mode to the second mode is received from a user interface of the computer system. 
     
     
         11 . A computer system for authenticating an operator, comprising:
 one or more processors; and   a memory coupled to the one or more processors and including program code that, when executed by the one or more processors, causes the one or more processors to:   receive a request to switch from a first mode to a second mode;   in response to receiving the request, unload an operating system as part of terminating the first mode;   after the operating system has been unloaded, load the operating system as part of switching to the second mode;   perform authentication of the operator before loading of the operating system is completed; and   only allow loading of the operating system to complete if authentication is successful.   
     
     
         12 . The computer system of  claim 11  wherein the first mode is associated with a first set of data and the program code further causes the one or more processors to:
 in response to receiving the request to switch from the first mode to the second mode, remove the first set of data from the computer system; and 
 only switching from the first mode to the second mode after the first set of data has been removed from the computer system. 
 
     
     
         13 . The computer system of  claim 12  wherein removing the first set of data from the computer system includes removing any data from the first set of data from any location that is accessible by the operating system. 
     
     
         14 . The computer system of  claim 12  wherein the second mode is associated with a second set of data and the program code further causes the one or more processors to:
 in response to the first set of data being removed from the computer system, load the second set of data into the computer system. 
 
     
     
         15 . The computer system of  claim 14  wherein the operating system is not launched until after the second set of data is loaded into the computer system. 
     
     
         16 . The computer system of  claim 11  wherein the first mode and the second mode each include respective security policies, and the program code further causes the one or more processors to:
 in response to switching from the first mode to the second mode, regulate operation of the computer system based on the security policies of the second mode. 
 
     
     
         17 . The computer system of  claim 11  wherein the program code causes the one or more processors to unload and load the operating system by rebooting the computer system. 
     
     
         18 . The computer system of  claim 11  wherein the request to switch from the first mode to the second mode is received in response to a computing device crossing a geographic perimeter. 
     
     
         19 . The computer system of  claim 18  wherein the request to switch from the first mode to the second mode is issued by the computing device in response to the computing device crossing the geographic perimeter. 
     
     
         20 . A computer program product for authenticating an operator, comprising:
 a non-transitory computer-readable storage medium; and   program code stored on the non-transitory computer-readable storage medium that, when executed by one or more processors, causes the one or more processors to:   receive a request to switch from a first mode to a second mode;   in response to receiving the request, unload an operating system as part of terminating the first mode;   after the operating system has been unloaded, load the operating system as part of switching to the second mode;   perform authentication of the operator before loading of the operating system is completed; and   only allow loading of the operating system to complete if authentication is successful.

Join the waitlist — get patent alerts

Track US2018285578A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.