Virus immune computer system and method
Abstract
A method and apparatus prevents hacker code from infecting an application program by requiring decryption of the application program prior to running the application program on a computer. The device is preferably a computer system that includes a dongle, or a separate unit that is connected or connectable to the computer. A security program decrypts a first key with a second key stored on the dongle. When a new application is installed the first time on the computer, the security program uses a decrypted first key to encrypt whatever is installed such that the encrypted application program is the only installed version of the application program on any non-transitory computer readable memory accessible by the computer. When a command is given to startup the application program, whatever code is needed for startup is first decrypted using the decrypted first key.
Claims
exact text as granted — not AI-modified1 : (canceled)
2 . A method for improving operation of a computer to provide security to a file, the method comprising the steps of:
hosting an operating system in a non-transitory computer storage medium accessible by a computer; storing an encrypted program symmetric private key in the non-transitory computer storage medium; storing an encrypted operating system symmetric private key in the non-transitory computer storage medium; receiving at the computer an encryption/decryption key; using the encryption/decryption key to decrypt the encrypted operating system symmetric private key on the computer to derive a decrypted operating system symmetric private key; using the decrypted operating system symmetric private key to decrypt the encrypted program symmetric private key on the computer to derive a decrypted program symmetric private key; encrypting a file using the decrypted program symmetric private key upon first saving of the file and thereby create an encrypted file, then saving the encrypted file on the non-transitory computer storage medium of the computer; when executing a command to load the file into a random access memory accessible by the computer, requiring the operating system to use the decrypted program symmetric private key to decrypt a first part of the encrypted file necessary to load the file into a random access memory accessible by the computer; requiring the computer to use the decrypted program symmetric private key to subsequently decrypt any second part of the encrypted file that is needed during operation of the first part; and storing the first part and any second part that is decrypted in the random access memory accessible by the computer.
3 . The method of claim 2 , further comprising the step of assigning the encrypted program symmetric private key to the file.
4 . The method of claim 2 , further comprising the step of receiving the encryption/decryption key through a network connection.
5 . The method of claim 2 , further comprising limiting storage such that the encrypted file is the only stored version of the file on the computer.
6 . The method of claim 2 , further comprising the step of requiring the file to be a software program.
7 . A method for improving operation of a computer to provide security to a file, the method comprising the steps of:
hosting an operating system in a non-transitory computer storage medium accessible by a computer; storing an encrypted program symmetric private key in the non-transitory computer storage medium; receiving at the computer an encrypted operating system symmetric private key; decrypting the encrypted operating system symmetric private key on the computer to derive a decrypted operating system symmetric private key; using the decrypted operating system symmetric private key to decrypt the encrypted program symmetric private key on the computer to derive a decrypted program symmetric private key; encrypting a file using the decrypted program symmetric private key upon first saving of the file and thereby create an encrypted file, then saving the encrypted file on the non-transitory computer storage medium of the computer; when executing a command to load the file into a random access memory accessible by the computer, requiring the operating system to use the decrypted program symmetric private key to decrypt a first part of the encrypted file necessary to load the file into a random access memory accessible by the computer; requiring the computer to use the decrypted program symmetric private key to subsequently decrypt any second part of the encrypted file that is needed during operation of the first part; and storing the first part and any second part that is decrypted in a random access memory accessible by the computer.
8 . The method of claim 7 , further comprising the step of limiting the computer such that the encrypted file is the only stored version of the file on the computer.
9 . The method of claim 7 , further comprising the step of receiving the encrypted operating system symmetric private key through a network connection.
10 . The method of claim 7 , further comprising the step of assigning the encrypted program symmetric private key to the file.
11 . A computer system comprising:
a storage device that is a separate unit from components necessary for startup of a computer, the storage device comprising: a first-non-transitory computer storage medium, the first-non-transitory computer storage medium storing:
a device symmetric private key, the device symmetric private key operable to decrypt an encrypted operating system symmetric private key so as to produce a decrypted operating system symmetric private key; and
a computer comprising: a central processing unit; an address bus; and a second-non-transitory computer storage medium on which is stored an encrypted program symmetric private key, the encrypted operating system symmetric private key, and a security program that is operable to:
retrieve the device symmetric private key from the storage device;
decrypt the encrypted operating system symmetric private key with the device symmetric private key to produce the decrypted operating system symmetric private key;
use the decrypted operating system symmetric private key to decrypt the encrypted program symmetric private key on the computer to derive a decrypted program symmetric private key;
encrypt a file using the decrypted program symmetric private key upon first saving of the file and thereby create an encrypted file, then save the encrypted file on the first-non-transitory computer storage medium of the computer;
enable the computer, each time a command is given to load the file, to use the decrypted program symmetric private key to decrypt a first portion of the encrypted file needed implement the command, and to store what was decrypted in a random access memory accessible by the computer; and,
require the computer to use the decrypted program symmetric private key to subsequently decrypt any second portion of the encrypted file that is needed during operation of the first portion and to store what was subsequently decrypted in the random access memory accessible by the computer.
12 . The computer system of claim 11 , wherein the security program is further operable to associate the encrypted program symmetric private key with the file.
13 . The computer system of claim 11 , wherein the security program is further operable to prevent access to the device symmetric private key after the device symmetric private key is first accessed to produce the decrypted operating system symmetric private key, unless express authorization is first obtained.
14 . The computer system of claim 11 , wherein the security program is further operable to preclude storage of the device symmetric private key or the decrypted operating system symmetric private key or the decrypted program symmetric private key in any non-transitory computer storage medium accessible by the computer.
15 . The computer system of claim 11 , wherein the first-non-transitory computer storage medium of the storage device is selected from the group consisting of an electronic chip, and a removable compact disk.
16 . The computer system of claim 11 , wherein the security program is further operable to require the computer, after startup of the computer, to decrypt encrypted data residing in the random access memory accessible by the computer, where the decrypted operating system symmetric private key is used to decrypt the encrypted data.
17 . The computer system of claim 11 , wherein the security program is further operable to ensure that the encrypted file is the only stored version of the file in any non-transitory computer storage medium accessible by the computer.
18 . The computer system of claim 11 , wherein the security program is further operable to require the file to be a software program.
19 . The computer system of claim 11 , wherein the storage device is an electronic chip integrated into the computer.
20 . The computer system of claim 19 , further comprising a first-electronic tristate switch in the electronic chip; and wherein the security program is further operable to activate the first-electronic tristate switch in order to prevent access to the device symmetric private key.
21 . The computer system of claim 20 , further comprising a second-electronic tristate switch in the electronic chip; and wherein the security program is further operable to activate the second-electronic tristate switch to prevent reading the device symmetric private key from the random access memory accessible by the computer.Join the waitlist — get patent alerts
Track US2020242235A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.