IP Library Granted Patent US 7,263,718
Granted Patent B2
US 7,263,718 · App. 10/726,290 · Granted Aug 28, 2007

Security framework for supporting kernel-based hypervisors within a computing system

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,263,718
App. No.
10/726,290
Granted
Aug 28, 2007
Kind
B2
Abstract

An inventive security framework for supporting kernel-based hypervisors within a computer system. The security framework includes a security master, one or more security modules and a security manager, wherein the security master and security modules execute in kernel space.

Claims (41)

1. A security framework for supporting kernel-based hypervisors within a computer system, the security framework comprising:

a security master;

one or more security modules; and

a security manager;

wherein the security master and security modules execute in kernel space.

2. The security framework of claim 1 , wherein the security manager executes in user space.

3. The security framework of claim 1 , wherein one of the security modules is designed to apply a security policy to a specific application.

4. The security framework of claim 1 , wherein one of the security modules is designed to apply a security policy to two or more different applications.

5. The security framework of claim 1 , wherein one of the security modules enforces application-specific policy decisions for applications running in user space.

6. The security framework of claim 5 , wherein the security module grants access to one or more computing resources as a function of the application requesting access.

7. The security framework of claim 5 , wherein one of the security modules enforces resource-specific policy decisions for applications running in user space.

8. The security framework of claim 7 , wherein the security module grants access to one or more computing resources as a function of the computing resource being requested.

9. The security framework of claim 7 , wherein one of the security modules is designed to apply a security policy to a specific application.

10. The security framework of claim 7 , wherein one of the security modules is designed to apply a security policy to two or more different applications.

11. The security framework of claim 7 , wherein the security master includes a kernel-based facility for installing, configuring, monitoring and removing security modules.

12. The security framework of claim 7 , wherein the security master includes:

a kernel-based facility for installing, configuring, monitoring and removing security modules; and

entry points for registering a security module, intercepting system calls, releasing system calls, and communicating messages between security modules and user space.

13. The security framework of claim 7 , wherein the security manager includes an interface for communicating with security master, wherein the interface permits a user to configure and control security modules from user space.

14. The security framework of claim 7 , wherein the security manager includes an interface for communicating with security master, wherein the interface permits a user to configure and control security modules from user space, wherein management functions available to the user include:

the ability to list a set of rules that are being enforced by each security module;

the ability to load a new set of rules for a particular security module; and

the ability to log and view activity within the security framework.

15. The security framework of claim 7 , wherein a user daemon executes in user space and allows the security master to initiate actions in user space.

16. The security framework of claim 1 , wherein one of the security modules enforces resource-specific policy decisions for applications running in user space.

17. The security framework of claim 16 , wherein the security module grants access to one or more computing resources as a function of the computing resource being requested.

18. The security framework of claim 16 , wherein one of the security modules is designed to apply a security policy to a specific application.

19. The security framework of claim 16 , wherein one of the security modules is designed to apply a security policy to two or more different applications.

20. The security framework of claim 16 , wherein the security modules are hierarchically configured.

21. The security framework of claim 1 , wherein the security modules are hierarchically configured.

22. The security framework of claim 1 , wherein the security modules are designed so they can be loaded while the computing system is running.

23. The security framework of claim 1 , wherein the security master includes a kernel-based facility for installing, configuring, monitoring and removing security modules.

24. The security framework of claim 1 , wherein the security master includes:

a kernel-based facility for installing, configuring, monitoring and removing security modules; and

entry points for registering a security module, intercepting system calls, releasing system calls, and communicating messages between security modules and user space.

25. The security framework of claim 1 , wherein the security manager includes an interface for communicating with security master, wherein the interface permits a user to configure and control security modules from user space.

26. The security framework of claim 1 , wherein the security manager includes an interface for communicating with security master, wherein the interface permits a user to configure and control security modules from user space, wherein management functions available to the user include:

the ability to list a set of rules that are being enforced by each security module;

the ability to load a new set of rules for a particular security module; and

the ability to log and view activity within the security framework.

27. The security framework of claim 1 , wherein a user daemon executes in user space and allows the security master to initiate actions in user space.

Assignments (12)
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY NUMBERS PREVIOUSLY RECORDED AT REEL: 021523 FRAME: 0713. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF PATENT SECURITY AGREEMENT. Recorded Apr 11, 2022
From: CITICORP USA, INC.
To: SECURE COMPUTING CORPORATION
Reel/Frame 059690/0187 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 28, 2010
From: SECURE COMPUTING, LLC
To: MCAFEE, INC.
Reel/Frame 024456/0724 →
CHANGE OF NAME Recorded Mar 25, 2010
From: SECURE COMPUTING CORPORATION
To: SECURE COMPUTING, LLC
Reel/Frame 024128/0806 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 12, 2008
From: CITICORP USA, INC.
To: SECURE COMPUTING CORPORATION
Reel/Frame 021523/0713 →
SECURITY AGREEMENT Recorded Sep 14, 2006
From: SECURE COMPUTING CORPORATION; CIPHERTRUST, INC.
To: CITICORP USA, INC. AS ADMINISTRATIVE AGENT
Reel/Frame 018247/0359 →