IP Library Granted Patent US 8,341,404
Granted Patent B2
US 8,341,404 · App. 11/357,448 · Granted Dec 25, 2012

System and method for intelligence based security

Assignee: Credant Technologies, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,341,404
App. No.
11/357,448
Filed
Feb 17, 2006
Granted
Dec 25, 2012
Kind
B2
Art Unit
2436
USPC
713/165
Abstract

Included in the present disclosure are a system, method and program of instructions operable to protect vital information by combining information about a user and what they are allowed to see with information about essential files that need to be protected on an information handling system. Using intelligent security rules, essential information may be encrypted without encrypting the entire operating system or application files. According to aspects of the present disclosure, shared data, user data, temporary files, paging files, the password hash that is stored in the registry, and data stored on removable media may be protected.

Claims (41)

1. A method for securing data, implemented in a computer system, the computer system including a tangible, non-transitory storage section, a user input device, an output device, and a processor, the method comprising:

receiving, at the computer system, one or more parameters defining a security policy;

dynamically generating, by executing with the processor of the computer system instructions stored in the storage section, one or more intelligent security rules based on the security policy, each rule including at least one qualifier and at least one attribute;

maintaining the one or more intelligent security rules, by executing with the processor of the computer system instructions stored in the storage section, for use by an intelligent security filter operable to leverage the one or more intelligent security rules;

determining whether applying the one or more intelligent security rules would cause a system misconfiguration; and

responsive to the determining step, altering the one or more intelligent security rules to avoid the system misconfiguration.

2. The method of claim 1 , wherein the attribute of each rule indicates whether data identified by the rule is to be encrypted or to remain unencrypted and, if encrypted, what type of encryption and what type of key are to be used for encryption.

3. The method of claim 1 , wherein the qualifier of each rule includes a pathname, path scope, data type, file type, file system owner, file system attributes and running process attributes and owner.

4. The method of claim 1 , wherein the parameters of the security policy include one or more of a pathname, path scope, data type, data ownership, category of data and active process attributes.

5. A system for securing data, comprising: at least one processor; a memory operably associated with the at least one processor; and

a program of instructions storable in the memory and executable by the processor, the program of instructions including:

at least one instruction operable to apply one or more security measures to data identified by one or more of: a pathname, data type, file type, file system owner, file system attributes, and running process attributes and owner, maintain the one or more security measures applicable to data while the data is not in use, and automatically remove the one or more security measures from data in response to detecting a triggering file operation requesting access to the data;

at least one instruction operable to apply one or more security measures to data in response to detecting a triggering file operation, the one or more security measures being applied based on one or more intelligence based encryption rules, each intelligence based encryption rule including one or more of: a path at which data to be protected is stored, a scope of data to be protected stored at the path, and one or more attributes of processes required to be running for data to be protected;

at least one instruction operable to receive one or more parameters defining a security policy, and generate the one or more intelligence based encryption rules based on the security policy;

determining whether applying the one or more intelligent security rules would cause a system misconfiguration; and

responsive to the determining step, altering the one or more intelligent security rules to avoid the system misconfiguration.

6. The system of claim 5 , further comprising the program of instructions including at least one instruction operable to block pending file open operations until after appropriate security measures have been applied to the file.

7. The system of claim 5 , wherein the intelligence based encryption rules include a type of data to be protected.

8. The system of claim 5 , wherein the program of instructions is operable to apply one or more security measures to a paging file associated with one or more applications.

9. The system of claim 5 , wherein the program of instructions is further operable to: store a representation of one or more user credentials in a secure location; remove one or more protective measures from the representation in response to a request seeking access to the representation; and restore the representation to a secure location when not in use by a requesting application.

10. The system of claim 9 , wherein the representation includes a hash of a domain password; and where the secure location is outside a registry.

11. The system of claim 5 , wherein the program of instructions includes at least one instruction operable to apply one or more security measures to data maintained on accessible removable media.

12. A method for securing data, implemented in a computer system, the computer system including a tangible, non-transitory storage section, a processor, a first set of instructions comprising an intelligent security filter, and a second set of instructions comprising a security service, the instructions being executable by the processor, the method comprising:

receiving, at the security service, parameters defining a security policy;

generating, at the security service, one or more intelligent security rules based on the security policy;

detecting, at the intelligent security filter, a triggering file operation generated by an application run by or on behalf of a user;

determining, at the intelligent security, whether any of the one or more intelligent security rules requires a security measure to be applied to data in the storage section in response to the triggering file operation;

responsive to determining that the triggering file operation requires a security measure, applying the security measure at the intelligent security filter;

wherein the detecting, determining, generating, and applying steps are performed without user interaction;

wherein the security measure is applied without direction and control from the application;

determining whether applying the one or more intelligent security rules would cause a system misconfiguration; and

responsive to the determining step, altering the one or more intelligent security rules to avoid the system misconfiguration.

13. The method of claim 12 , wherein the security measure includes one or more techniques selected from the group consisting of: encrypting data and writing the encrypted data to the storage section, decrypting data and providing the decrypted data to the application, and restricting access to data.

14. The method of claim 12 , wherein the one of more intelligent security rules include at least one qualifier and at least one attribute.

15. The method of claim 14 , wherein the attribute of each rule indicates whether data identified by the rule is to be encrypted or to remain unencrypted and, if encrypted, what type of encryption and what type of key are to be used for encryption.

16. The method of claim 14 , wherein the qualifier of each rule includes one or more of: a pathname, path scope, data type, file type, file system owner, file system attributes and running process attributes and owner.

17. The method of claim 12 , wherein at least one of the one or more intelligent security rules requires a security measure to be applied to data stored in removable media.

18. The method of claim 12 , wherein the computer system further includes a network connection, and wherein at least one of the one or more intelligent security rules requires a security measure to be applied to data stored in a remote storage location that is accessed via the network connection.

19. The method of claim 12 , further comprising logging security relevant file operations to the storage section based on the one or more intelligent security rules.

20. The method of claim 12 , wherein the security measure includes encrypting data placed in an application-swap file with the intelligent security filter.

21. The method of claim 12 , wherein the security measure includes decrypting data placed in an application-swap file with the intelligent security filter when the application-swap file is accessed by the application.

Assignments (20)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
MERGER Recorded Feb 17, 2021
From: CREDANT TECHNOLOGIES, INC.
To: DELL MARKETING L.P.
Reel/Frame 055297/0015 →
MERGER Recorded Feb 17, 2021
From: CREDANT TECHNOLOGIES, INC.
To: DELL MARKETING L.P.
Reel/Frame 055297/0357 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
RELEASE OF SECURITY INTEREST Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040065/0618 →
RELEASE OF SECURITY INTEREST Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040040/0001 →
RELEASE OF SECURITY INTEREST Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLANT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040065/0216 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Jan 2, 2014
From: APPASSURE SOFTWARE, INC.; ASAP SOFTWARE EXPRESS, INC.; BOOMI, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL USA L.P.; FORCE10 NETWORKS, INC.; GALE TECHNOLOGIES, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS FIRST LIEN COLLATERAL AGENT
Reel/Frame 031897/0348 →
PATENT SECURITY AGREEMENT (ABL) Recorded Jan 2, 2014
From: DELL INC.; APPASSURE SOFTWARE, INC.; ASAP SOFTWARE EXPRESS, INC.; BOOMI, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL USA L.P.; FORCE10 NETWORKS, INC.; GALE TECHNOLOGIES, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 031898/0001 →
PATENT SECURITY AGREEMENT (TERM LOAN) Recorded Jan 2, 2014
From: DELL INC.; APPASSURE SOFTWARE, INC.; ASAP SOFTWARE EXPRESS, INC.; BOOMI, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL USA L.P.; FORCE10 NETWORKS, INC.; GALE TECHNOLOGIES, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 031899/0261 →
RELEASE OF PATENT SECURITY AGREEMENT Recorded Dec 20, 2012
From: SILICON VALLEY BANK
To: CREDANT TECHNOLOGIES, INC.
Reel/Frame 029507/0288 →
SECURITY AGREEMENT Recorded Apr 8, 2008
From: CREDANT TECHNOLOGIES, INC.
To: SILICON VALLEY BANK
Reel/Frame 020771/0561 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2007
From: BURCHETT, CHRISTOPHER D.; JAYNES, JASON; CHIN, BRYAN; CONSOLVER, DAVID
To: CREDANT TECHNOLOGIES, INC.
Reel/Frame 019697/0756 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 22, 2006
From: BURCHETT, CHRISTOPHER D.; JAYNES, JASON; CHIN, BRYAN; CONSOLVER, DAVID
To: CREDANT TECHNOLOGIES, INC.
Reel/Frame 017655/0146 →
Continuity (3)
Provisional Application 60654165 · Feb 18, 2005
Provisional Application 60736930 · Nov 15, 2005
Related Publication 20070174909A1 · Jul 26, 2007