IP Library Granted Patent US 8,640,226
Granted Patent B2
US 8,640,226 · App. 12/147,737 · Granted Jan 28, 2014

Mechanisms to secure data on hard reset of device

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,640,226
App. No.
12/147,737
Granted
Jan 28, 2014
Kind
B2
Abstract

Mechanisms to secure data on a hard reset of a device are provided. A hard reset request is detected on a handheld device. Before the hard reset is permitted to process an additional security compliance check is made. Assuming, the additional security compliance check is successful and before the hard reset is processed, the data of the handheld device is backed up to a configurable location.

Claims (32)

1. A machine-implemented method for processing a hard reset operation on a handheld device, comprising:

receiving, via an operating system kernel, the hard reset operation on the handheld device and interacting with hardware of the handheld device to disable all interrupts;

enforcing a configured security policy before permitting the hard reset operation to proceed, wherein enforcing further includes prompting a user of the handheld device to enter authentication credentials defined by the configured security policy before proceeding further with the hard reset operation on the handheld device, the authentication credentials are different from other authentication credentials of the user for access to the handheld device or log on to the handheld device, and the authentication credentials are a secure Personal Identification Number (PIN) that has to be provided within a limited time duration by the user otherwise the interrupts are re-enabled; and

backing up user data held on the handheld device to a different location that is external from the handheld device when the security policy is successfully enforced.

2. The method of claim 1 further comprising, passing the hard reset operation along to a kernel of an operating system to be processed on the handheld device once the user data is backed up.

3. The method of claim 1 , wherein receiving further includes receiving, by an application, a notice from a kernel of an operating system of the handheld device that the hard reset operation has been requested on the handheld device.

4. The method of claim 1 , wherein enforcing further includes accessing the configured security policy on the handheld device from a location that is not subject to the hard reset operation.

5. The method of claim 1 , wherein backing up further includes identifying the location as a removable memory card interfaced to the handheld device or as a remote storage location located over a wide-area network that the handheld device is in communication with.

6. A machine-implemented method, comprising:

identifying an attempt by a resource to perform a hard reset on a handheld device and disabling all interrupts on the handheld device;

requesting additional credentials from the resource to authorize the hard reset; and

verifying the additional credentials before proceeding with the hard reset on the handheld device, the additional credentials are different from other credentials of the resource that the resource has for log on or access to the handheld device, and the authentication credentials are a secure Personal Identification Number (PIN) that has to be provided within a limited time duration by the resource otherwise the interrupts are re-enabled.

7. The method of claim 6 further comprising, backing up resource data from the handheld device to a location that is independent from the handheld device before proceeding with the hard reset on the handheld device.

8. The method of claim 7 , wherein backing up further includes backing up the resource data to a remote and external network location.

9. The method of claim 7 , wherein backing up further includes backing up the resource data to a removable memory card inserted into the handheld device.

10. The method of claim 6 , wherein requesting further includes prompting a user that is identified as the resource to enter an identifier and a password that are assigned to the hard reset.

11. The method of claim 10 , wherein prompting further includes identifying the identifier and the password as being associated with an administrator assigned set of credentials that is different from a resource identifier and a resource password used by the user to access the handheld device on startup of the handheld device.

12. A machine-implemented system, comprising:

a hard reset validator implemented in a machine-accessible and readable medium that process on a handheld device; and

a backup service implemented in a machine-accessible and readable medium and to process on the handheld device;

wherein the hard reset validator ensures that additional security compliance is achieved when a hard reset is requested on the handheld device by disabling all interrupts on the handheld device, and wherein when the additional security compliance is achieved the backup service backs up user data located on the handheld device to a different location that is external and independent from the handheld device before the hard reset is processed on the handheld device, the additional security compliance ensures that a user provides different credentials from what the user has to logging into or accessing the handheld device, and the different credentials are a secure Personal Identification Number (PIN) that has to be provided within a limited time duration by the user otherwise the interrupts are re-enabled.

13. The system of claim 12 , wherein the additional security compliance is pre-defined as a policy located in a secure area of the handheld device.

14. The system of claim 12 , wherein hard reset validator interacts with a user in response to the additional security compliance to acquire an administrator-defined set of credentials that the hard reset validator validates before permitting the hard reset to proceed on the handheld device.

15. The system of claim 12 , wherein the hard reset validator is triggered in response to a notification from a kernel process of an operating system for the handheld device that receives the hard reset as an OS interrupt.

16. The system of claim 12 , wherein the backup service uses a backup policy to identify types of the user data to backup and to identify the different location for storing the user data.

17. The system of claim 12 , wherein when the backup service stores the user data to one or more of the following: a removable media card interfaced to the handheld device, another device interfaced to the handheld device, and a network storage location located over a wide-area network connection from the handheld device.

18. A machine-implemented system, comprising:

an operating system (OS) kernel implemented in a machine-accessible and readable medium and that processes on a handheld device; and

a hard reset interrupt handler implemented in a machine-accessible and readable medium and to process within the OS kernel of the handheld device;

wherein a kernel process of the OS kernel notifies the hard reset interrupt handler when a hard reset operation is issued on the handheld device and waits for further instruction from the hard reset interrupt handler after notification and disables all interrupts, and wherein the hard reset interrupt handler performs a security compliance check to ensure the hard reset operation is permissible and when it is notifies the kernel process to proceed with the hard reset operation and when it is not notifies the kernel process to ignore the hard reset operation, wherein the hard reset interrupt handler prompts a user of the handheld device for an additional secure Personal identification Number (PIN) in response to the additional security compliance check that are different from an identifier and password of the user to login or access the handheld device, and the secure PIN has to be provided within a limited time duration by the user otherwise the interrupts are re-enabled.

19. The system of claim 18 , wherein when the security compliance check indicates that the hard reset operation is permissible and before the hard reset interrupt handler notifies the kernel process, the hard reset interrupt handler backs up data stored on the handheld device.

20. The system of claim 19 , wherein the data is backed up to a location that is independent and separate from the handheld device.

Assignments (16)
RELEASE OF SECURITY INTEREST REEL/FRAME 035656/0251 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: BORLAND SOFTWARE CORPORATION; ATTACHMATE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.)
Reel/Frame 062623/0009 →
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0718 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC); BORLAND SOFTWARE CORPORATION; MICRO FOCUS (US), INC.; SERENA SOFTWARE, INC; ATTACHMATE CORPORATION; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.); NETIQ CORPORATION
Reel/Frame 062746/0399 →
CORRECTIVE ASSIGNMENT TO CORRECT THE TO CORRECT TYPO IN APPLICATION NUMBER 10708121 WHICH SHOULD BE 10708021 PREVIOUSLY RECORDED ON REEL 042388 FRAME 0386. ASSIGNOR(S) HEREBY CONFIRMS THE NOTICE OF SUCCESSION OF AGENCY. Recorded Jul 26, 2018
From: BANK OF AMERICA, N.A., AS PRIOR AGENT
To: JPMORGAN CHASE BANK, N.A., AS SUCCESSOR AGENT
Reel/Frame 048793/0832 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ATTACHMATE CORPORATION; BORLAND SOFTWARE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE, INC.; ENTIT SOFTWARE LLC; ARCSIGHT, LLC; SERENA SOFTWARE, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0718 →
NOTICE OF SUCCESSION OF AGENCY Recorded May 2, 2017
From: BANK OF AMERICA, N.A., AS PRIOR AGENT
To: JPMORGAN CHASE BANK, N.A., AS SUCCESSOR AGENT
Reel/Frame 042388/0386 →
CHANGE OF NAME Recorded Sep 13, 2016
From: NOVELL, INC.
To: MICRO FOCUS SOFTWARE INC.
Reel/Frame 040020/0703 →
SECURITY INTEREST Recorded May 13, 2015
From: MICRO FOCUS (US), INC.; BORLAND SOFTWARE CORPORATION; ATTACHMATE CORPORATION; NETIQ CORPORATION; NOVELL, INC.
To: BANK OF AMERICA, N.A.
Reel/Frame 035656/0251 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 028252/0316 Recorded Nov 24, 2014
From: CREDIT SUISSE AG
To: NOVELL, INC.
Reel/Frame 034469/0057 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 028252/0216 Recorded Nov 24, 2014
From: CREDIT SUISSE AG
To: NOVELL, INC.
Reel/Frame 034470/0680 →
GRANT OF PATENT SECURITY INTEREST FIRST LIEN Recorded May 23, 2012
From: NOVELL, INC.
To: CREDIT SUISSE AG, AS COLLATERAL AGENT
Reel/Frame 028252/0216 →
GRANT OF PATENT SECURITY INTEREST SECOND LIEN Recorded May 23, 2012
From: NOVELL, INC.
To: CREDIT SUISSE AG, AS COLLATERAL AGENT
Reel/Frame 028252/0316 →
RELEASE OF SECURITY IN PATENTS SECOND LIEN (RELEASES RF 026275/0018 AND 027290/0983) Recorded May 22, 2012
From: CREDIT SUISSE AG, AS COLLATERAL AGENT
To: NOVELL, INC.
Reel/Frame 028252/0154 →
RELEASE OF SECURITY INTEREST IN PATENTS FIRST LIEN (RELEASES RF 026270/0001 AND 027289/0727) Recorded May 22, 2012
From: CREDIT SUISSE AG, AS COLLATERAL AGENT
To: NOVELL, INC.
Reel/Frame 028252/0077 →
GRANT OF PATENT SECURITY INTEREST (SECOND LIEN) Recorded May 13, 2011
From: NOVELL, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 026275/0018 →
GRANT OF PATENT SECURITY INTEREST Recorded May 12, 2011
From: NOVELL, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 026270/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 30, 2008
From: CHATURVEDI, PRADEEP KUMAR; SAHOO, PRASANTA KUMAR
To: NOVELL, INC.
Reel/Frame 021167/0869 →