IP Library Granted Patent US 7,975,034
Granted Patent B1
US 7,975,034 · App. 12/262,369 · Granted Jul 5, 2011

Systems and methods to secure data and hardware through virtualization

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,975,034
App. No.
12/262,369
Granted
Jul 5, 2011
Kind
B1
Abstract

A method to secure data and hardware associated with a computing device is described. A request to initiate a secondary operating system is received. The secondary operating system may be partitioned from a primary operating system. In one embodiment, a reporting program may be executed on the secondary operating system and may also be isolated from the primary operating system. A determination may be made as to whether characteristics of the secondary operating system have been altered. The request to initiate the secondary operating system may be denied if characteristics of the secondary operating system have been altered. However, the secondary operating system may be initiated if characteristics of the secondary operating system have not been altered. In addition, the primary operating system may be initiated if characteristics of the secondary operating system have not been altered.

Claims (40)

1. A computer-implemented method to secure data and hardware associated with a computing device, the method comprising:

Executing, by a processor of the computing device a reporting program;

receiving, by the processor, a request to initiate a secondary operating system, wherein the secondary operating system isolated from a primary operating system by a partition;

Determining, by the processor, whether the partition isolating the secondary operating system has been altered;

upon determining that the partition isolating the secondary operating system has been altered, recording, by the reporting program, information regarding the altering of the partition to a remote server within a predetermined period of time defined by a connectivity timer, denying, by the processor, the request to initiate the secondary operating system and preventing the initiation of the primary operating system;

Determining, by the connectivity timer, whether a connection over a network has been established between the reporting program and the remote server within a predetermined period of time; and

Upon determining that the connection over the network has not been established between the reporting program and the remote server within the predetermined period of time, disabling, by the processor, at least one function of the computing device.

2. The method of claim 1 , further comprising initiating the secondary operating system if the partition isolating the secondary operating system has not been altered.

3. The method of claim 2 , further comprising initiating the primary operating system if the partition isolating the secondary operating system has not been altered.

4. The method of claim 2 , further comprising establishing a connection with a server using a virtualized network interface card (NIC).

5. The method of claim 4 , further comprising sending data associated with the identification of the computing device to the server.

6. The method of claim 4 , further comprising sending data associated with the activity of a user of the computing device to the server.

7. The method of claim 4 , further comprising receiving one or more security commands from the server, wherein the one or more security commands comprise a command to terminate the initiation of the primary operating system.

8. The method of claim 1 , wherein the method is implemented by a software program running on the secondary operating system.

9. The method of claim 1 , wherein the method is executed by a software program implemented on an integrated circuit.

10. A computer system that is configured to secure data and hardware associated with a computing system, the computer system comprising:

A processor configured to implement a primary operating system and a secondary operating system through virtualization;

The processor configured to execute a reporting program;

A verification module implemented by the secondary operating system, the verification module being configured to:

receive a request to initiate a secondary operating system, wherein the secondary operating system isolated from a primary operating system by a partition;

determine whether the partition isolating the secondary operating system has been altered;

denying the request to initiate the secondary operating system and preventing the initiation of the primary operating system if the partition isolating the secondary operating system has been altered;

upon determining that the partition isolating the secondary operating system has been altered, recording, by the reporting program, information regarding the altering of the partition to a remote server within a predetermined period of time defined by a connectivity timer, the verification module is configured to deny the request to initiate the secondary operating system and preventing the initiation of the primary operating system;

the connectivity timer being configured to:

Determine whether a connection over a network has been established between the reporting program and the remote server within a predetermined period of time; and

Upon determining that the connection over the network has not been established between the reporting program and the remote server within the predetermined period of time, the verification module is configured to disable at least one function of the computing device.

11. The computer system of claim 10 , wherein the verification module is further configured to initiate the secondary operating system if the partition isolating the secondary operating system has not been altered.

12. The computer system of claim 11 , wherein the verification module is further configured to initiate the primary operating system if the partition isolating the secondary operating system has not been altered.

13. The computer system of claim 12 , further comprising a virtualized network interface card (NIC) configured to establish a connection with a server.

14. The computer system of claim 13 , wherein the reporting program is configured to send data associated with the identification of the computer system to the server.

15. The computer system of claim 13 , wherein the reporting program is further configured to send data associated with the activity of a user of the computer system to the server.

16. The computer system of claim 13 , wherein the reporting program is further configured to receive one or more security commands from the server, wherein the one or more security commands comprise a command to terminate the initiation of the primary operating system.

17. A computer-program product to securing data and hardware associated with a computing device, the computer-program product comprising a non-transitory computer-readable medium having instructions thereon, the instructions comprising:

Code programmed to execute a reporting program;

code programmed to receive a request to initiate a secondary operating system, wherein the secondary operating system isolated from a primary operating system by a partition;

Code programmed to determine whether the partition isolating the secondary operating system has been altered;

upon determining that the partition isolating the secondary operating system has been altered, recording, by the reporting program, information regarding the altering of the partition to a remote server within a predetermined period of time defined by a connectivity timer, code programmed to deny the request to initiate the secondary operating system and prevent initiation of the primary operating system;

The connectivity timer to determine whether a connection over a network has been established between the reporting program executing on the computing device and the remote server within a predetermined period of time; and

upon determining that the connection over the network has not been established between the reporting program and the remote server within the predetermined period of time, code programmed to disable at least one function of the computing device.

18. The computer-program product of claim 17 , wherein the instructions further comprise code programmed to initiate the primary operating system and the secondary operating system if characteristics of the secondary operating system have not been altered.

Assignments (5)
NOTICE OF SUCCESSION OF AGENCY (REEL 050926 / FRAME 0560) Recorded Sep 13, 2022
From: JPMORGAN CHASE BANK, N.A.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 061422/0371 →
SECURITY AGREEMENT Recorded Sep 13, 2022
From: NORTONLIFELOCK INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062220/0001 →
CHANGE OF NAME Recorded Jan 30, 2020
From: SYMANTEC CORPORATION
To: NORTONLIFELOCK INC.
Reel/Frame 051759/0845 →
SECURITY AGREEMENT Recorded Nov 4, 2019
From: SYMANTEC CORPORATION; BLUE COAT LLC; LIFELOCK, INC,; SYMANTEC OPERATING CORPORATION
To: JPMORGAN, N.A.
Reel/Frame 050926/0560 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 31, 2008
From: CHANDRA, ROBIN; EGOYAN, ARTEM
To: SYMANTEC CORPORATION
Reel/Frame 021768/0094 →