IP Library Patent Application 12304859
Patent Application
App. No. 12/304,859

Implementing a Process-Based Protection System in a User-Based Protection Environment in a Computing Device

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
12/304,859
Abstract

A computing device having a security model based on user permissions is provided with an ability to emulate a security model based on process capabilities by providing each executable program on the device with a separate user identity.

Claims (9)

1 . A method of operating a computing device having a security model based on user permissions, the method comprising enabling the computing device to emulate a capability based security model by providing each executable program on the device with a separate user identity.

2 . A method according to claim 1 wherein the user identity given to an executable program is either

a. determined at install time, by means including but not limited to the use of the next free identity in a sequence; or

b. determined before install time, by means including but not limited to the inclusion of the identity in the program package to be installed.

3 . A method according to claim 1 wherein each user identity confers an ability to access a private file storage area reserved for that user identity.

4 . A method according to claim 1 wherein user identities are collected into group identities, which may not be mutually exclusive, and in which membership of any group confers an ability to access system resources denied to user identities that are not members of that group.

5 . A method according to claim 1 wherein the computing device comprises a Unix operating system or a related operating system, and wherein the setuid and setgid bits of an executable program are used to enable a process to adopt the user and group identities for that program.

6 . A computing device arranged to operate in accordance with a method as claimed in claim 1 .

7 . An operating system for causing a computing device to operate in accordance with a method as claimed in claim 1 .

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 6, 2009
From: HARKER, ANDREW; ALLEN, MATTHEW
To: NOKIA CORPORATION
Reel/Frame 022359/0129 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 11, 2009
From: SYMBIAN LIMITED; SYMBIAN SOFTWARE LIMITED
To: NOKIA CORPORATION
Reel/Frame 022240/0266 →