IP Library Granted Patent US 8,850,549
Granted Patent B2
US 8,850,549 · App. 12/772,914 · Granted Sep 30, 2014

Methods and systems for controlling access to resources and privileges per process

Inventors: Peter David Beauregard (Dover, NH); Andrey Kolishchak (Luxembourg, RU); Shannon E. Jennings (Exeter, NH); Robert F. Hogan (Portsmouth, NH)
Assignee: BeyondTrust Software, Inc.
G06F9/468G06F21/604
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,850,549
App. No.
12/772,914
Granted
Sep 30, 2014
Kind
B2
Abstract

To control privileges and access to resources on a per-process basis, an administrator creates a rule that may be applied to modify a token of a process. The rule may include an application-criterion set and changes to be made to the groups and/or privileges of the token. The rule may be set as a policy within a group policy object (GPO), where a GPO is associated with one or more groups of computers or users. When a GPO containing a rule is applied to a computer, a driver installed on the computer may access the rule(s) anytime a logged-on user executes a process. If the executed process satisfies the criterion set of a rule, the changes contained within the rule are made to the process token, and the user has expanded and/or contracted access and/or privileges for only that process.

Claims (46)

1. A method comprising:

detecting an event related to a process before execution of the process by a processor of a digital device;

identifying one or more applicable rules that apply to the process;

receiving from a user justification text describing a reason for the user to have access rights to the process on the digital device, the reason being provided by the user;

configuring a token for the process, wherein the token relates to a level of access of the user of the digital device to the process in accordance with the one or more applicable rules, the configuring of the token occurring in response to the receiving the justification text;

before executing the process, accessing the token of the process to determine at least one of a permission, a privilege, or an integrity level with which to execute the process; and

allowing the user to access the process based, at least in part, on the determination.

2. The method of claim 1 , wherein the one or more applications rules is at least one of a hash rule, a path rule, a folder rule, an MSI Path rule, an MSI folder rule, an ActiveX rule, a certificate rule, a shell rule, and a CD/DVD rule.

3. The method of claim 1 , wherein the method further comprises authenticating the user and wherein the configuration of the token only occurs if the user is authenticated.

4. The method of claim 1 , wherein the configuration of the token only occurs if the process is owned by an Administrators Group.

5. The method of claim 1 , wherein the configuration of the token occurs for all processes launched by a specified application.

6. The method of claim 1 , wherein the method further comprises applying the one or more applicable rules to all programs in all subfolders of a specified folder.

7. The method of claim 1 , wherein the justification text is logged to a system event log.

8. A computer readable non-transitory medium comprising executable instructions, the instructions being executable by a processor to perform a method, the method comprising:

detecting an event related to a process before execution of the process by a processor of a digital device;

identifying one or more applicable rules that apply to the process;

receiving from a user justification text describing a reason for the user to have access rights to the process on the digital device, the reason being provided by the user;

configuring a token for the process, wherein the token relates to a level of access of the user of the digital device to the process in accordance with the one or more applicable rules, the configuring of the token occurring in response to the receiving the justification text;

before executing the process, accessing the token of the process to determine at least one of a permission, a privilege, or an integrity level with which to execute the process; and

allowing the user to access the process based, at least in part, on the determination.

9. The computer readable non-transitory medium of claim 8 , wherein the one or more applicable rules is at least one of a hash rule, a path rule, a folder rule, an MSI Path rule, an MSI folder rule, an ActiveX rule, a certificate rule, a shell rule, and a CD/DVD rule.

10. The computer readable non-transitory medium of claim 8 , wherein the method further comprises authenticating the user and wherein the configuration of the token only occurs if the user is authenticated.

11. The computer readable non-transitory medium of claim 8 , wherein the configuration of the token only occurs if the process is owned by an Administrators Group.

12. The computer readable non-transitory medium of claim 8 , wherein the configuration of the token occurs for all processes launched by a specified application.

13. The computer readable non-transitory medium of claim 8 , wherein the method further comprises applying the one or more applicable rules to all programs in all subfolders of a specified folder.

14. The computer readable non-transitory medium of claim 8 , wherein the configuration of the token only occurs if the user enters a justification.

15. The computer readable non-transitory medium of claim 8 , wherein the justification text is logged to a system event log.

16. A method comprising:

prior to setting an integrity level for an indicated process executed by a processor of a digital device, requesting justification text for setting the integrity level from a user of the digital device, the justification text requesting that the integrity level be set, the justification text describing a reason, by the user, for setting the integrity level, the integrity level corresponding to access rights of the user to the indicated process;

receiving from the user the justification text;

setting, in response to the receiving the justification text, the integrity level for the indicated process by the processor, wherein setting the integrity level of the indicated process does not modify an integrity level of any non-indicated process;

before execution of the indicated process, accessing an integrity level indication to determine under what integrity level to execute the indicated process; and

evaluating whether a non-indicated process is allowed to interact with the indicated process based on the determination.

17. The method of claim 16 , further comprising, prior to setting the integrity level, verifying an identity of the user requesting that the integrity level be set.

18. The method of claim 16 , wherein setting the integrity level is done in accordance with at least one rule.

19. The method of claim 18 , wherein the at least one rule is a shell rule, and wherein the integrity level is set for the indicated process upon receiving an on-demand request.

20. The method of claim 18 , wherein the at least one rule is a certificate rule, and wherein the integrity level is set if at least one criterion of a certificate of the indicated process is met.

21. The method of claim 18 , wherein the at least one rule is an administrator-defined rule, and wherein the integrity level is set upon providing a user credential.

22. The method of claim 16 , wherein the justification text is logged to a system event log.

23. A computer readable non-transitory medium comprising executable instructions, the instructions being executable by a processor to perform a method, the method comprising:

prior to setting an integrity level for an indicated process executed by a processor of a digital device, requesting justification text for setting the integrity level from a user of the digital device, the justification text requesting that the integrity level be set, the justification text describing a reason, by the user, for setting the integrity level, the integrity level corresponding to access rights to the indicated process;

receiving from the user the justification text;

setting, in response to the receiving the justification text, the integrity level for the indicated process by the processor, wherein setting the integrity level of the indicated process does not modify an integrity level of any non-indicated process;

before execution of the indicated process, accessing an integrity level indication to determine under what integrity level to execute the indicated process; and

evaluating whether a non-indicated process is allowed to interact with the indicated process based on the determination.

24. The computer readable non-transitory medium of claim 23 , wherein the justification text is logged to a system event log.

Assignments (14)
MERGER Recorded Dec 5, 2023
From: BEYONDTRUST SOFTWARE, INC.
To: BEYONDTRUST CORPORATION
Reel/Frame 065764/0741 →
RELEASE OF SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 28, 2023
From: JEFFERIES FINANCE LLC,
To: BEYONDTRUST SOFTWARE, INC.
Reel/Frame 065697/0345 →
RELEASE OF FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 28, 2023
From: JEFFERIES FINANCE LLC
To: BEYONDTRUST SOFTWARE, INC.
Reel/Frame 065696/0798 →
SECURITY INTEREST Recorded Nov 28, 2023
From: BEYONDTRUST CORPORATION
To: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
Reel/Frame 065682/0447 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 4, 2018
From: BEYONDTRUST SOFTWARE, INC.
To: JEFFERIES FINANCE LLC, AS THE COLLATERAL AGENT
Reel/Frame 047195/0252 →
RELEASE OF SECURITY INTEREST UNDER REEL/FRAME NO. 044496/0009 Recorded Oct 3, 2018
From: ARES CAPITAL CORPORATION
To: BEYONDTRUST SOFTWARE, INC.
Reel/Frame 047189/0516 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Oct 3, 2018
From: BEYONDTRUST SOFTWARE, INC.
To: JEFFERIES FINANCE LLC, AS THE COLLATERAL AGENT
Reel/Frame 047190/0238 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 033825/0238 Recorded Nov 21, 2017
From: OAKTREE FUND ADMINISTRATION, LLC (AS SUCCESSOR TO FIFTH STREET MANAGEMENT LLC)
To: BEYONDTRUST SOFTWARE, INC.
Reel/Frame 044495/0893 →
PATENT SECURITY AGREEMENT Recorded Nov 21, 2017
From: BEYONDTRUST SOFTWARE, INC.
To: ARES CAPITAL CORPORATION
Reel/Frame 044496/0009 →
ASSIGNMENT OF PATENT SECURITY AGREEMENT Recorded Oct 20, 2017
From: FIFTH STREET MANAGEMENT LLC
To: OAKTREE FUND ADMINISTRATION, LLC
Reel/Frame 044242/0585 →
RELEASE OF SECURITY INTEREST Recorded Sep 25, 2014
From: WELLS FARGO CAPITAL FINANCE, LLC
To: BEYONDTRUST SOFTWARE, INC.; BEYONDTRUST CORPORATION; BEYONDTRUST, INC.
Reel/Frame 033820/0518 →
PATENT SECURITY AGREEMENT Recorded Sep 25, 2014
From: BEYONDTRUST SOFTWARE, INC.
To: FIFTH STREET MANAGEMENT LLC
Reel/Frame 033825/0238 →
SECURITY INTEREST Recorded Apr 21, 2011
From: BEYONDTRUST SOFTWARE, INC.; BEYONDTRUST CORPORATION
To: WELLS FARGO CAPITAL FINANCE, LLC, AS AGENT
Reel/Frame 026167/0636 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 14, 2010
From: BEAUREGARD, PETER DAVID; KOLISHCHAK, ANDREY; JENNINGS, SHANNON E.; HOGAN, ROBERT F.
To: BEYONDTRUST SOFTWARE, INC.
Reel/Frame 025141/0701 →
Continuity (2)
Provisional Application 61174513 · May 1, 2009
Related Publication 20110030045A1 · Feb 3, 2011