IP Library Granted Patent US 8,474,011
Granted Patent B2
US 8,474,011 · App. 13/287,475 · Granted Jun 25, 2013

On-line centralized and local authorization of executable files

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,474,011
App. No.
13/287,475
Granted
Jun 25, 2013
Kind
B2
Abstract

A system and system for controlling the execution of executable files. The executables are identified by either a cryptographic digest or a digital certificate. The cryptographic digest is computed from the binary image of the executable. An executable that is attempting to execute is intercepted by a protection module that consults a database of stored rules over a secure channel to determine whether or not the executable can be identified as a permitted executable and whether or not it has permission to execute on a particular computer system under certain specified conditions. If a stored permission is available, it is used to control the execution. Otherwise, the user is consulted for permission.

Claims (17)

1. A method comprising:

(a) attempting to execute a first executable file on a first computer system associated with a first user;

(b) intercepting a system service in response to the attempting step (a);

(c) after the attempting step (a), determining whether to execute the first executable file, wherein the determining step comprises examining a set of global authorization rules;

(i) wherein at least some of the rules of the set of global authorization rules at least include a listing of:

(A) applicable users;

(B) applicable executable files;

(ii) wherein, when one located rule of the set of global authorization rules includes both (I) the first user in the listing of applicable users and (II) the first executable file in the listing of applicable executable files, the first computer system applies a stored permission associated with the one located rule to determine whether it is permissible to execute the first executable file;

(iii) wherein, when the set of global authorization rules is free of any one rule having both (A) the first user in the listing of applicable users and (B) the first executable file in the listing of applicable executable files, the first computer system examines a local authorization listing associated with the first user to determine whether there is a stored user input associated with the first executable file;

(A) wherein, when the local authorization listing associated with the first user includes a stored user input associated with the first executable file, the computer system applies the stored user input associated with the first executable file to determine whether it is permissible to execute the first executable file;

(B) wherein, when the local authorization listing is absent of a stored user input associated with the first executable file, the computer system obtains a user input from the first user to determine whether it is permissible to execute the first executable tile, and stores the user input in the local authorization listing relative to the first user and the first executable file; and

(d) after the examining step (c), invoking the system service when it is permissible to execute the first executable file.

2. The method of claim 1 , wherein the intercepting step (e) comprises identifying the first executable file via a cryptographic digest.

3. The method of claim 2 , wherein the identifying step comprises using a binary image of the first executable file.

4. The method of claim 3 , wherein the binary image is a full binary image.

5. The method of claim 3 , wherein the binary image is a partial binary image.

6. The method of claim 1 , comprising identifying at least some of the applicable executable files via a digital certificate of an executable file.

Assignments (16)
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY 14633493 WHICH WAS ENTERED INCORRECTLY AS 14633793 PREVIOUSLY RECORDED ON REEL 71176 FRAME 315. ASSIGNOR(S) HEREBY CONFIRMS THE FIRST LIEN NEWCO SECURITY AGREEMENT. Recorded Nov 10, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 073818/0515 →
FIRST LIEN NEWCO SECURITY AGREEMENT Recorded May 5, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 071176/0315 →
SECURITY INTEREST Recorded May 2, 2025
From: IVANTI, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071164/0482 →
NOTICE OF SUCCESSION OF AGENCY FOR SECURITY INTEREST AT REEL/FRAME 054665/0873 Recorded Apr 29, 2025
From: BANK OF AMERICA, N.A., AS RESIGNING AGENT
To: ALTER DOMUS (US) LLC, AS SUCCESSOR AGENT
Reel/Frame 071123/0386 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; IVANTI, INC.; MOBILEIRON, INC.; IVANTI US LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 054665/0062 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; INVANTI, INC.; MOBILEIRON, INC.; INVANTI US LLC
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 054665/0873 →
RELEASE OF SECURITY INTEREST : RECORDED AT REEL/FRAME - 41459/0436 Recorded Dec 1, 2020
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: HEAT SOFTWARE USA INC.
Reel/Frame 054560/0713 →
RELEASE OF SECURITY INTEREST : RECORDED AT REEL/FRAME - 41052/0735 Recorded Dec 1, 2020
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: HEAT SOFTWARE USA INC.
Reel/Frame 054560/0744 →
MERGER Recorded Jan 10, 2019
From: HEAT SOFTWARE USA INC.
To: IVANTI, INC.
Reel/Frame 047950/0296 →
RELEASE OF SECURITY INTERESTS IN PATENTS AT REEL/FRAME NO. 33380/0644 Recorded Jan 21, 2017
From: WELLS FARGO BANK, NATIONAL ASSOCIATION
To: HEAT SOFTWARE USA INC., AS SUCCESSOR IN INTEREST TO LUMENSION SECURITY, INC.
Reel/Frame 041052/0794 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jan 20, 2017
From: HEAT SOFTWARE USA INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 041459/0436 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jan 20, 2017
From: HEAT SOFTWARE USA INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 041052/0735 →
MERGER AND CHANGE OF NAME Recorded Jan 18, 2017
From: LUMENSION SECURITY INC.; HEAT SOFTWARE USA INC.
To: HEAT SOFTWARE USA INC.
Reel/Frame 041010/0854 →
RELEASE OF SECURITY INTEREST Recorded Oct 25, 2016
From: CONSORTIUM FINANCE, LLC
To: NETMOTION WIRELESS HOLDINGS, INC.; NETMOTION WIRELESS, INC.; LUMENSION SECURITY, INC.
Reel/Frame 040479/0001 →
PATENT SECURITY AGREEMENT (SECOND LIEN) Recorded Jul 23, 2014
From: NETMOTION WIRELESS HOLDINGS, INC.; NETMOTION WIRELESS, INC.; LUMENSION SECURITY, INC.
To: CONSORTIUM FINANCE, LLC
Reel/Frame 033381/0536 →
PATENT SECURITY AGREEMENT Recorded Jul 22, 2014
From: LUMENSION SECURITY, INC.
To: WELLS FARGO BANK, NATIONAL ASSOCIATION
Reel/Frame 033380/0644 →