IP Library Granted Patent US 8,959,657
Granted Patent B2
US 8,959,657 · App. 13/829,511 · Granted Feb 17, 2015

Secure data management

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,959,657
App. No.
13/829,511
Granted
Feb 17, 2015
Kind
B2
Abstract

The disclosed subject matter includes a method. The method includes identifying an attempt to access, by an application instance running in a user space of an operating system, a first security zone of a computer readable medium, where the first security zone is associated with a first security level. The method further includes determining whether a restriction level associated with the application instance is higher than the first security level, where the restriction level is a function of previous security zones that have been accessed by the application instance. When the restriction level associated with the application instance is higher than the first security level, the method would prevent the application instance from writing to the first security zone. When the restriction level associated with the application instance is not higher than the first security level, the method would authorize the application instance to access the first security zone.

Claims (51)

1. An apparatus comprising:

a non-transitory memory storing computer readable instructions;

a processor in communication with the memory and with a non-transitory computer readable medium having a first security zone, wherein the computer readable instructions are configured to cause the processor to:

receive a request, from an application instance running in a user space of an operating system, to access the first security zone, wherein the first security zone is associated with a first security level;

determine whether a restriction level associated with the application instance is higher than the first security level, wherein the restriction level associated with the application instance is a function of previous security zones that have been accessed by the application instance;

when the restriction level associated with the application instance is higher than the first security level, prevent the application instance from accessing the first security zone; and

when the restriction level associated with the application instance is not higher than the first security level, authorize the application instance to access the first security zone.

2. The apparatus of claim 1 , wherein the non-transitory memory further comprises instructions that cause the processor to:

determine whether the application instance is associated with any restriction level; and

when the application instance is not associated with any restriction level, authorize the application instance to access the first security zone.

3. The apparatus of claim 1 , wherein the restriction level associated with the application instance is a highest security level of all previous security zones that have been accessed by the application instance.

4. The apparatus of claim 1 , wherein the association between the first security zone and the first security level is maintained in a configuration file stored in the non-transitory memory.

5. The apparatus of claim 1 , wherein the request to access the first security zone includes a request to authorize a write operation to the first security zone.

6. The apparatus of claim 1 , wherein the non-transitory memory further comprises instructions that cause the processor to:

receive a request, from the application instance, to authorize a read operation to a second security zone of the computer readable medium, wherein the second security zone is associated with a second security level;

determine whether the restriction level associated with the application instance is higher than the second security level; and

when the restriction level associated with the application instance is higher than the second security level, modify the restriction level of the application instance as the second security level.

7. The apparatus of claim 6 , wherein the non-transitory memory further comprises instructions that cause the processor to:

determine whether the application instance is associated with any restriction level; and

when the application instance is not associated with any restriction level, associate the application instance with a restriction level, wherein the restriction level is set as the second security level.

8. The apparatus of claim 1 , wherein the instructions are configured to be executed in a kernel space of the operating system.

9. The apparatus of claim 8 , wherein the instructions comprise a loadable kernel module configured to be executed in the kernel space of the operating system.

10. A non-transitory computer readable medium having executable instructions operable to cause an apparatus to:

identify an attempt, by an application instance running in a user space of an operating system, to access a first security zone of non-transitory memory, wherein the first security zone is associated with a first security level;

determine whether a restriction level associated with the application instance is higher than the first security level, wherein the restriction level associated with the application instance is a function of previous security zones that have been accessed by the application instance;

when the restriction level associated with the application instance is higher than the first security level, prevent the application instance from writing to the first security zone; and

when the restriction level associated with the application instance is not higher than the first security level, authorize the application instance to access the first security zone.

11. The computer readable medium of claim 10 , further comprising executable instructions operable to cause the apparatus to:

determine whether the application instance is associated with any restriction level; and

when the application instance is not associated with any restriction level, authorize the application instance to access the first security zone.

12. The computer readable medium of claim 10 , further comprising executable instructions operable to cause the apparatus to:

identify an attempt by the application instance to perform a read operation to a second security zone of the computer readable medium, wherein the second security zone is associated with a second security level;

determine whether the restriction level associated with the application instance is higher than the second security level; and

when the restriction level associated with the application instance is higher than the second security level, modify the restriction level of the application instance as the second security level.

13. The computer readable medium of claim 12 , further comprising executable instructions operable to cause the apparatus to:

determine whether the application instance is associated with any restriction level; and

when the application instance is not associated with any restriction level, associate the application instance with a restriction level, wherein the restriction level is set as the second security level.

14. A method comprising:

identifying, by a module in a computer system, an attempt to access, by an application instance running in a user space of an operating system, a first security zone of a computer readable medium, wherein the first security zone is associated with a first security level;

determining, by the module, whether a restriction level associated with the application instance is higher than the first security level, wherein the restriction level is a function of previous security zones that have been accessed by the application instance;

when the restriction level associated with the application instance is higher than the first security level, preventing the application instance from writing to the first security zone; and

when the restriction level associated with the application instance is not higher than the first security level, authorizing the application instance to access the first security zone.

15. The method of claim 14 , further comprising:

receiving a request, from the application instance, to authorize a read operation to a second security zone of the computer readable medium, wherein the second security zone is associated with a second security level;

determining whether the restriction level associated with the application instance is higher than the second security level; and

when the restriction level associated with the application instance is higher than the second security level, modifying the restriction level of the application instance as the second security level.

16. The method of claim 14 , wherein the association between the first security zone and the first security level is maintained in a configuration file stored in memory.

17. The method of claim 14 , wherein the module in the computer system is running in a kernel space of the operating system.

18. The method of claim 17 , wherein the module comprises a loadable kernel module running in the kernel space of the operating system.

19. The method of claim 17 , wherein identifying the attempt to access the first security zone comprises receiving, from the application instance, a system call to authorize a write operation to the first security zone.

20. The method of claim 17 , wherein authorizing the application instance to access the first security zone comprises sending, via an interface between the kernel space and the user space, an acknowledgment message to the application instance, indicating that the application instance is authorized to perform a write operation to the first security zone.

Assignments (17)
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY 14633493 WHICH WAS ENTERED INCORRECTLY AS 14633793 PREVIOUSLY RECORDED ON REEL 71176 FRAME 315. ASSIGNOR(S) HEREBY CONFIRMS THE FIRST LIEN NEWCO SECURITY AGREEMENT. Recorded Nov 10, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 073818/0515 →
FIRST LIEN NEWCO SECURITY AGREEMENT Recorded May 5, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 071176/0315 →
SECURITY INTEREST Recorded May 3, 2025
From: IVANTI US LLC
To: ALTER DOMUS (US) LLC
Reel/Frame 071165/0089 →
NOTICE OF SUCCESSION OF AGENCY FOR SECURITY INTEREST AT REEL/FRAME 054665/0873 Recorded Apr 29, 2025
From: BANK OF AMERICA, N.A., AS RESIGNING AGENT
To: ALTER DOMUS (US) LLC, AS SUCCESSOR AGENT
Reel/Frame 071123/0386 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; IVANTI, INC.; MOBILEIRON, INC.; IVANTI US LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 054665/0062 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; INVANTI, INC.; MOBILEIRON, INC.; INVANTI US LLC
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 054665/0873 →
RELEASE OF SECURITY INTEREST : RECORDED AT REEL/FRAME - 43971/0495 Recorded Dec 1, 2020
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: APPSENSE US LLC
Reel/Frame 054560/0278 →
RELEASE OF SECURITY INTEREST : RECORDED AT REEL/FRAME - 43971/0549 Recorded Dec 1, 2020
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: APPSENSE US LLC
Reel/Frame 054560/0389 →
CHANGE OF NAME Recorded Mar 5, 2019
From: APPSENSE US LLC
To: IVANTI US LLC
Reel/Frame 048511/0832 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Sep 15, 2017
From: APPSENSE US LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 043971/0495 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Sep 15, 2017
From: APPSENSE US LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 043971/0549 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 25, 2017
From: APPSENSE LIMITED
To: APPSENSE US LLC
Reel/Frame 043406/0821 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORDED AT R/F 038333/0821 Recorded Sep 28, 2016
From: JEFFERIES FINANCE LLC
To: APPSENSE LIMITED
Reel/Frame 040171/0172 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORDED AT R/F 038333/0879 Recorded Sep 28, 2016
From: JEFFERIES FINANCE LLC
To: APPSENSE LIMITED
Reel/Frame 040169/0981 →
SECURITY INTEREST Recorded Apr 20, 2016
From: APPSENSE LIMITED
To: JEFFERIES FINANCE LLC
Reel/Frame 038333/0821 →
SECURITY INTEREST Recorded Apr 20, 2016
From: APPSENSE LIMITED
To: JEFFERIES FINANCE LLC
Reel/Frame 038333/0879 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 19, 2013
From: WALTON, TRAVIS; DELIVETT, PAUL; SOMERFIELD, RICHARD J.
To: APPSENSE LIMITED
Reel/Frame 030044/0223 →