IP Library Granted Patent US 9,275,221
Granted Patent B2
US 9,275,221 · App. 13/875,039 · Granted Mar 1, 2016

Context-aware permission control of hybrid mobile applications

Inventor: Kapil K. Singh (White Plains, NY)
Assignee: GLOBALFOUNDRIES INC.
G06F21/52G06F9/46G06F21/6218G06F21/79H04L29/06H04L63/10H04L63/1425H04M1/72522H04W4/021G06F15/16G06F21/00G06F2221/2105G06F2221/2147H04L63/107H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,275,221
App. No.
13/875,039
Granted
Mar 1, 2016
Kind
B2
Abstract

Controlling access to secure resources of a data processing system is provided. An input-to-output mapping of an application installed on the data processing system is generated that determines whether a secure resource in the data processing system is shared with an external entity associated with the application and under what specified conditions. It is determined whether the specified conditions exist during runtime of the application. In response to determining that the specified conditions do not exist during runtime of the application, sharing of the secure resource of the data processing system with the external entity associated with the application is prevented. In response to determining that the specified conditions do exist during runtime of the application, sharing of the secure resource of the data processing system with the external entity associated with the application is allowed.

Claims (24)

1. A method for controlling access to secure resources of a data processing system that includes a processor unit, the method comprising:

removing, by the data processing system, all direct application programming interface calls by an application install on the data processing system to the secure resources of the data processing system;

requiring, by the data processing system, the application accessing the secure resources of the data processing system to utilize a set of custom information flow control application programming interfaces located in an information flow control module of the data processing system to call the secure resources;

generating, by the data processing system, an input-to-output mapping of the application installed on the data processing system that determines whether a secure resource of the secure resources in the data processing system is shared with an external entity associated with the application and under what specified conditions;

determining, by the data processing system, whether the specified conditions exist during runtime of the application;

responsive to the data processing system determining that the specified conditions do not exist during runtime of the application, preventing, by the data processing system, sharing of the secure resource of the data processing system with the external entity associated with the application; and

responsive to the data processing system determining that the specified conditions do exist during runtime of the application, allowing, by the data processing system, sharing of the secure resource of the data processing system with the external entity associated with the application.

2. The method of claim 1 , further comprising:

monitoring, by the data processing system, a number of accesses sharing the secure resource of the data processing system with the external entity associated with the application;

determining, by the data processing system, whether the number of accesses sharing the secure resource of the data processing system exceeded an access control threshold value corresponding to the secure resource;

responsive to the data processing system determining that the number of accesses sharing the secure resource of the data processing system does not exceed the access control threshold value corresponding to the secure resource, detecting, by the data processing system, whether the specified conditions exist during runtime of the application; and

responsive to the data processing system determining that the number of accesses sharing the secure resource of the data processing system does exceed the access control threshold value corresponding to the secure resource, terminating, by the data processing system, the sharing of the secure resource of the data processing system with the external entity associated with the application.

3. The method of claim 1 , further comprising:

receiving, by the data processing system, a chunk specification that specifies a set of code chunks within the application, each particular code chunk in the set of code chunks is associated with a particular set of one or more secure resources of the data processing system that the particular code chunk has access to and a particular external entity that the particular code chunk has been granted permission to communicate with;

receiving, by the data processing system, a set of context-aware security policies that is associated with the application and defines particular conditions under which permission to access secure resources of the data processing system are granted; and

splitting, by the data processing system, the application into the set of code chunks based on at least one of the chunk specification and the set of context-aware security policies.

4. The method of claim 3 , further comprising:

generating, by the data processing system, a manifest file associated with the application that specifies each requested communication between each code chunk in the set of code chunks within the application and a respective external entity that a particular code chunk communicates with and also specifies a particular secure resource that is shared with the respective external entity based on the chunk specification.

5. The method of claim 4 , further comprising:

verifying, by the data processing system, that selections in the manifest file granting permission to a set of requested external entity communications complies with the set of context-aware security policies; and

displaying, by the data processing system, a notification of non-compliant selections in the manifest file granting permission to the set of requested external entity communications.

6. The method of claim 1 , further comprising:

generating, by the data processing system, a mapping between a set of context-aware security policies that grant permission to access the secure resources of the data processing system and the set of custom information flow control application programming interfaces required to call the secure resources.

7. The method of claim 1 , wherein the specified conditions include at least one of a current geographic location of the data processing system, an identity of the external entity associated with the application, and an access control threshold value associated with the secure resource.

Assignments (6)
RELEASE OF SECURITY INTEREST Recorded May 12, 2021
From: WILMINGTON TRUST, NATIONAL ASSOCIATION
To: GLOBALFOUNDRIES U.S. INC.
Reel/Frame 056987/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 20, 2020
From: WILMINGTON TRUST, NATIONAL ASSOCIATION
To: GLOBALFOUNDRIES INC.
Reel/Frame 054636/0001 →
SECURITY AGREEMENT Recorded Nov 29, 2018
From: GLOBALFOUNDRIES INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 049490/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 5, 2015
From: GLOBALFOUNDRIES U.S. 2 LLC; GLOBALFOUNDRIES U.S. INC.
To: GLOBALFOUNDRIES INC.
Reel/Frame 036779/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 3, 2015
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: GLOBALFOUNDRIES U.S. 2 LLC
Reel/Frame 036550/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 1, 2013
From: SINGH, KAPIL K.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 030329/0896 →
Continuity (1)
Related Publication 20140331317A1 · Nov 6, 2014