IP Library Granted Patent US 9,195,836
Granted Patent B2
US 9,195,836 · App. 14/025,480 · Granted Nov 24, 2015

Techniques for secure data management in a distributed environment

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,195,836
App. No.
14/025,480
Granted
Nov 24, 2015
Kind
B2
Abstract

Techniques for secure data management in a distributed environment are provided. A secure server includes a modified operating system that just allows a kernel application to access a secure hard drive of the secure server. The hard drive comes prepackaged with a service public and private key pair for encryption and decryption services with other secure servers of a network. The hard drive also comes prepackaged with trust certificates to authenticate the other secure servers for secure socket layer (SSL) communications with one another, and the hard drive comes with a data encryption key, which is used to encrypt storage of the secure server. The kernel application is used during data restores, data backups, and/or data versioning operations to ensure secure data management for a distributed network of users.

Claims (11)

1. A method, comprising:

modifying, via a processor, an operating system (OS) during a boot of a machine by decreasing original permissions of root resources maintained by the OS, wherein the OS designates the root resources as privileged resources as designated by the OS, and wherein original permissions are access-level rights for the root resources for operating within the OS, and wherein the root resources are programs that run in the OS;

preventing, via the processor, the privileged resources from reading and writing to a secure storage based on the decreased permissions during operation of the machine by the modified OS, wherein the original permissions permitted reading and writing to the secure storage before the original permissions were modified during the boot of the machine to establish the decreased permissions;

providing, via the processor and through the modified OS, authorized network-based resources access to the secure storage during operation of the machine over a secure network connection; and

maintaining, by the processor, trust certificates for secure servers on the secure storage and utilizing the trust certificates when providing access to the secure storage to the authorized network-based resources, wherein the secure servers are the authorized network-based resources.

2. The method of claim 1 , wherein modifying further includes keeping file permissions for an existing file system of the OS unchanged even with the decreased permissions for the privileged resources on the OS.

3. The method of claim 1 further comprising, providing, by the processor, access to the secure storage to just a special kernel process of the modified OS, wherein the special kernel process manages and provides the access of the authorized network-based resources to the secure storage.

4. The method of claim 1 further comprising, maintaining, by the processor, a private key used to validate the trust certificates and to provide decryption services to the secure servers.

5. The method of claim 4 further comprising, loading, by the processor, the trust certificates from the secure storage in a fixed address range of memory for the machine during the boot, wherein the machine includes the OS.

6. The method of claim 4 further comprising, maintaining, by the processor, a random key on the secure storage for encrypting data associated with one or more storage environments of the secure servers and utilizing the data that is encrypted when providing access to the secure storage to the secure servers.

7. The method of claim 6 further comprising, encrypting, by the processor, backup data with the random key on the secure storage for backup operations, version control, and restore operations associated with the one or more storage environments.

Assignments (7)
RELEASE OF SECURITY INTEREST REEL/FRAME 035656/0251 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: BORLAND SOFTWARE CORPORATION; ATTACHMATE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.)
Reel/Frame 062623/0009 →
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0718 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC); BORLAND SOFTWARE CORPORATION; MICRO FOCUS (US), INC.; SERENA SOFTWARE, INC; ATTACHMATE CORPORATION; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.); NETIQ CORPORATION
Reel/Frame 062746/0399 →
CORRECTIVE ASSIGNMENT TO CORRECT THE TO CORRECT TYPO IN APPLICATION NUMBER 10708121 WHICH SHOULD BE 10708021 PREVIOUSLY RECORDED ON REEL 042388 FRAME 0386. ASSIGNOR(S) HEREBY CONFIRMS THE NOTICE OF SUCCESSION OF AGENCY. Recorded Jul 26, 2018
From: BANK OF AMERICA, N.A., AS PRIOR AGENT
To: JPMORGAN CHASE BANK, N.A., AS SUCCESSOR AGENT
Reel/Frame 048793/0832 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ATTACHMATE CORPORATION; BORLAND SOFTWARE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE, INC.; ENTIT SOFTWARE LLC; ARCSIGHT, LLC; SERENA SOFTWARE, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0718 →
NOTICE OF SUCCESSION OF AGENCY Recorded May 2, 2017
From: BANK OF AMERICA, N.A., AS PRIOR AGENT
To: JPMORGAN CHASE BANK, N.A., AS SUCCESSOR AGENT
Reel/Frame 042388/0386 →
CHANGE OF NAME Recorded Sep 13, 2016
From: NOVELL, INC.
To: MICRO FOCUS SOFTWARE INC.
Reel/Frame 040020/0703 →
SECURITY INTEREST Recorded May 13, 2015
From: MICRO FOCUS (US), INC.; BORLAND SOFTWARE CORPORATION; ATTACHMATE CORPORATION; NETIQ CORPORATION; NOVELL, INC.
To: BANK OF AMERICA, N.A.
Reel/Frame 035656/0251 →