IP Library Granted Patent US 9,350,760
Granted Patent B2
US 9,350,760 · App. 14/162,549 · Granted May 24, 2016

Method and system for implementing mandatory file access control in native discretionary access control environments

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,350,760
App. No.
14/162,549
Granted
May 24, 2016
Kind
B2
Abstract

A method is provided for implementing a mandatory access control model in operating systems which natively use a discretionary access control scheme. A method for implementing mandatory access control in a system comprising a plurality of computers, the system comprising a plurality of information assets, stored as files on the plurality of computers, and a network communicatively connecting the plurality of computers, wherein each of the plurality of computers includes an operating system that uses a discretionary access control policy, and wherein each of a subset of the plurality of computers includes a software agent component operable to perform the steps of intercepting a request for a file operation on a file from a user of one of the plurality of computers including the software agent, determining whether the file is protected, if the file is protected, altering ownership of the file from the user to another owner, and providing access to the file based on a mandatory access control policy.

Claims (36)

1. A computer system configured to act as a Domain Controller (DC) for a computer network comprising plurality of client computers, the plurality of client computers running an operating system that uses a discretionary access policy regarding file operations, the computer system comprising:

one or more hardware processors communicatively coupled to a non-transitory computer readable storage medium wherein the non-transitory computer readable storage medium comprises instructions stored thereon that when executed by the one or more processors cause the one or more processors to:

receive a login request associated with a first user on a first client computer of the plurality of client computers; and

receive an indication from a mandatory access control agent executing on the first client computer to modify a login session in response to the login request, the login session configured to exclude the first user from a default user group and to associate the first user with a second user group for a duration of the login session;

wherein protected files accessible on the computer network are associated with an access control list that denies access to the default user group and allows access to the second user group; and

wherein the access control agent and the DC implement a security policy regarding file operations within the computer network that is configured by default with the discretionary access policy regarding file operations.

2. The computer system of claim 1 , wherein the instructions to cause the one or more processors to receive an indication to modify a login session comprise instructions to cause the one or more processors to receive a user identification and determine using the user identification to create the login session.

3. The computer system of claim 1 , wherein the discretionary access policy comprises a discretionary access control policy.

4. The computer system of claim 1 , wherein the security policy regarding file operations comprises a mandatory access control policy.

5. The computer system of claim 1 , wherein the instructions to cause the one or more processors to receive an indication to modify a login session comprise instructions to cause the one or more processors to receive an indication that the first client computer is configured with a mandatory access control agent.

6. The computer system of claim 1 , wherein a second user can authenticate to the DC from a second client computer system without having the login session configured.

7. The computer system of claim 6 , wherein the second client computer system is not configured with the access control agent and the second client computer system conforms to the discretionary access policy regarding file operations.

8. The computer system of claim 1 , wherein the first user can authenticate to the DC from a second client computer system without having the login session configured based, at least in part, on a condition that the second client computer system is not executing the access control agent.

9. The computer system of claim 1 , wherein the DC concurrently provides authentication services for the plurality of client computers and the plurality of client computers comprises at least one client configured with the access control agent and at least one client configured without the access control agent.

10. One or more non-transitory computer readable media comprising instructions stored thereon that when executed by a programmable device configure the programmable device to act as a Domain Controller (DC) for a computer network comprising a plurality of client computers, the plurality of client computers running an operating system that uses a discretionary access policy regarding file operations, the instructions further comprising instructions to configure the programmable device to:

receive a login request associated with a first user on a first client computer selected from the plurality of client computers; and

accept an indication from a mandatory access control agent executing on the first client computer to modify a login session in response to the login request, the login session configured to exclude the first user from a default user group and to associate the first user with a second user group for a duration of the login session;

wherein protected files accessible on the computer network include an access control list that denies access to the default user group and allows access to the second user group; and

wherein the access control agent and the DC implement an security policy regarding file operations within the computer network that is configured by default with the discretionary access policy regarding file operations.

11. The one or more computer readable media of claim 10 , wherein the instructions to cause the programmable device to receive an indication to modify a login session comprise instructions to cause the programmable device to receive a user identification and determine using the user identification to create the login session.

12. The one or more computer readable media of claim 10 , wherein the discretionary access policy comprises a discretionary access control policy.

13. The one or more computer readable media of claim 10 , wherein the security policy regarding file operations comprises a mandatory access control policy.

14. The one or more computer readable media of claim 10 , wherein the instructions to cause the programmable device to receive an indication to modify a login session comprise instructions to cause the programmable device to receive an indication that the first client computer is configured with a mandatory access control agent.

15. The one or more computer readable media of claim 10 , wherein a second user can authenticate to the DC from a second client computer system without having the login session configured.

16. The one or more computer readable media of claim 15 , wherein the second client computer system is not configured with the mandatory access control agent and the second client computer system conforms to the discretionary access policy regarding file operations.

17. The one or more computer readable media of claim 10 , wherein the first user can authenticate to the DC from a second client computer system without having the login session configured based, at least in part, on a condition that the second client computer system is not executing the mandatory access control agent.

18. The one or more computer readable media of claim 10 , wherein the DC concurrently provides authentication services for the plurality of client computers and the plurality of client computers comprises at least one client configured with the mandatory access control agent and at least one client configured without the mandatory access control agent.

19. A method for configuring a programmable device to act as a Domain Controller (DC) for a computer network comprising a plurality of client computers, the plurality of client computers running an operating system that uses a discretionary access policy regarding file operations, the method comprising:

receiving a login request associated with a first user on a first client computer selected from the plurality of client computers; and

accepting an indication from a mandatory access control agent executing on the first client computer to modify a login session in response to the login request, the login session configured to exclude the first user from a default user group and to associate the first user with a second user group for a duration of the login session;

wherein protected files accessible on the computer network include an access control list that denies access to the default user group and allows access to the second user group; and

wherein the access control agent and the DC implement an security policy regarding file operations within the computer network that is configured by default with the discretionary access policy regarding file operations.

20. The method of claim 19 , wherein receiving an indication to modify a login session comprises:

receiving a user identification; and

determining using the user identification to create the login session.

21. The method of claim 19 , wherein receiving an indication to modify a login session comprises receiving an indication that the first client computer is configured with a mandatory access control agent.

Assignments (20)
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 057453, FRAME 0053 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0413 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 056990, FRAME 0960 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0430 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068656/0098 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068656/0920 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068657/0764 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068657/0843 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 1, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 060561/0466 →
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY NUMBERS PREVIOUSLY RECORDED AT REEL: 057315 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Apr 11, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 060878/0126 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 056990/0960 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057453/0053 →
RELEASE OF SECURITY INTEREST Recorded Jul 26, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: MCAFEE, LLC; SKYHIGH NETWORKS, LLC
Reel/Frame 057620/0102 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →