IP Library Granted Patent US 8,875,281
Granted Patent B2
US 8,875,281 · App. 14/171,512 · Granted Oct 28, 2014

Methods and systems for using derived user accounts

Inventor: Ulfar Erlingsson (San Francisco, CA)
Assignee: Google Inc
G06F21/6281G06F21/6218
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,875,281
App. No.
14/171,512
Filed
Feb 3, 2014
Granted
Oct 28, 2014
Kind
B2
Art Unit
2434
USPC
726/30
Abstract

Methods, systems and articles of manufacture consistent with features of the present invention allow the generation and use of derived user accounts, or DUA, in a computer system comprising user accounts. In particular, derivation rules define how a DUA is linked to or created based on an existing original user account, or OUA. Derivation transformations may also update the state of a DUA based on its corresponding OUA or give feedback from the state of a DUA to the state of its corresponding OUA.

Claims (34)

1. A computer-implemented method for accessing a resource in a computer system comprising an operating system, comprising:

receiving a request to access a file system or a registry value from an application;

determining if the application is running in a derived user account (DUA) context, wherein the DUA context represents a security context of a DUA that is derived from an original user account (OUA) associated with a user, and wherein the determining comprises examining an access token associated with the request to determine if the request is associated with the DUA;

if the application is not running in the DUA context, creating the DUA and directing the application to run in the DUA context; and

granting the application access to the file system or the registry value.

2. The computer-implemented method of claim 1 , wherein creating the DUA comprises applying a derivation transformation to an OUA state of the OUA to generate a corresponding DUA state of the DUA.

3. The computer-implemented method of claim 1 , wherein directing the application to run in the DUA context comprises modifying the access token to generate a modified access token and associating the application with the modified access token.

4. The computer-implemented method of claim 1 , wherein creating the DUA comprises generating the DUA using a user account creation mechanism of the operating system.

5. The computer-implemented method of claim 1 , wherein the DUA comprises different access rights than the OUA.

6. The computer-implemented method of claim 1 , wherein creating the DUA comprises creating a copy of the file system or the registry value.

7. The computer-implemented method of claim 6 , wherein the granting comprises granting the application access to the copy of the file system or the registry value.

8. The computer-implemented method of claim 1 , wherein directing the application to run in the DUA context comprises annotating activity associated with the application as belonging to the DUA.

9. The computer-implemented method of claim 8 , wherein annotating the activity associated with the application comprises annotating the activity associated with the application in a kernel thread control block or a kernel process control block.

10. An apparatus, comprising:

at least one memory having program instructions to execute an operating system; and

at least one processor configured to execute the program instructions to perform the operations of:

receiving a request to access a file system or a registry value from an application;

determining if the application is running in a derived user account (DUA) context, wherein the DUA context represents a security context of a DUA that is derived from an original user account (OUA) associated with a user, and wherein the determining comprises examining an access token associated with the request to determine if the request is associated with the DUA;

if the application is not miming in the DUA context, creating a DUA and directing the application to run in the DUA context; and

granting the application access to the file system or the registry value.

11. The apparatus of claim 10 , wherein creating the DUA comprises applying a derivation transformation to an OUA state of the OUA to generate a corresponding DUA state of the DUA.

12. The apparatus of claim 10 , wherein directing the application to run in the DUA context comprises modifying the access token to generate a modified access token and associating the modified access token with the application.

13. The apparatus of claim 10 , wherein directing the application to run in the DUA context comprises annotating activity associated with the application as belonging to the DUA.

14. The apparatus of claim 13 , wherein annotating the activity associated with the application comprises annotating the activity associated with the application in a kernel thread control block or a kernel process control block.

15. A non-transitory computer-readable medium containing computer-readable instructions enabling a computer to perform a method, the method comprising:

receiving a request to access a file system or a registry value from an application;

determining if the application is running in a derived user account (DUA) context, wherein the DUA context represents a security context of a DUA that is derived from an original user account (OUA) associated with a user, and wherein the determining comprises examining an access token associated with the request to determine if the request is associated with the DUA;

if the application is not running in the DUA context, creating the DUA and directing the application to run in the DUA context; and

granting the application access to the file system or the registry value.

16. The non-transitory computer-readable medium of claim 15 , wherein creating the DUA comprises creating a copy of the file system or the registry value, and wherein the granting comprises granting the application access to the copy of the file system or the registry value.

17. The non-transitory computer-readable medium of claim 15 , wherein creating the DUA comprises applying a derivation transformation to an OUA state of the OUA to generate a corresponding DUA state of the DUA.

18. The non-transitory computer-readable medium of claim 15 , wherein directing the application to run in the DUA context comprises modifying the access token to generate a modified access token and associating the modified access token with the application.

19. The non-transitory computer-readable medium of claim 15 , wherein directing the application to run in the DUA context comprises annotating activity associated with the application as belonging to the DUA.

20. The non-transitory computer-readable medium of claim 19 , wherein annotating the activity associated with the application comprises annotating the activity associated with the application in a kernel thread control block or a kernel process control block.

Assignments (3)
CHANGE OF NAME Recorded Oct 5, 2017
From: GOOGLE INC.
To: GOOGLE LLC
Reel/Frame 044129/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 3, 2014
From: ERLINGSSON, ULFAR
To: GREEN BORDER TECHNOLOGIES
Reel/Frame 032123/0500 →
MERGER Recorded Feb 3, 2014
From: GREEN BORDER TECHNOLOGIES
To: GOOGLE INC.
Reel/Frame 032123/0502 →
Continuity (4)
Continuation 13565483 · Aug 2, 2012
Continuation 10144048 · May 10, 2002
Provisional Application 60335894 · Nov 1, 2001
Related Publication 20140150122A1 · May 29, 2014