IP Library Granted Patent US 10,162,767
Granted Patent B2
US 10,162,767 · App. 14/752,914 · Granted Dec 25, 2018

Virtualized trusted storage

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,162,767
App. No.
14/752,914
Granted
Dec 25, 2018
Kind
B2
Abstract

Particular embodiments described herein provide for an electronic device that can be configured to receive a request from a process to access data is a system, determine if the data is in a virtualized protected area of memory in the system, and allow access to the data if the data is in the virtualized protected area of memory and the process is a trusted process. The electronic device can also be configured to determine if new data should be protected, store the new data in the virtualized protected area of memory in the system if the new data should be protected, and store the new data in an unprotected area of memory in the system if the new data should not be protected.

Claims (55)

1. At least one non-transitory machine readable medium comprising one or more instructions that when executed by at least one processor, cause the at least one processor to:

receive a request from a process to access data in a system;

determine whether the data is in a virtualized protected area of memory in the system, wherein the virtualized protected area of memory is a secure storage area and wherein the data is stored unencrypted; and

responsive to determining that the data is not in a virtualized protected area of memory, allow access to the data; or

responsive to determining that the data is in a virtualized protected area of memory, determine whether the process is a trusted process; and

allow access to the data based on a determination that the data is in the virtualized protected area of memory and the process is a trusted process.

2. The at least one non-transitory machine readable medium of claim 1 , further comprising one or more instructions that when executed by at least one processor, cause the at least one processor to:

determine whether new data should be protected;

store the new data unencrypted in the virtualized protected area of memory in the system based on a determination that the new data should be protected; and

store the new data in an unprotected area of memory in the system based on a determination that the new data should not be protected.

3. The at least one non-transitory machine readable medium of claim 1 , wherein the virtualized protected area of memory is a secured vault.

4. The at least one machine non-transitory readable medium of claim 1 , wherein the virtualized protected area of memory is a cloud vault.

5. The at least one non-transitory machine readable medium of claim 1 , wherein a filter driver controls input and output access to the virtualized protected area of memory.

6. An apparatus comprising:

a hardware processor configured to:

receive a request from a process to access data in a system;

determine whether the data is in a virtualized protected area of memory in the system, wherein the virtualized protected area of memory is a secure storage area and wherein the data is stored unencrypted; and

responsive to determining that the data is not in a virtualized protected area of memory, allow access to the data; or

responsive to determining that the data is in a virtualized protected area of memory, determine whether the process is a trusted process; and

allow access to the data based on a determination that the data is in the virtualized protected area of memory and the process is a trusted process.

7. The apparatus of claim 6 , wherein the hardware processor is further configured to:

determine whether new data should be protected;

store the new data unencrypted in the virtualized protected area of memory in the system based on a determination that the new data should be protected; and

store the new data in an unprotected area of memory in the system based on a determination that the new data should not be protected.

8. The apparatus of claim 6 , wherein the virtualized protected area of memory is a secured vault.

9. The apparatus of claim 6 , wherein the virtualized protected area of memory is a cloud vault.

10. The apparatus of claim 6 , wherein a filter driver controls input and output access to the virtualized protected area of memory.

11. A method comprising:

receiving a request from a process to access data in a system;

determining whether the data is in a virtualized protected area of memory in the system, wherein the virtualized protected area of memory is a secure storage area and wherein the data is stored unencrypted; and

responsive to determining that the data is not in a virtualized protected area of memory, allowing access to the data; or

responsive to determining that the data is in a virtualized protected area of memory, determining whether the process is a trusted process; and

allowing access to the data based on a determination that the data is in the virtualized protected area of memory and the process is a trusted process.

12. The method of claim 11 , further comprising:

determining whether new data should be protected;

storing the new data unencrypted in the virtualized protected area of memory in the system based on a determination that the new data should be protected; and

storing the new data in an unprotected area of memory in the system based on a determination that the new data should not be protected.

13. The method of claim 11 , wherein the virtualized protected area of memory is a secured vault.

14. The method of claim 11 , wherein the virtualized protected area of memory is a cloud vault.

15. The method of claim 11 , further comprising:

denying access to the data based on a determination that the data is in the virtualized protected area of memory and the process is an untrusted process.

16. A system for virtualized trusted secure storage, the system comprising:

a hardware processor configured to:

receive a request from a process to access data in a system;

determine whether the data is in a virtualized protected area of memory in the system, wherein the virtualized protected area of memory is a secure storage area and wherein the data is stored unencrypted; and

responsive to determining that the data is not in a virtualized protected area of memory, allow access to the data; or

responsive to determining that the data is in a virtualized protected area of memory, determine whether the process is a trusted process; and

allow access to the data based on a determination that the data is in the virtualized protected area of memory and the process is a trusted process.

17. The system of claim 16 , wherein the system is further configured to:

determine whether new data should be protected;

store the new data unencrypted in the virtualized protected area of memory in the system based on a determination that the new data should be protected; and

store the new data in an unprotected area of memory in the system based on a determination that the new data should not be protected.

18. The system of claim 16 , wherein the virtualized protected area of memory is a secured vault.

19. The system of claim 16 , wherein the virtualized protected area of memory is a cloud vault.

20. The system of claim 16 , wherein a filter driver controls input and output access to the virtualized protected area of memory.

Assignments (10)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 8, 2015
From: EDWARDS, JONATHAN L.; PHAM, KHAI N.; KAPOOR, ADITYA; SPURLOCK, JOEL R.; ZHANG, ZHENG
To: MCAFEE, INC.
Reel/Frame 036030/0378 →
Cited By (9)
US 12,231,464 US 12,267,304 US 12,267,355 US 12,284,206 US 12,299,117 US 12,348,494 US 12,381,890 US 12,519,754 US 12,647,362