IP Library Granted Patent US 10,417,417
Granted Patent B2
US 10,417,417 · App. 14/911,140 · Granted Sep 17, 2019

Digital protection that travels with data

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,417,417
App. No.
14/911,140
Granted
Sep 17, 2019
Kind
B2
Abstract

The present disclosure relates to a system and method for performing antimalware scanning of data files that is data-centric rather than device-centric, In the example, a plurality of computing devices are connected via a network. An originating device creates or first receives data, and scans the data for malware, After scanning the data, the originating device creates and attaches to the data a metadata record including the results of the malware scan, The originating device may also scan the data for malware contextually-relevant to a second device.

Claims (27)

1. At least one machine readable, non-transitory storage medium having instructions stored thereon for providing data-centric computer security between a first device and a second device remote from the first device, wherein the instructions, when executed by at least one processor, cause the at least one processor to perform operations comprising:

scanning a data file using a security scanner at the first device to produce results;

receiving, from the second device, an indication of an operating system platform version at the second device, a version of software at the second device for accessing the data file, or a date for accessing the data file at the second device;

scanning the data file for malware contextually relevant to the second device based on the operating system platform version, the version of the software, or the date;

creating a record based in part on the results from the security scanner, the record comprising a cryptographic hash of the data file, the record further comprising device information associated with the first device, scan information associated with the security scanner, or user information associated with a user of the first device, wherein the device information comprises at least one of a reputation of the first device, a version of the security scanner, and the operating system platform version, the user information comprises at least one of a reputation of the user of the first device and a manner in which the user of the first device is linked to a user of the second device, and the record is generated or augmented according to the indication; and

transmitting the record along with the data file from the first device to the second device.

2. The at least one machine readable, non-transitory storage medium according to claim 1 , wherein the scan information comprises at least one of scan status or results, scan parameters, and a target platform for which the security scanner scanned.

3. The at least one machine readable, non-transitory storage medium according to claim 1 , wherein the record further comprises privacy information comprising at least one of a privacy reputation of the user of the first device, and the manner in which the user of the first device is linked to the user of the second device.

4. A first device for providing data-centric computer security between the first device and a second device remote from the first device, the first device comprising:

at least one memory element;

at least one processor coupled to the at least one memory element; and

a file sharing client that, when executed by the at least one processor, is configured to

receive, from the second device, an indication of an operating system platform version at the second device, a version of software at the second device for accessing the data file, or a date for accessing the data file at the second device,

create a record associated with a data file based in part on scan results from a security scanner of the first device, the record comprising a cryptographic hash of the data file, the record further comprising device information associated with the first device, scan information associated with the security scanner, or user information associated with a user of the first device, wherein the security scanner of the first device is configured to scan the data file for malware contextually relevant to the second device based on the operating system platform version, the version of the software, or the date, the record is generated or augmented according to the indication, the device information comprises at least one of a reputation of the first device, a version of the security scanner, and the operating system platform version, and the user information comprises at least one of a reputation of the user of the first device and a manner in which the user of the first device is linked to a user of the second device, and

transmit the record along with the data file from the first device to the second device.

5. The first device according to claim 4 , wherein the scan information comprises at least one of scan status or results, scan parameters, and a target platform for which the security scanner scanned.

6. The first device according to claim 4 , wherein the record further comprises privacy information comprising at least one of a privacy reputation of the user of the first device, and the manner in which the user of the first device is linked to the user of the second device.

7. A method for providing data-centric computer security between a first device and a second device remote from the first device, comprising:

receiving, at a file sharing client of the first device, from the second device, an indication of an operating system platform version at the second device, a version of software at the second device for accessing a data file, or a date for accessing the data file at the second device;

scanning, using a security scanner of the first device, the data file for malware contextually relevant to the second device based on the operating system platform version, the version of the software, or the date;

retrieving scan results associated with the data file from the security scanner of the first device;

creating, using the file sharing client, a record based in part on the scan results, the record comprising a cryptographic hash of the data file, the record further comprising device information associated with the first device, scan information associated with the security scanner, or user information associated with a user of the first device, wherein the record is generated or augmented according to the indication, the device information comprises at least one of a reputation of the first device, a version of the security scanner, and the operating system platform version, and the user information comprises at least one of a reputation of the user of the first device and a manner in which the user of the first device is linked to a user of the second device; and

transmitting the record along with the data file from the first device to the second device.

8. The method according to 7 , wherein the scan information comprises at least one of scan status or results, scan parameters, and a target platform for which the security scanner scanned.

9. The method according to claim 7 , wherein the record further comprises privacy information comprising at least one of a privacy reputation of the user of the first device, and the manner in which the user of the first device is linked to the user of the second device.

10. The at least one machine readable, non-transitory storage medium according to claim 1 , wherein the record comprises a name of the data file.

11. The at least one machine readable, non-transitory storage medium according to claim 1 , wherein the record comprises a time stamp of the record.

Assignments (9)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →