IP Library Granted Patent US 10,686,827
Granted Patent B2
US 10,686,827 · App. 15/098,720 · Granted Jun 16, 2020

Intermediate encryption for exposed content

Inventors: Harald Schutz (Linz, AT); Anthony John Merry (Kessel-lo, BE); Kenneth D. Ray (Seattle, WA); Andreas Berger (Linz, AT)
Assignee: Sophos Limited
H04L63/1441G06F21/554G06F21/6218H04L9/006H04L9/14H04L9/30H04L63/06G06F2221/2107
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,686,827
App. No.
15/098,720
Granted
Jun 16, 2020
Kind
B2
Abstract

An endpoint encrypts local files with a key to protect file contents. If the endpoint or processes on the endpoint becomes exposed to potentially harmful locations or resources, the key can be revoked to prevent access to encrypted files on the endpoint. In order to facilitate continued operation of the endpoint, files that are currently open can be encrypted with a second key so that the corresponding data is isolated from the other encrypted files while remaining accessible to current users.

Claims (39)

1. A computer program product comprising computer executable code embodied in a non-transitory computer readable medium that, when executing on an endpoint, performs the steps of:

providing a first key to a process executing on the endpoint, the first key providing access to a plurality of files on the endpoint;

detecting a potential security compromise to the endpoint;

in response to detecting the potential security compromise, providing a second key to the process different than the first key;

encrypting a first one of the plurality of files that is open by the process with the second key;

storing the first one of the plurality of files after encryption with the second key;

revoking the first key from the process to prevent access to other ones of the plurality of files by the process;

initiating a remediation of the potential security compromise; and

if the potential security compromise is resolved, returning the first key to the process and transcribing the first one of the plurality of files for access using the first key.

2. The computer program product of claim 1 wherein revoking the first key includes physically removing the first key from the endpoint.

3. The computer program product of claim 2 wherein returning the first key to the process includes recovering the first key from a remote key management system.

4. The computer program product of claim 1 further comprising code that performs the step of, if the potential security compromise is resolved, deleting the second key and saving the first one of the plurality of files.

5. The computer program product of claim 1 wherein detecting the potential security compromise to the endpoint includes identifying a compromised state on the endpoint.

6. The computer program product of claim 5 wherein identifying the compromised state includes identifying malicious software based on at least one of static analysis and behavioral analysis.

7. The computer program product of claim 5 wherein detecting the potential security compromise includes detecting an exposure of the process to an unknown data source.

8. A method comprising:

providing a first key to a process executing on an endpoint, the first key providing access to a plurality of files on the endpoint;

detecting a potential security compromise to the endpoint;

in response to detecting the potential security compromise, providing a second key to the process different than the first key;

encrypting a first one of the plurality of files that is open by the process with the second key;

revoking the first key from the process to prevent access to other ones of the plurality of files by the process; and

if the potential security compromise is resolved, returning the first key to the process and transcribing the first one of the plurality of files for access using the first key.

9. The method of claim 8 wherein revoking the first key includes physically removing the first key from the endpoint.

10. The method of claim 9 wherein returning the first key to the process includes recovering the first key from a remote key management system.

11. The method of claim 8 further comprising, if the potential security compromise is resolved, deleting the second key and saving the first one of the plurality of files.

12. The method of claim 8 wherein detecting the potential security compromise to the endpoint includes identifying a compromised state on the endpoint.

13. The method of claim 12 wherein identifying the compromised state includes identifying malicious software based on static analysis.

14. The method of claim 12 wherein identifying the compromised state includes identifying malicious software based on behavioral analysis.

15. The method of claim 8 wherein detecting the potential security compromise includes identifying a compromised state of the process.

16. The method of claim 8 wherein detecting the potential security compromise includes detecting an exposure of the process to an unknown data source.

17. The method of claim 8 further comprising initiating a remediation of the potential security compromise.

18. The method of claim 17 further comprising storing the first one of the plurality of files after encryption with the second key and before initiating the remediation.

19. A system comprising:

an endpoint;

a first memory on the endpoint storing a first key;

a second memory on the endpoint storing a plurality of files encrypted by the first key;

a process executing on a processor on the endpoint, the process using the first key to access a first one of the plurality of files; and

a security agent executing on the processor, the security agent configured to detect a potential security compromise to the endpoint, wherein the processor is configured to provide, in response to detecting the potential security compromise, a second key to the process different than the first key, to respond to the potential security compromise by encrypting the first one of the plurality of files with the second key, to provide access by the process to the second key, and to revoke the first key from the process to prevent access by the process to other ones of the plurality of files.

20. The system of claim 19 wherein the processor is further configured to initiate a remediation of the potential security compromise, and to respond to a successful remediation of the potential security compromise by returning the first key to the process for access to the plurality of files.

Assignments (4)
RELEASE OF SECURITY INTEREST IN PATENTS AT R/F 053476/0681 Recorded Mar 9, 2021
From: OWL ROCK CAPITAL CORPORATION, AS COLLATERAL AGENT
To: SOPHOS LIMITED
Reel/Frame 056469/0815 →
PATENT SECURITY AGREEMENT FIRST LIEN Recorded Jul 6, 2020
From: SOPHOS LIMITED
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 053124/0350 →
PATENT SECURITY AGREEMENT SECOND LIEN Recorded Jul 6, 2020
From: SOPHOS LIMITED
To: OWL ROCK CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 053476/0681 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 16, 2016
From: SCHUTZ, HARALD; MERRY, ANTHONY JOHN; RAY, KENNETH D.; BERGER, ANDREAS
To: SOPHOS LIMITED
Reel/Frame 038601/0841 →
Cited By (2)
US 12,231,409 US 12,519,633