IP Library Granted Patent US 10,705,855
Granted Patent B2
US 10,705,855 · App. 15/826,281 · Granted Jul 7, 2020

Method for securely configuring an information system

Inventors: Mickey J. Malone, II (Rowlett, TX); Jacob Minnis (Plano, TX)
Assignee: FORCEPOINT LLC
G06F9/44505G06F21/51G06F21/575H04L9/3236H04L9/3247
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,705,855
App. No.
15/826,281
Granted
Jul 7, 2020
Kind
B2
Abstract

Systems, method, and non-transitory computer readable storage medium are provided for configuring an information computing machine during execution of a kernel image. The system can create a file system from a base file system image in system memory of the computing system, apply configuration files from a bundle image to the file system in memory, copy files from a persistent file system stored in the storage resource to memory, validate the files from the persistent file system, and apply validated files to the file system in memory. The base file system image and bundle image can be verified by comparing a signed hash of the image with a hash generated by the initial file system and checking the hash signature against a public certificate included in the initial filesystem. The system can further execute /sbin/init and start application services.

Claims (44)

1. A system for configuring an information computing machine during execution of a kernel image and an initial file system, the system comprising:

a storage resource;

a processor communicatively coupled to the storage resource, wherein the processor executes application code instruction that are stored in the storage resource to cause the system to:

create a file system from a base file system image in system memory of the information computing system;

apply binary and configuration files from a bundle image to the file system in memory;

copy files from a persistent file system stored in the storage resource to memory;

validate the files from the persistent file system;

apply validated files to the file system in memory; and

verify the bundle image by comparing a signed hash of the image with a hash generated by the initial file system and checking the hash signature against a public certificate included in the initial filesystem, wherein the initial filesystem includes a memory file system module, a base file system image and the bundle image, wherein the bundle image is further verified by determining if the hash has been signed by an administrator and validated against a white list.

2. The system of claim 1 further comprising application code instruction to cause the system to:

verify the base file system image by comparing a signed hash of the image that includes a plurality of digital signatures with a hash generated by the initial file system and checking the plurality of digital signatures against public certificates included in the initial filesystem.

3. The system of claim 1 wherein the base file system image can be retrieved from a local storage resource or from a remote storage resource.

4. The system of claim 1 wherein the bundle image can be retrieved from a local storage resource or from a remote storage resource.

5. The system of claim 1 further comprising application code instruction to cause the system to:

execute /sbin/init; and

start services.

6. A computer aided method of a system for configuring an information computing system during execution of a kernel image and an initial file system, the method comprising:

creating a file system from a base file system image in system memory of the information computing system;

applying configuration files from a bundle image to the file system in memory;

copying files from a persistent file system stored in the storage resource to memory;

validating the files from the persistent file system;

applying validated files to the file system in memory; and

verifying the bundle image by comparing a signed hash of the image with a hash generated by the initial file system and checking the hash signature against a public certificate included in the initial filesystem, wherein the initial filesystem includes a memory file system module, a base file system image and the bundle image, wherein the bundle image is further verified by determining if the hash has been signed by an administrator and validated against a white list.

7. The method of claim 6 further comprising:

verifying the base file system image by comparing a signed hash of the image with a hash generated by the initial file system and checking the hash signature against a public certificate included in the initial filesystem.

8. The method of claim 6 further comprising retrieving the base file system image from a local storage resource or from a remote storage resource.

9. The method of claim 6 further comprising retrieving the bundle image from a local storage resource or from a remote storage resource.

10. The method of claim 6 further comprising:

executing /sbin/init; and

starting services.

11. A non-transitory computer readable medium containing computer readable instructions for configuring an information computing machine, the computer-readable instructions comprising instructions for causing the computing machine to:

create a file system from a base file system image in system memory of the information computing system;

apply configuration files from a bundle image to the file system in memory;

copy files from a persistent file system stored in the storage resource to memory;

validate the files from the persistent file system;

apply validated files to the file system in memory; and

verify the bundle image by comparing a signed hash of the image with a hash generated by the initial file system and checking the hash signature against a public certificate included in the initial filesystem, wherein the initial filesystem includes a memory file system module, a base file system image and the bundle image, wherein the bundle image is further verified by determining if the hash has been signed by an administrator and validating the bundle image against a white list.

12. The non-transitory computer readable medium of claim 11 further includes computer readable instruction to cause the computing machine to:

verify the base file system image by comparing a signed hash of the image with a hash generated by the initial file system and checking the hash signature against a public certificate included in the initial filesystem.

13. The non-transitory computer readable medium of claim 11 wherein the base file system image can be retrieved from a local storage resource or from a remote storage resource.

14. The non-transitory computer readable medium of claim 11 wherein the bundle image can be retrieved from a local storage resource or from a remote storage resource.

15. The non-transitory computer readable medium of claim 11 further includes computer readable instruction to cause the computing machine to:

execute /sbin/init; and

start services.

Assignments (11)
RELEASE OF SECURITY INTEREST Recorded Apr 2, 2025
From: UBS AG, STAMFORD BRANCH
To: FORCEPOINT, LLC; BITGLASS, LLC
Reel/Frame 070706/0263 →
CHANGE OF NAME Recorded Feb 13, 2024
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: EVERFOX HOLDINGS LLC
Reel/Frame 066582/0531 →
PARTIAL PATENT RELEASE AND REASSIGNMENT AT REEL/FRAME 055052/0302 Recorded Oct 3, 2023
From: CREDIT SUISSE, AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: FORCEPOINT FEDERAL HOLDINGS LLC (F/K/A FORCEPOINT LLC)
Reel/Frame 065103/0147 →
SECURITY INTEREST Recorded Sep 29, 2023
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: APOLLO ADMINISTRATIVE AGENCY LLC, AS COLLATERAL AGENT
Reel/Frame 065086/0822 →
CHANGE OF NAME Recorded May 12, 2021
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 056216/0309 →
PATENT SECURITY AGREEMENT Recorded Jan 20, 2021
From: REDOWL ANALYTICS, INC.; FORCEPOINT LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 055052/0302 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: FORCEPOINT LLC
Reel/Frame 055492/0266 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: FORCEPOINT LLC
Reel/Frame 055479/0676 →
PATENT SECURITY AGREEMENT SUPPLEMENT Recorded Mar 15, 2019
From: FORCEPOINT LLC
To: RAYTHEON COMPANY
Reel/Frame 048613/0636 →
PATENT SECURITY AGREEMENT SUPPLEMENT Recorded Jul 6, 2018
From: FORCEPOINT LLC
To: RAYTHEON COMPANY
Reel/Frame 046495/0561 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 29, 2017
From: MALONE, MICKEY J., II; MINNIS, JACOB
To: FORCEPOINT LLC
Reel/Frame 044253/0409 →