IP Library Granted Patent US 11,200,066
Granted Patent B2
US 11,200,066 · App. 15/993,451 · Granted Dec 14, 2021

Secure device for bypassing operating system (OS) security

Inventors: Sergio Silva (Atlanta, GA); Mustafa Abdulelah (Atlanta, GA); Nicholas Caine (Cumming, GA); John Tatum Dyal (Acworth, GA); Andrew Klenzak (Atlanta, GA); Brian Patrick Rogers (Roswell, GA); Jeremy Cyle Taylor (Cumming, GA); Andrew John Wurfel (Smyrna, GA)
Assignee: NCR Corporation
G06F9/441G06F21/31
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,200,066
App. No.
15/993,451
Granted
Dec 14, 2021
Kind
B2
Abstract

A portable device having a key is interfaced to a host computing device. The host computing device detects the key on the portable device and authenticates a user for using the key. A boot is forced of the host computing device and during the boot a customized image of an Operating System (OS) for the host computing device is loaded into volatile memory of the host computing device and customized security settings are applied to the OS based on a value of the key.

Claims (21)

1. A method, comprising:

detecting, on a device, a key located on an interfaced device, wherein detecting further includes detecting the key when the device is in a normal operational state and not associated with any boot process while the device is fully accessible to a user;

forcing a boot of the device based on a presence of the key;

loading, by an Operating System (OS) loader of the device, a customized image of an OS with custom security settings to complete the boot based on the key; and

processing, on the device, the detecting, the forcing, and the loading while the device lacks network connectivity.

2. The method of claim 1 , wherein detecting further includes authenticating the user for performing the boot and using the key on the device.

3. The method of claim 2 , wherein authenticating further includes writing the key to one of:

a non-volatile secure memory location on the device and a secure hard drive storage location on the device.

4. The method of claim 3 , wherein forcing further includes checking for the key in the non-volatile secure memory location or the secure hard drive storage location during the boot and before loading of the OS on the device.

5. The method of claim 4 , wherein loading further includes selecting the customized image of the OS from a plurality of images for the OS based on the key.

6. The method of claim 1 , wherein loading further includes selecting the customized image of the OS as a base image for the OS.

7. The method of claim 6 , wherein loading further includes starting native services within the OS for availability within the OS post boot.

8. The method of claim 1 , wherein loading further includes selecting the customized security settings based on the key.

9. The method of claim 8 , wherein selecting further includes providing the customized security settings as increased access from what is available during a safe boot of the OS.

10. The method of claim 1 further comprising, providing access to an executing instance of the OS on the device post boot with the customized security settings being enforced by the OS.

11. A system, comprising:

a device; and

a portable device;

wherein the device is configured to: (i) detect a key present on the portable device when the portable device is interfaced to the device when the device is in a normal operational state and not associated with any boot process while the device is fully accessible to a user, (ii) authenticat the user for using the key, (iii) force a boot of the device, and (iv) load, by an Operating System (OS) loader of the device, a customized OS with customized security settings into volatile memory of the OS for execution on the device based on a value for the key to complete the boot, wherein (i), (ii), (iii), and (iv) are processed by the device while the device lacks network connectivity.

12. The system of claim 11 , wherein the portable device is a Universal Serial Bus (USB) device, and wherein the device is one of: a Self-Service Terminal (SST), an Automated Teller Machine (ATM), a kiosk, and a Point-of-Sale (POS) terminal.

13. The system of claim 11 , wherein the device is further configured, in (ii), to: write the key to one of: a secure memory location and a secure hard drive storage location for detection during the boot of the device.

Assignments (7)
CHANGE OF NAME Recorded Dec 7, 2023
From: NCR CORPORATION
To: NCR VOYIX CORPORATION
Reel/Frame 065820/0704 →
RELEASE OF PATENT SECURITY INTEREST Recorded Oct 25, 2023
From: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
To: NCR VOYIX CORPORATION
Reel/Frame 065346/0531 →
SECURITY INTEREST Recorded Oct 25, 2023
From: NCR VOYIX CORPORATION
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 065346/0168 →
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY NUMBERS SECTION TO REMOVE PATENT APPLICATION: 15000000 PREVIOUSLY RECORDED AT REEL: 050874 FRAME: 0063. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Apr 12, 2021
From: NCR CORPORATION
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 057047/0161 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 8, 2020
From: SILVA, SERGIO; ABDULELAH, MUSTAFA; DYAL, JOHN TATUM; KLENZAK, ANDREW; ROGERS, BRIAN PATRICK; TAYLOR, JEREMY CYLE; WURFEL, ANDREW JOHN
To: NCR CORPORATION
Reel/Frame 054573/0942 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 8, 2020
From: CAINE, NICHOLAS
To: NCR CORPORATION
Reel/Frame 054577/0702 →
SECURITY INTEREST Recorded Oct 29, 2019
From: NCR CORPORATION
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 050874/0063 →