IP Library Granted Patent US 10,929,540
Granted Patent B2
US 10,929,540 · App. 16/565,643 · Granted Feb 23, 2021

Trusted updates

Inventors: Preet Mohinder (New Delhi, IN); Ratnesh Pandey (Uttar Pradesh, IN); Jaskaran Singh Khurana (New Delhi, IN); Amritanshu Johri (Haryana, IN)
Assignee: McAfee, LLC
G06F21/57G06F8/65G06F2221/2141
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,929,540
App. No.
16/565,643
Granted
Feb 23, 2021
Kind
B2
Abstract

There is disclosed in one example a computing apparatus, including: a hardware platform including a processor and a memory; a whitelist; an updater, the updater being an executable object authorized to modify files within the whitelist and to launch one or more child processes; and instructions encoded within the memory to provide a system management agent to: maintain a chain of trust between the one or more child processes and the updater, wherein the one or more child processes inherit whitelist permissions associated with the updater; and track the chain of trust across a system reboot, including granting a child process the chain of trust after a reboot only if the child process has associated with it a valid certificate.

Claims (34)

1. A computing apparatus, comprising:

a hardware platform comprising a processor and a memory;

a whitelist;

an updater, the updater being an executable object authorized to modify files within the whitelist and to launch one or more child processes; and

instructions encoded within the memory to provide a system management agent to:

maintain a chain of trust between the one or more child processes and the updater, wherein the one or more child processes inherit whitelist permissions associated with the updater; and

track the chain of trust across a system reboot, comprising granting a child process the chain of trust after a reboot only if the child process has associated with it a valid certificate.

2. The computing apparatus of claim 1 , wherein the certificate is valid only if it is signed by a trusted certificate authority.

3. The computing apparatus of claim 1 , wherein maintaining the chain of trust comprises tracking files created or imported by a trusted executable and sharing a common certificate.

4. The computing apparatus of claim 1 , wherein the system management agent is further to permit files within a common chain of trust to modify one another.

5. The computing apparatus of claim 1 , wherein the whitelist is specific to the updater.

6. The computing apparatus of claim 1 , wherein the instructions are further to allocate a trusted file set, the trusted file set being a subset of the whitelist belonging to a common workflow with the updater.

7. The computing apparatus of claim 1 , wherein the updater is a system management agent.

8. The computing apparatus of claim 1 , wherein the updater is to run with elevated privileges.

9. The computing apparatus of claim 1 , wherein the updater is a kernel module.

10. The computing apparatus of claim 1 , wherein the whitelist is a system-wide whitelist.

11. The computing apparatus of claim 1 , wherein the updater is further authorized to execute any binary executable object on the computing apparatus, including binary executable objects not on the whitelist.

12. One or more tangible, non-transitory computer-readable media having stored thereon executable instructions to:

associate a whitelist with an authorized updater process, the whitelist including a list of files that the authorized updater process and its descendant processes are authorized to modify;

assign the updater process inheritable authority to launch child processes in a chain of trust;

maintain the chain of trust when the authorized updater or a descendant of the authorized updater launches a process; and

upon an invalidating event that invalidates the chain of trust, re-establish the chain of trust after establishing that a process in the chain of trust attempting to re-establish activity has a valid certificate for the chain of trust.

13. The one or more tangible, non-transitory computer-readable media of claim 12 , wherein the invalidating event is a reboot.

14. The one or more tangible, non-transitory computer-readable media of claim 12 , wherein the certificate is valid only if it is signed by a trusted certificate authority.

15. The one or more tangible, non-transitory computer-readable media of claim 12 , wherein maintaining the chain of trust comprises tracking files created or imported by a trusted executable and sharing a common certificate.

16. The one or more tangible, non-transitory computer-readable media of claim 12 , wherein the instructions are further to permit files within a common chain of trust to modify one another.

17. The one or more tangible, non-transitory computer-readable media of claim 12 , wherein the whitelist is specific to the authorized updater.

18. The one or more tangible, non-transitory computer-readable media of claim 12 , wherein the instructions are further to allocate a trusted file set, the trusted file set being a subset of the whitelist belonging to a common workflow with the updater.

19. A computer-implemented method, comprising:

associating a whitelist with an updater process, wherein the updater process has inheritable permissions, including permission to modify files in the whitelist;

maintaining a chain of trust for the updater process, wherein direct or indirect child processes of the updater process inherit the permissions of the updater process;

detecting a reboot event that breaks the chain of trust; and

re-establishing the chain of trust after determining that a process attempting to resume execution is a direct or indirect child of the updater process, and has a valid certificate.

20. The method of claim 19 , wherein the certificate is valid only if it is signed by a trusted certificate authority.

Assignments (2)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
Priority Claims (1)
IN 6600/CHE/2014 · Dec 26, 2014 · national
Continuity (2)
Continuation 15535552
Related Publication 20200004966A1 · Jan 2, 2020