IP Library Granted Patent US 11,397,822
Granted Patent B2
US 11,397,822 · App. 16/936,652 · Granted Jul 26, 2022

System and method of utilizing document security

Inventors: Yevgeni Gehtman (Modi'in, IL); Tomer Shachar (Omer, IL); Maxim Balin (Gan Yavne, IL)
Assignee: Dell Products L.P.
G06F21/6209G06F21/57G06F21/602G06F21/64
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,397,822
App. No.
16/936,652
Granted
Jul 26, 2022
Kind
B2
Abstract

In one or more embodiments, one or more systems, one or more methods, and/or one or more processes may: read a document; determine that the document includes executable instructions; execute the executable instructions of the document; determine if a security agent exists on an information handling system (IHS); if the security agent does not exist on the IHS, corrupt data of the document; if the security agent does exist on the information handling system: generate an array of bytes associated with multiple identifiers of multiple of components of the IHS; determine a first hash value of the array of bytes and the document; retrieve a second hash value from the document; determine if the first hash value matches the second hash value; if the first hash value matches the second hash value, provide the data of the document to an application; and if not, corrupt the data of the document.

Claims (58)

1. An information handling system, comprising:

a processor; and

a memory medium, coupled to the processor, that stores instructions executable by the processor, which when executed by the processor, cause the information handling system to:

read a document;

determine that the document includes document security executable instructions;

execute the document security executable instructions of the document;

determine if a security agent exists on the information handling system;

if the security agent does not exist on the information handling system, corrupt data of the document; and

if the security agent does exist on the information handling system:

load a kernel loadable module, which includes the security agent, into an operating system executing on the information handling system;

generate an array of bytes associated with a plurality of identifiers of a plurality of components of the information handling system;

determine a first hash value of the array of bytes and the document;

retrieve a second hash value from the document;

determine if the first hash value matches the second hash value;

if the first hash value does not match the second hash value, corrupt the data of the document; and

if the first hash value does match the second hash value, provide the data of the document to an application.

2. The information handling system of claim 1 , wherein, to execute the document security executable instructions of the document, the application causes the processor to execute the document security executable instructions of the document.

3. The information handling system of claim 1 , wherein, to execute the document security executable instructions of the document, the application executes the document security executable instructions of the document.

4. The information handling system of claim 1 , wherein the plurality of identifiers of the plurality of components of the information handling system include two of more of a processor identifier of the processor, a graphics processing unit (GPU) identifier of a GPU, a display identifier of a display, a volatile memory medium identifier of a volatile memory medium, a first non-volatile memory medium identifier of a first non-volatile memory medium, a second non-volatile memory medium identifier of a second non-volatile memory medium, a network interface identifier of a network interface, an information handling system firmware (IHSFW) identifier of IHSFW, a virtual private network (VPN) identifier of a VPN connection, a keyboard identifier of a keyboard, and a pointing device identifier of a pointing device.

5. The information handling system of claim 1 , wherein, to generate the array of bytes, the instructions further cause the information handling system to combine the plurality of identifiers of the plurality of components of the information handling system.

6. The information handling system of claim 1 , wherein at least one of the plurality of identifiers includes a network address.

7. A method, comprising:

reading, by an application executing on an information handling system, a document;

determining, by the application, that the document includes document security executable instructions;

executing the document security executable instructions of the document;

determining if a security agent exists on the information handling system;

if the security agent does not exist on the information handling system, corrupting data of the document; and

if the security agent does exist on the information handling system:

loading a kernel loadable module, which includes the security agent, into an operating system executing on the information handling system;

generating an array of bytes associated with a plurality of identifiers of a plurality of components of the information handling system;

determining a first hash value of the array of bytes and the document;

retrieving a second hash value from the document;

determining if the first hash value matches the second hash value;

if the first hash value does not match the second hash value, performing the corrupting the data of the document; and

if the first hash value does match the second hash value, providing the data of the document to the application.

8. The method of claim 7 , wherein the executing the document security executable instructions of the document includes the application executing the document security executable instructions of the document.

9. The method of claim 7 , wherein the executing the executable instructions of the document includes the application instructing a processor of the information handling system to execute the executable instructions of the document.

10. The method of claim 7 , wherein the plurality of identifiers of the plurality of components of the information handling system include two of more of a processor identifier of the processor, a graphics processing unit (GPU) identifier of a GPU, a display identifier of a display, a volatile memory medium identifier of a volatile memory medium, a first non-volatile memory medium identifier of a first non-volatile memory medium, a second non-volatile memory medium identifier of a second non-volatile memory medium, a network interface identifier of a network interface, an information handling system firmware (IHSFW) identifier of IHSFW, a virtual private network (VPN) identifier of a VPN connection, a keyboard identifier of a keyboard, and a pointing device identifier of a pointing device.

11. The method of claim 7 , wherein the generating the array of bytes includes combining the plurality of identifiers of the plurality of components of the information handling system.

12. The method of claim 7 , wherein at least one of the plurality of identifiers includes a network address.

13. A computer-readable non-transitory memory medium that includes instructions that, when executed by a processor of an information handling system, cause the information handling system to:

read a document;

determine that the document includes document security executable instructions;

execute the document security executable instructions of the document;

determine if a security agent exists on the information handling system;

if the security agent does not exist on the information handling system, corrupt data of the document; and

if the security agent does exist on the information handling system:

load a kernel loadable module, which includes the security agent, into an operating system executing on the information handling system;

generate an array of bytes associated with a plurality of identifiers of a plurality of components of the information handling system;

determine a first hash value of the array of bytes and the document;

retrieve a second hash value from the document;

determine if the first hash value matches the second hash value;

if the first hash value does not match the second hash value, corrupt the data of the document; and

if the first hash value does match the second hash value, provide the data of the document to the application.

14. The computer-readable non-transitory memory medium of claim 13 , wherein, to execute the document security executable instructions of the document, the application causes the processor to execute the document security executable instructions of the document.

15. The computer-readable non-transitory memory medium of claim 13 , wherein the plurality of identifiers of the plurality of components of the information handling system include two of more of a processor identifier of the processor, a graphics processing unit (GPU) identifier of a GPU, a display identifier of a display, a volatile memory medium identifier of a volatile memory medium, a first non-volatile memory medium identifier of a first non-volatile memory medium, a second non-volatile memory medium identifier of a second non-volatile memory medium, a network interface identifier of a network interface, an information handling system firmware (IHSFW) identifier of IHSFW, a virtual private network (VPN) identifier of a VPN connection, a keyboard identifier of a keyboard, and a pointing device identifier of a pointing device.

16. The computer-readable non-transitory memory medium of claim 13 , wherein, to generate the array of bytes, the instructions further cause the information handling system to combine the plurality of identifiers of the plurality of components of the information handling system.

17. The computer-readable non-transitory memory medium of claim 13 , wherein at least one of the plurality of identifiers includes a network address.

Assignments (9)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053578/0183) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 060332/0864 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053574/0221) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 060333/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053573/0535) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 060333/0106 →
RELEASE OF SECURITY INTEREST AT REEL 053531 FRAME 0108 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 058001/0371 →
SECURITY INTEREST Recorded Aug 21, 2020
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 053578/0183 →
SECURITY INTEREST Recorded Aug 21, 2020
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 053573/0535 →
SECURITY INTEREST Recorded Aug 21, 2020
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 053574/0221 →
SECURITY AGREEMENT Recorded Aug 18, 2020
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 053531/0108 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 23, 2020
From: GEHTMAN, YEVGENI; SHACHAR, TOMER; BALIN, MAXIM
To: DELL PRODUCTS L.P.
Reel/Frame 053290/0955 →