IP Library › Granted Patent US 10,157,286
Granted Patent B2
US 10,157,286 · App. 14/975,567 · Granted Dec 18, 2018

Platform for adopting settings to secure a protected file

Inventors: Chad Skipper (Granger, TX); Elliot D. Lewis (Henderson, NV); David Konetski (Austin, TX); Christopher Burchett (Lewisville, TX); Richard William Schuckle (Austin, TX); James Michael Burke (Frisco, TX); Warren Wade Robbins (Celina, TX); Carrie Elaine Gates (Livermore, CA)
Assignee: DELL PRODUCTS LP
G06F21/6209G06F21/604H04L63/10H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,157,286
App. No.
14/975,567
Granted
Dec 18, 2018
Kind
B2
Abstract

Aspects of the present invention provide the ability to enforce access methods on data based upon a policy or policies identified within the metadata of a file. The data is self-protected by including or being wrapped with one or more policy/rule identifiers that act as a form of body armor to the data when in transit or in different situations. In embodiments, access is only granted upon successful authentication and compliance with the identified policy or policies. In embodiments, depending upon the conditions and policies, varying level access may be granted. In embodiments, depending upon the conditions and policies, the system may take one or more mitigations or remedial access levels, such as containerizing, sandboxing, granting limited access, or erasing the data.

Claims (40)

1. A computer-implemented method for controlling security of a computing device, the method comprising:

responsive to a protected file comprising a payload in an encrypted format and metadata being stored in a memory on the computing device, accessing the metadata of the protected file, the metadata comprising information related to one or more policies regarding security for accessing the payload of the protected file, the metadata further comprising a set of operations in a set order that is associated with one or more extensible content transformation modules, the one or more extensible content transformation modules providing one or more extensible transformative capabilities that are used by a secure data format processor according to the set order to decode the encrypted payload into a user-accessible format;

gathering computing device configuration data and situational data relevant to the one or more policies using one or more components of the computing device;

determining whether the computing device is able to be placed into an appropriate security configuration based upon applying at least some of the computing device configuration data and the situational data to the one or more policies regarding security for accessing the payload; and

responsive to the computing device being able to be placed into the appropriate security configuration, using a trusted platform module that interfaces with one or more components of the computing device to alter one or more configuration settings of the one or more components of the computing device to apply the appropriate security configuration to allow access to contents of the payload.

2. The computer-implemented method of claim 1 wherein the trusted platform module is a root-of-trust module that sets one or more configuration settings in the computing device that are always trusted by an operating system of the computing device.

3. The computer-implemented method of claim 1 wherein the step of gathering computing device configuration data and situational data relevant to the one or more policies using one or more components of the computing device comprises:

collecting, as indicated by the one or more policies, data comprising at least one or more of clock data, location data, BIOS data, operating system data, file system data, network data, connectivity data, security features data, user data, authentication data, user privileges data, software data of the computing device, and hardware data of the computing device.

4. The computer-implemented method of claim 1 wherein the trusted platform module operates in a run-time implementation mode.

5. The computer-implemented method of claim 1 wherein the steps of claim 1 are performed as part of a boot-up procedure of the computing device.

6. The computer-implemented method of claim 5 further comprising:

responsive to the computing device not being able to be placed into at least one appropriate security configuration, not allowing the computing device to complete the boot-up procedure.

7. The computer-implemented method of claim 2 wherein the one or more components with which the trusted platform module interfaces are hardware components, firmware components, or both.

8. The computer-implemented method of claim 7 further comprising:

responsive to the computing device not being able to be placed into an appropriate security configuration, using the trusted platform module that interfaces with one or more components of the computing device to alter one or more configuration settings of the one or more components of the computing device to disable or not enable one or more functions of the computing device.

9. The computer-implemented method of claim 8 wherein the step of disabling or not enabling one or more functions of the computing device comprises:

disabling one or more communication ports on the computing device to prevent data leaks of the protected file.

10. A system for adopting a configuration setting of a computing system to be consistent with a selected policy of a protected file, the system comprising:

a memory that stores the protected file, the protected file comprising a payload that has been encrypted and metadata, the metadata comprising information related to one or more policies regarding security of the payload and in which a policy corresponding to a set of configuration settings for the computing system, the metadata further comprising a set of operations in a set order;

an access control engine, communicatively coupled to a secure data format processor, that analyzes a current status of the computing system based upon the one or more policies and situational data received from one or more system components;

a policy/rules module, communicatively coupled to the access control engine that stores or acquires the one or more policies;

the secure data format processor that detects a presence of the protected file and coordinates selection and application of the selected policy responsive to the computing system being able to be placed into an appropriate security configuration corresponding to the selected policy, the selected policy indicating a set of configuration settings for the computing system;

a trusted platform module, communicatively coupled to the access control engine, that interfaces with one or more components of the computing system to alter one or more configuration settings of the one or more components according to the selected policy; and

one or more extensible content transformation modules, communicatively coupled to the secure data format processor via a security services component, that are associated with the set of operations included in the metadata and provide one or more extensible transformative capabilities to the secure data format processor, the one or more extensible transformative capabilities being used by the secure data format processor according to the set order to decode the encrypted payload into a user-accessible format.

11. The system of claim 10 wherein the trusted platform module comprises a root-of-trust platform for the computing system.

12. The system of claim 11 further comprising a system instrumentation module, communicatively coupled to the access control engine, that provides at least some of the situational data by collecting data relevant to the one or more policies.

13. The system of claim 11 further comprising an access environmental controls module, communicatively coupled to the access control engine, that provides at least some of the situational data by collecting data relevant to the one or more policies related to environmental conditions of the computing system.

14. The system of claim 11 wherein the selected policy is selected and applied as part of a boot-up procedure of the computing system.

15. The system of claim 14 wherein the selected policy comprises:

responsive to the computing system not being able to be placed into at least one appropriate security configuration to allow unencrypted access to the payload, not allowing the computing system to complete the boot-up procedure.

16. The system of claim 11 wherein the selected policy comprises:

disabling or not enabling one or more functions of the computing system as indicated by the selected policy.

17. A computing system for automatically altering its configuration to be consistent with one or more policies of a protected file stored on the computing system, the system comprising:

a memory that stores the protected file, the protected file comprising a payload in an encrypted format and metadata, the metadata comprising information related to one or more policies regarding security of the payload, the metadata further comprising a set of operations in a set order;

a secure data access system that analyzes a current security status of the computing system based upon the one or more policies and situational data received from one or more system components of the computing system and that selects a set of configuration settings for the computing system that is consistent with a policy from the one or more polices of the protected file and the situational data;

a trusted supply chain, communicatively coupled to the secure data access system, that comprises at least one hardware component of the computing system and that applies the set of configuration settings to one or more of the at least one hardware component; and

one or more extensible content transformation modules, communicatively coupled to a secure data format processor via a security services component, that are associated with the set of operations included in the metadata and provide one or more extensible transformative capabilities to the secure data format processor, the one or more extensible transformative capabilities being used by the secure data format processor according to the set order to decode the encrypted payload into a user-accessible format.

18. The system of claim 17 wherein the trusted platform module comprises a root-of-trust platform for the computing system.

19. The system of claim 17 wherein the set of configuration settings comprises disabling or not enabling one or more hardware features of the computing system.

20. The system of claim 10 , wherein, responsive to the system not having a transformative capability identified in the set of operations in the metadata, an extensible content transformation module that provides the transformative capability is added to the system, wherein the secure data format processor verifies that added the extensible content transformation module is a trusted module.

Assignments (15)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
RELEASE OF REEL 037848 FRAME 0001 (TL) Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040028/0152 →
RELEASE OF REEL 037848 FRAME 0210 (NOTE) Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040031/0725 →
RELEASE OF REEL 037847 FRAME 0843 (ABL) Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040017/0366 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 17, 2016
From: SKIPPER, CHAD; LEWIS, ELLIOT D; KONETSKI, DAVID; BURCHETT, CHRISTOPHER; SCHUCKLE, RICHARD WILLIAM; BURKE, JAMES MICHAEL; ROBBINS, WARREN WADE; GATES, CARRIE ELAINE
To: DELL PRODUCTS L.P.
Reel/Frame 038013/0126 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (TERM LOAN) Recorded Feb 18, 2016
From: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 037848/0001 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (ABL) Recorded Feb 18, 2016
From: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 037847/0843 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (NOTES) Recorded Feb 18, 2016
From: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 037848/0210 →
Continuity (2)
Continuation 14819322 · Aug 5, 2015
Related Publication 20170039379A1 · Feb 9, 2017
Cited By (2)
US 12,218,978 US 12,335,280