IP Library Granted Patent US 10,691,476
Granted Patent B2
US 10,691,476 · App. 14/752,888 · Granted Jun 23, 2020

Protection of sensitive data

Inventors: Aditya Kapoor (Portland, OR); Jonathan L. Edwards (Portland, OR)
Assignee: McAfee, LLC
G06F9/45558G06F21/53G06F21/554G06Q20/20G06Q20/206G06Q20/40G06Q20/4016G06F2009/45587
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,691,476
App. No.
14/752,888
Granted
Jun 23, 2020
Kind
B2
Abstract

Particular embodiments described herein provide for an electronic device that can be configured to monitor access to data in a secured area of memory at a hypervisor level, receive a request from a process to the data in the secured area, and deny the request if the process is not a trusted process. In an example, the electronic device is a point of sale device.

Claims (64)

1. At least one non-transitory machine readable medium comprising one or more instructions that when executed by at least one processor of an electronic device, cause the at least one processor to:

receive data via a network;

determine if the data includes sensitive information;

store the data in a secured area of memory if the data includes sensitive information;

monitor, by a security module, access to the data in the secured area of memory, wherein the secured area of memory is at a hypervisor level;

receive a request from an application to access the data in the secured area;

determine if the application is a trusted application; and

allow the request if the application is a trusted application; or

deny the request if the application is not a trusted application; and

wherein the one or more instructions further cause the at least one processor to store the data in a non-secured area of memory if the data does not include sensitive information.

2. The at least one non-transitory machine readable medium of claim 1 , further comprising one or more instructions that when executed by the at least one processor, further cause the at least one processor to:

set a permission to read the data in the secured area of memory to a deny permission.

3. The at least one non-transitory machine readable medium of claim 1 , further comprising one or more instructions that when executed by the at least one processor, further cause the at least one processor to:

allow the request if the application is included in a whitelist.

4. The at least one non-transitory machine readable medium of claim 1 , wherein the electronic device is a point of sale device.

5. An electronic device comprising:

memory; and

a hardware processor configured to execute a security module configured to:

receive data via a network;

determine if the data includes sensitive information;

store the data in a secured area of memory if the data includes sensitive information;

monitor access to data in a secured area of the memory, wherein the secured area of memory is at a hypervisor level;

receive a request from an application to access the data in the secured area;

determine if the application is a trusted application; and

allow the request if the application is a trusted application; or

deny the request if the application is not a trusted application; and

wherein the hardware processor is further configured to store the data in a non-secured area of memory if the data does not include sensitive information.

6. The apparatus of claim 5 , wherein the security module is further configured to:

set a permission to read the data in the secured area of the memory to a deny permission.

7. The apparatus of claim 5 wherein the security module is further configured to:

allow the request if the application is included in a whitelist.

8. The apparatus of claim 5 , wherein the electronic device is a point of sale device.

9. A method comprising:

receiving, with a hardware processor of an electronic device, data via a network;

determining, with the hardware processor, if the data includes sensitive information;

storing, with the hardware processor, the data in a secured area of memory if the data includes sensitive information;

monitoring, with the hardware processor, access to data in a secured area of memory, wherein the secured area of memory is at a hypervisor level;

receiving, with the hardware processor, a request from an application to access the data in the secured area;

determining, with the hardware processor, if the application is a trusted application; and

allowing, with the hardware processor, the request if the application is a trusted application; or

denying, with the hardware processor, the request if the application is not a trusted application; and

wherein the hardware processor is further configured to store the data in a non-secured area of memory if the data does not include sensitive information.

10. The method of claim 9 , further comprising:

setting a permission to read the data in the secured area of memory to a deny permission.

11. The method of claim 9 , further comprising:

allowing, with the hardware processor, the request if the application is included in a whitelist.

12. The method of claim 9 , wherein the electronic device is a point of sale device.

13. A system for protecting data, the system comprising:

memory in an electronic device;

a hardware processor in the electronic device, wherein the processor is configured to execute a security module configured to:

receive data via a network;

determine if the data includes sensitive information;

store the data in a secured area of memory if the data includes sensitive information;

monitor access to data in a secured area of the memory, wherein the secured area of memory is at a hypervisor level;

receive a request from an application to access the data in the secured area;

determine if the application is a trusted application; and

allow the request if the application is a trusted application; or

deny the request if the application is not a trusted application; and

wherein the hardware processor is further configured to store the data in a non-secured area of memory if the data does not include sensitive information.

14. The system of claim 13 , wherein the system is further configured to:

set a permission to read the data in the secured area of the memory to a deny permission.

15. The system of claim 13 , wherein the system is further configured to:

allow the request if the application is included in a whitelist.

16. The system of claim 13 , wherein the electronic device is a point of sale device.

Assignments (10)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 10, 2015
From: KAPOOR, ADITYA; EDWARDS, JONATHAN L.
To: MCAFEE, INC.
Reel/Frame 036060/0916 →