IP Library Granted Patent US 12,468,802
Granted Patent B2
US 12,468,802 · App. 18/522,402 · Granted Nov 11, 2025

Kernel-based protection of computer processes

Inventors: Yoav Orot (Somerville, MA); Gal Kaplan (Tel Aviv, IL); Roi Leibovich (Tel Aviv, IL); Dan Amiga (Ramat Hasharon, IL)
Assignee: ISLAND TECHNOLOGY, INC.
G06F21/54G06F2221/032
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,468,802
App. No.
18/522,402
Granted
Nov 11, 2025
Kind
B2
Abstract

Computer security apparatus including a kernel driver configured to be executed by a computer in a kernel mode and to thereupon perform protecting a process of a first computer software application executed by the computer, where the protecting is performed in accordance with a protection policy, receiving an instruction from the process to modify the protection policy, modifying the protection policy in accordance with the instruction, and protecting the process in accordance with the protection policy after it has been modified in accordance with the instruction.

Claims (56)

1 . A computer security method comprising:

protecting a process of a first computer software application executed by a computer, where the protecting is performed in accordance with a protection policy;

receiving an instruction from the process to modify the protection policy;

modifying the protection policy in accordance with the instruction; and

protecting the process in accordance with the protection policy after it has been modified in accordance with the instruction,

wherein the protecting, receiving, and modifying are performed by a kernel driver executed by the computer.

2 . The computer security method according to claim 1 wherein the first computer software application is a web browser.

3 . The computer security method according to claim 1 wherein any of the protecting, receiving, and modifying are performed after determining that a digital signature is valid, wherein the digital signature is of an executable file of the first computer software application, and wherein the determining is performed by the kernel driver executed by the computer.

4 . The computer security method according to claim 1 wherein the protecting comprises:

detecting an attempt, by a process of a second computer software application executed by the computer, to access an object associated with the first computer software application;

determining whether a digital signature is valid, wherein the digital signature is of an executable file of the second computer software application; and

allowing or preventing access to the object by the second computer software application in accordance with the protection policy, wherein the protection policy is at least partly based on whether the digital signature is valid,

wherein the detecting, determining, allowing, and preventing are performed by the kernel driver executed by the computer.

5 . The computer security method according to claim 4 wherein the object is a process or a thread of a process.

6 . The computer security method according to claim 1 wherein the protecting comprises:

receiving a decryption key from the process of the first computer software application;

receiving a request from the process of the first computer software application to receive the decryption key;

determining whether a digital signature is valid, wherein the digital signature is of the first computer software application; and

providing or not providing the decryption key to the process in accordance with the protection policy, wherein the protection policy is at least partly based on whether the digital signature is valid,

wherein the receiving, determining, allowing, providing, and not providing are performed by the kernel driver executed by the computer.

7 . The computer security method according to claim 6 wherein the decryption key is encrypted after receiving the decryption key from the process of the first computer software application, and further comprising decrypting the encrypted decryption key, if the digital signature is valid, prior to providing the decryption key to the process of the first computer software application.

8 . The computer security method according to claim 1 wherein the protecting comprises:

receiving an encrypted message from the process of the first computer software application, where the message is encrypted using a public key of a key pair;

determining whether a digital signature is valid, wherein the digital signature is of an executable file of the first computer software application; and

if the digital signature is valid,

decrypting the encrypted message using a private key of the key pair,

encrypting a response to the message using the private key, and

providing the encrypted response to the process of the first computer software application,

wherein the receiving, determining, decrypting, encrypting, and providing are performed by the kernel driver executed by the computer.

9 . Computer security apparatus comprising:

a kernel driver configured to be executed by a computer in a kernel mode and thereupon to perform

protecting a process of a first computer software application executed by the computer, where the protecting is performed in accordance with a protection policy,

receiving an instruction from the process to modify the protection policy,

modifying the protection policy in accordance with the instruction, and

protecting the process in accordance with the protection policy after it has been modified in accordance with the instruction.

10 . The computer security apparatus according to claim 9 wherein the first computer software application is a web browser.

11 . The computer security apparatus according to claim 9 wherein the kernel driver is configured to perform any of the protecting, receiving, and modifying after the kernel driver determines that a digital signature is valid, wherein the digital signature is of an executable file of the first computer software application.

12 . The computer security apparatus according to claim 9 wherein the kernel driver is configured to perform the protecting by

detecting an attempt, by a process of a second computer software application executed by the computer, to access an object associated with the first computer software application,

determining whether a digital signature is valid, wherein the digital signature is of an executable file of the second computer software application, and

allowing or preventing access to the object by the second computer software application in accordance with the protection policy, wherein the protection policy is at least partly based on whether the digital signature is valid.

13 . The computer security apparatus according to claim 12 wherein the object is a process or a thread of a process.

14 . The computer security apparatus according to claim 9 wherein the kernel driver is configured to perform the protecting by

receiving a decryption key from the process of the first computer software application;

receiving a request from the process of the first computer software application to receive the decryption key;

determining whether a digital signature is valid, wherein the digital signature is of the first computer software application; and

providing or not providing the decryption key to the process in accordance with the protection policy, wherein the protection policy is at least partly based on whether the digital signature is valid,

wherein the receiving, determining, allowing, providing, and not providing are performed by the kernel driver executed by the computer.

15 . The computer security apparatus according to claim 14 wherein the kernel driver is configured to encrypt the decryption key after receiving the decryption key from the process of the first computer software application, and decrypt the encrypted decryption key, if the digital signature is valid, prior to providing the decryption key to the process of the first computer software application.

16 . The computer security apparatus according to claim 9 wherein the kernel driver is configured to perform the protecting by

receiving an encrypted message from the process of the first computer software application, where the message is encrypted using a public key of a key pair,

determining whether a digital signature is valid, wherein the digital signature is of an executable file of the first computer software application, and

if the digital signature is valid,

decrypting the encrypted message using a private key of the key pair,

encrypting a response to the message using the private key, and

providing the encrypted response to the process of the first computer software application.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 5, 2023
From: OROT, YOAV; KAPLAN, GAL; AMIGA, DAN; LEIBOVICH, ROI
To: ISLAND TECHNOLOGY LTD.
Reel/Frame 065759/0810 →
Continuity (2)
Provisional Application 63428748 · Nov 30, 2022
Related Publication 20240176876A1 · May 30, 2024
References Cited (24)
US 11113086B1 · Steinberg · 2021 [cited by examiner]
US 11314859B1 · Singh · 2022 [cited by examiner]
US 11366931B2 · Goodridge · 2022 [cited by examiner]
US 11449602B1 · Tumblin · 2022 [cited by examiner]
US 20130227279A1 · Quinlan et al. · 2013 [cited by applicant]
US 20210089647A1 · Suwad · 2021 [cited by examiner]
US 20210117246A1 · Lal · 2021 [cited by examiner]
US 20210312057A1 · Kloth · 2021 [cited by examiner]
US 20220004623A1 · Trabelsi · 2022 [cited by examiner]
US 20220137996A1 · Mooring · 2022 [cited by examiner]
US 20220207139A1 · Strogov · 2022 [cited by examiner]
US 20220215101A1 · Rioux · 2022 [cited by examiner]
US 20220222338A1 · Gupta · 2022 [cited by examiner]
US 20220269802A1 · Iyer · 2022 [cited by examiner]
US 20220382855A1 · Burenkov · 2022 [cited by examiner]
US 20230062436A1 · Christner · 2023 [cited by examiner]
US 20230229761A1 · Laplante · 2023 [cited by examiner]
Wang, Xueyang; Karri, Ramesh. Reusing Hardware Performance Counters to Detect and Identify Kernel Control-Flow Modifying Rootkits. IEEE Transactions on Computer-Aided Design of Integrated Circuits and Systems, vol. 35, … [cited by examiner]
Tian, Donghai et al. A practical online approach to protecting kernel heap buffers in kernel modules. China Communications, vol. 13, Issue: 11. https://ieeexplore.ieee.org/stamp/stamp.jsp?tp=&arnumber=7781725 (Year: 201… [cited by examiner]
Sun, Jianhua et al. A Virtualized Harvard Architectural Approach to Protect Kernel Code. 2009 First International Workshop on Education Technology and Computer Science. https://ieeexplore.ieee.org/stamp/stamp.jsp?tp=&ar… [cited by examiner]
Kurtz, et al., “Towards a Framework for Android Security Modules: Extending SE Android Type Enforcement to Android Middleware”, TU biblio, Nov. 1, 2012, TU Darmstadt, Hesse, Germany. [cited by applicant]
Bugiel, et al., “Flexible and Fine-Grained Mandatory Access Control on Android for Diverse Security and Privacy Policies”, Proc. 22nd Usenix Security Symp., Sep. 28, 2013, pp. 131-146, USENIX: The Advanced Computing Sys… [cited by applicant]
Bugiel, et al., “Towards a Framework for Android Security Modules: Extending SE Android Type Enforcement to Android Middleware”, TU biblio, Nov. 1, 2012, TU Darmstadt, Hesse, Germany. [cited by applicant]
Deyannis, et al., “Andromeda: Enabling Secure Enclaves for the Android Ecosystem”, International Conference on Information Security, Nov. 2021, pp. 195-217, ICISC, Republic of Korea. [cited by applicant]