IP Library Granted Patent US 9,760,720
Granted Patent B2
US 9,760,720 · App. 15/205,377 · Granted Sep 12, 2017

Securing temporary data on untrusted devices

Inventor: Robert Scott Chapman, III (Lewisville, NC)
Assignee: Senteon LLC
G06F21/602G06F3/065G06F3/067G06F3/0619G06F3/0659G06F21/6218
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,760,720
App. No.
15/205,377
Granted
Sep 12, 2017
Kind
B2
Abstract

One example method for securing data on untrusted devices includes the steps of intercepting a file command from a software application, the file command comprising a save command or a read command, and indicating a data file; determining whether the data file is a temporary data file; responsive to determining the data file is a temporary data file: if the command is a save command, encrypting data associated with the save command and writing the encrypted data to the temporary data file, if the command is a read command, decrypting data associated with the read command and providing the decrypted data to the software application.

Claims (53)

1. A method comprising:

intercepting a first command to open a data file from a software application;

prior to opening the data file, copying the data file to a first partition;

opening the copied data file on the first partition by the software application and not opening the data file;

after opening the copied data file, intercepting a file command from the software application, the file command comprising a save command or a read command, and indicating a temporary data file, the temporary data file associated with the copied data file;

determining whether the file command is directed to the temporary data file;

responsive to determining the file command is directed to the temporary data file:

if the file command is a save command, encrypting data associated with the save command and writing the encrypted data to the temporary data file, and

if the file command is a read command, decrypting data associated with the read command and providing the decrypted data to the software application; and

in response to intercepting a command to close the copied data file from the software application:

closing the copied data file;

replacing the data file with the copied data file; and

deleting the copied data file on the first partition and the temporary data file.

2. The method of claim 1 , further comprising linking a dynamically-linked library (“DLL”) to the software application, the DLL comprising at least one of a file save function or a file read function.

3. The method of claim 1 , wherein linking the DLL to the software application comprises replacing at least one link to an operating system (“OS”) file save function with a DLL file save function or an OS file read function with a DLL file read function.

4. The method of claim 1 , wherein the writing the encrypted data to the temporary data file comprises writing the temporary data file on a secure partition.

5. The method of claim 1 , wherein writing the encrypted data to the temporary data file comprises writing the encrypted data to the temporary data file on the first partition.

6. A system comprising:

a non-transitory computer-readable medium;

a processor in communication with the non-transitory computer readable medium, the processor configured to execute processor-executable instructions stored in the non-transitory computer-readable medium to:

intercept a first command to open a data file from a software application;

prior to opening the data file, copy the data file to a first partition;

open the copied data file on the first partition by the software application and not open the data file;

after opening the copied data file, intercept a file command from the a software application, the file command comprising a save command or a read command, and indicating a temporary data file, the temporary data file associated with the copied data file;

determine whether the file command is directed to the temporary data file is a temporary data file;

responsive to a determination the file command is directed to the data file is a temporary data file:

if the file command is a save command, encrypt data associated with the save command and write the encrypted data to the temporary data file; and

if the file command is a read command, decrypt data associated with the read command and provide the decrypted data to the software application; and

in response to intercepting a command to close the copied data file from the software application:

close the copied data file;

replace the data file with the copied data file; and

delete the copied data file on the first partition and the temporary data file.

7. The system of claim 6 , wherein the processor is further configured to link a dynamically-linked library (“DLL”) to the software application, the DLL comprising at least one of a file save function or a file read function.

8. The system of claim 6 , wherein the processor is further configured to replace at least one link to an operating system (“OS”) file save function with a DLL file save function or an OS file read function with a DLL file read function to link the DLL to the software application.

9. The system of claim 6 , wherein the processor is further configured to write the temporary data file on a secure partition to write the encrypted data to the temporary data file comprises.

10. The system of claim 6 , wherein the processor is further configured to write the encrypted data to the temporary data file on the first partition.

11. A non-transitory computer-readable medium comprising processor-executable instructions configured to cause a processor to:

intercept a first command to open a data file from a software application;

prior to opening the data file, copy the data file to a first partition;

open the copied data file on the first partition by the software application and not open the data file;

after opening the copied data file, intercept a file command from the software application, the file command comprising a save command or a read command, and indicating a temporary data file, the temporary data file associated with the copied data file;

determine whether the file command is directed to the temporary data file;

responsive to a determination the file command is directed to the temporary data file:

if the file command is a save command, encrypt data associated with the save command and write the encrypted data to the temporary data file; and

if the file command is a read command, decrypt data associated with the read command and provide the decrypted data to the software application; and

in response to intercepting a command to close the copied data file from the software application:

close the copied data file;

replace the data file with the copied data file; and

delete the copied data file on the first partition and the temporary data file.

12. The non-transitory computer-readable medium of claim 11 , wherein the processor-executable instructions are further configured to cause a processor to link a dynamically-linked library (“DLL”) to the software application, the DLL comprising at least one of a file save function or a file read function.

13. The non-transitory computer-readable medium of claim 11 , wherein the processor-executable instructions are further configured to cause a processor to replace at least one link to an operating system (“OS”) file save function with a DLL file save function or an OS file read function with a DLL file read function to link the DLL to the software application.

14. The non-transitory computer-readable medium of claim 11 , wherein the processor-executable instructions are further configured to cause a processor to write the temporary data file on a secure partition to write the encrypted data to the temporary data file comprises.

15. The non-transitory computer-readable medium of claim 11 , wherein the processor-executable instructions are further configured to cause a processor to write the encrypted data to the temporary data file on the first partition.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 26, 2018
From: SENTEON LLC
To: SV CAPITAL, LLC
Reel/Frame 047327/0071 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 16, 2016
From: CHAPMAN, ROBERT SCOTT, III
To: SENTEON LLC
Reel/Frame 040344/0875 →
Continuity (2)
Provisional Application 62191131 · Jul 10, 2015
Related Publication 20170083710A1 · Mar 23, 2017