IP Library Granted Patent US 11,531,759
Granted Patent B2
US 11,531,759 · App. 17/181,506 · Granted Dec 20, 2022

Trusted updates

Inventors: Preet Mohinder (New Delhi, IN); Ratnesh Pandey (Uttar Pradesh, IN); Jaskaran Singh Khurana (New Delhi, IN); Amritanshu Johri (Haryana, IN)
Assignee: McAfee, LLC
G06F21/57G06F8/65G06F2221/2141
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,531,759
App. No.
17/181,506
Granted
Dec 20, 2022
Kind
B2
Abstract

There is disclosed in one example a computing apparatus, including: a hardware platform including a processor and a memory; and instructions encoded within the memory to instruct the processor to: provide a permission list; allocate an executable, the executable to have permissions according to the permission list; designate a child object of the executable; allocate a certificate for the child object; and after a system reboot, grant the child object permissions of the executable after validating the certificate.

Claims (38)

1. A computing apparatus, comprising:

a hardware platform comprising a processor circuit and a memory; and

instructions encoded within the memory to instruct the processor to:

provide a permission list;

allocate an executable, the executable to have permissions according to the permission list;

designate a child object of the executable;

allocate a certificate for the child object; and

after a system reboot, grant the child object permissions of the executable after validating the certificate.

2. The computing apparatus of claim 1 , wherein the instructions are further to query a certificate authority to determine that the certificate is valid.

3. The computing apparatus of claim 1 , wherein the instructions are further to assign a common certificate to a plurality of files created or imported by the executable.

4. The computing apparatus of claim 3 , wherein the instructions are further to grant permission to the plurality of files having a common certificate to modify one another.

5. The computing apparatus of claim 1 , wherein the permission list is to provide permissions specific to the executable.

6. The computing apparatus of claim 1 , wherein the instructions are further to allocate a trusted file set, the trusted file set comprising a set of files identified by the permission list as belonging to a common workflow of the executable.

7. The computing apparatus of claim 1 , wherein the instructions include instructions to run at least partially as a system management agent.

8. The computing apparatus of claim 1 , wherein the instructions are to run at least partially with elevated privileges.

9. The computing apparatus of claim 1 , wherein the instructions are to execute at least partially within a kernel module.

10. The computing apparatus of claim 1 , wherein the permission list provides systemwide permissions.

11. The computing apparatus of claim 1 , wherein the instructions are to provide permissions, according to the certificate, to execute any binary object on the computing apparatus, including binary objects not listed in the permission list.

12. One or more tangible, non-transitory computer-readable storage media, comprising instructions to:

allocate an object permission data structure;

assign to an updater object permissions from the object permission data structure, the permissions including permission to operate on a set of files;

propagate the permissions to a child object of the updater object;

assign the child object a cryptographically-verifiable certificate; and

after the updater object and child object have terminated, verify the certificate and re-assign the permissions to the child object.

13. The one or more tangible, non-transitory computer-readable storage media of claim 12 , wherein the instructions are further to query a certificate authority to determine that the certificate is valid.

14. The one or more tangible, non-transitory computer-readable storage media of claim 12 , wherein the instructions are further to assign a common certificate to a plurality of files created or imported by the updater object.

15. The one or more tangible, non-transitory computer-readable storage media of claim 14 , wherein the instructions are further to grant permission to the plurality of files having a common certificate to modify one another.

16. The one or more tangible, non-transitory computer-readable storage media of claim 12 , wherein the permission data structure is to provide permissions specific to the updater object.

17. The one or more tangible, non-transitory computer-readable storage media of claim 12 , wherein the instructions are further to allocate a trusted file set, the trusted file set comprising a set of files identified by the permission data structure as belonging to a common workflow of the updater object.

18. A computer-implemented method of providing inheritable permissions, comprising:

allocating an updater binary, the updater binary to update an executable object;

assigning permissions to the updater binary, including permissions to operate on a set of files;

allocating a child of the updater binary;

associating a certificate with the child;

assigning the permissions to the child as inherited permissions; and

after a system reset event, causing the child to re-inherit the inherited permissions upon validating the certificate.

19. The method of claim 18 , further comprising querying a certificate authority to determine that the certificate is valid.

20. The method of claim 18 , further comprising assigning a common certificate to a plurality of files created or imported by the executable object.

Assignments (2)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
Priority Claims (1)
IN 6600/CHE/2014 · Dec 26, 2014 · national
Continuity (3)
Continuation 16565643 · Sep 10, 2019
Continuation 15535552
Related Publication 20210173933A1 · Jun 10, 2021