Nova Patents
CA2014868C

Computer file protection system

Abstract

The invention is a system for protecting the security of computer files. It has hardware elements, including a programmable auxiliary memory and control unit alomg with associated software elements. The security subsystem is installed on the host computer bus so that it resides in the control logic, address, and data signal path between the computer storage device and central processing unit. The security system is accessible by the computer operating system only during installation and initialization. Thereafter it is inaccessible to or by the operating system. Supervisor determined criteria for access permission to read, write and execute files are entered into the auxiliary memory system where they are protected from alteration. The security system will deny access to users with invalid entry criteria and refuse to write data to the file storage device when unauthorized operations have been performed. When breaches of these types occur the security system can lock the computer against further activity until it is released by entry of a master password from supervisory or security personnel. The system maintains a protected area in the computer memory device where, among other data, file signatures of all valid files are retained. The protected area of memory also maintains appropriate signatures of all internal files in the security system so that they can be automatically checked for integrity.

CA2014868C, drawing sheet 1
Sheet 1 of 25

Term

Term ended

Expired 19 April 2010, 16.4 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

34 claims: 4 independent, 30 dependent

  1. 1
    CLAIMS; 1. In a computer file protection method for a host digital computer, said computer having a file storage device and a central processing unit connected electronically by a bus carrying control logic, address, and data signals, said computer further being supplied with operating system software, the improvement which comprises:providing a file security subsystem for said digital computer, said security subsystem further comprising a programmable auxiliary memory and control unit attachable to the host computer bus in a manner 10 so that it resides in said control logic, address, and data signal path between said storage device and central processing unit, said security subsystem being accessible by the computer operating system for initialization and modification only during an installation stage of the security subsystem but following said installation stage, during computer 15 system operation, the security subsystem is inaccessible to or by the operating system, the auxiliary memory system being adapted for receiving and retaining supervisor entered criteria for access permission for read, write and execute operations for all files to be protected, 20 so that upon receiving valid user identification the auxiliary memory and control unit will indicate to the host computer operating system which files are accessible to that user and what operations may be performed upon said files, said auxiliary control unit denying entry to users with invalid entry criteria and refusing to write data to the 25 file storage device when unauthorized operations have been performed.
  2. 3
    A computer file protection method which comprises:providing a host digital computer, said computer having a file storage device and a central processing unit connected electronically by a bus carrying control logic, address and data signals;35 supplying operating system software for said computer;CA 02014868 1999-05-25 - 17 further providing a file security subsystem for said digital computer, said security subsystem further comprising a programmable auxiliary memory and control unit attachable to the host computer bus in a manner so that it resides in said control logic, address, and data signal path between said storage device and central processing unit, said security subsystem being accessible by the computer operating system for initialization and modification only during an installation stage of the security subsystem but following said installation stage, during computer system operation, the security subsystem is inaccessible to or by the operating system, the auxiliary memory system being adapted for receiving and retaining supervisor entered criteria for access permission for read, write and execute operations for all files to be protected, so that upon receiving valid user identification the auxiliary memory and control unit will indicate to the host computer operating system which files are accessible to that user and what operations may be performed upon said files, said auxiliary control unit denying entry to users with invalid entry criteria and refusing to write data to the file storage device when unauthorized operations have been performed.
  3. 15
    A computer file protection method for a digital computer accessible by a user, said computer having a file storage device for storing files and interconnected with a central processing unit by a bus carrying control logic signals, address signals, and data signals, said computer further being supplied with a computer operating system, which comprises :(a) providing a file security subsystem for said digital computer which comprises a programmable auxiliary memory and a control unit;(b) attaching said programmable auxiliary memory and said control unit to the bus in a manner so that it resides in the bus between said file storage device and said central processing unit;(c) allowing access to said file security subsystem by the computer operating system for initialization and modification only during an installation stage of the file security subsystem and disallowing access to said file security subsystem by said computer operating system following said installation stage;(d) providing the programmable auxiliary memory system with supervisor entered access criteria for access permission for read operations, write operations and execute operations for each one of all of the files stored in said file storage device;(e) requiring each user to provide to said programmable auxiliary memory a valid user identification, whereupon said programmable auxiliary memory and control unit will indicate to the computer operating system only those of said files which are accessible to that user and whether read operations, write operations and execute operations may be CA 02014868 2000-01-13 77983-1 performed upon said accessible files, said auxiliary memory and control unit denying access to users with invalid access criteria and refusing to write data to any of the files stored in said file storage device when operations without valid access criteria have been attempted.
  4. 25
    A computer file protection system for a digital computer accessible for storing files and interconnected with a central processing unit by a bus carrying control logic signals, address signals, and data signals, said computer CA 02014868 2000-01-13 77983-1 further being supplied with a computer operating system, the combination comprising:(a) means for providing a file security subsystem for said digital computer which comprises programmable auxiliary memory and a control unit;(b) means for attaching said programmable auxiliary memory and said control unit to the bus in a manner so that it resides in the bus between said file storage device and said central processing unit;(c) means for allowing access to said file security subsystem by the computer operating system for initialization and modification only during an installation stage of the file security subsystem by said computer operating system following said installation stage;(d) means for providing the programmable auxiliary memory system with supervisor entered access criteria for access permission for read operations, write operations and execute operations for each one of all the files stored in said file storage device;(e) means for requiring each user to provide to said programmable auxiliary memory a valid user identification, whereupon said programmable auxiliary memory and control unit will indicate to the computer operating system only those of said files which are accessible to that user and whether read operations, write operations and execute operations may be performed upon said accessible files, said auxiliary memory and control unit denying access to users with invalid access criteria and refusing to write data to any of the files stored in said file storage device when operations without valid access criteria have been attempted. CA 02014868 2000-01-13 77983-1