Nova Patents
EP3192002B1

Preserving data protection with policy

Abstract

This record has no abstract on file.

EP3192002B1, drawing sheet 1
Sheet 1 of 4

Term

9 yearsleft in the term

Expires 7 September 2035.

  1. Priority
  2. Filed
  3. Granted
  4. Today
  5. Expires

14 claims: 6 independent, 8 dependent

  1. 1
    A method implemented in a computing device, the method comprising:identifying (302) an entity-trusted application on the computing device (100), the entity-trusted application configured to access data, and the entity-trusted application being an enlightened application (106);associating (306) a first process (210) that is a running instance of the entity-trusted application with an identifier (214) of an entity (208) that sets a data protection policy controlling access to the data;and enforcing (308), by an operating system (104) of the computing device, the data protection policy of the entity to enhance data security provided by the computing device due to the operating system enforcing the data protection policy on behalf of the entity-trusted application, wherein enforcing the data protection policy includes enforcing the data protection policy in response to a request from the first process for the operating system to treat the enlightened application as an unenlightened application, wherein the enlightened application (106) can switch between operating in an enlightened mode and an unenlightened mode and this switch is performed by the process that is a running instance of the enlightened application (106) requesting that the operating system (104) treat the enlightened application (106) as an unenlightened application, wherein in the enlightened mode, the operating system (104) allows the process that is a running instance of the enlightened application (106) to protect the data in accordance with the data protection policy, and in the unenlightened mode, the operating system (104) performs encryption and decryption, and otherwise operates to maintain the protection on the data in accordance with the data protection policy, and the operating system performs these operations on behalf of the process that is a running instance of the enlightened application (106) as if the enlightened application (106) were an unenlightened application, and the enforcing including: obtaining, by the operating system, the data protection policy;automatically encrypting, by the operating system in accordance with the data protection policy, data saved by the first process;saving the encrypted data in a container file that includes both metadata (204) and the encrypted data (202), the metadata including the identifier (206) of the entity;and preventing, by the operating system in accordance with the data protection policy, a second process that is a running instance of an entity-untrusted application from accessing the encrypted data.
  2. 4
    The method as recited in claims 1 to 3, further comprising treating the entity-trusted application as being an untrusted application for at least part of the data protection policy in response to a request from the first process for the operating system to treat the entity-trusted application as an entity-untrusted application.
  3. 5
    The method as recited in claims 1 to 4, the first process having multiple threads, and the first process requesting that the operating system treat a first set of one or more of the multiple threads, but not a second set of one or more of the multiple threads, as untrusted to obtain different policy enforcement behavior for the first set of one or more threads than for the second set of one or more threads.
  4. 6
    The method as recited in claims 1 to 5, the enforcing further including protecting the data when communicating the data to another device via a network (122), during buffer read operations and buffer write operations, and during clipboard read operations and clipboard write operations.
  5. 8
    The method as recited in claims 1 to 7, further comprising performing the enforcing in the absence of logical or visual isolation of:the entity-trusted application and the entity-untrusted application in separate application containers;and a user of the computing device logging into different user accounts.
  6. 13
    One or more computer-readable storage media storing computer-executable instructions that, when executed by a processing system, instruct the processing system to perform acts according to any of the preceding claims.
  7. 14
    A computing device comprising:a processing system comprising one or more processors;and one or more computer-readable storage media having stored thereon multiple instructions that, when executed by the processing system, cause the processing system to perform the acts according to any one of claims 1 to 12.