System, Method and Computer Program Product for Administering Trust Dependent Functional Control over a Portable Endpoint Security Device
Claim Score by NHIP
Abstract
A system, method and computer program product for administering trust dependent functional control over a portable endpoint security device (PEPS). A reconnoitering application in conjunction with a trust enforcement policy determines a relative trusted state of the host processing unit and administers trust dependent functional control over the PEPS in dependence on one or more trust dependent characteristics reconnoitered from the host processing unit. The trust dependent characteristics reconnoitered from the host processing unit may be location dependent, context dependent, hardware configuration dependent and logical state dependent.

Term
Projected expiry 20 October 2026.
- Priority and filed
- Published
- Today
- Projected expiry
51 claims: 3 independent, 48 dependent
- 1A system for administering trust dependent functional control over a portable endpoint security device comprising:a trust enforcement policy including one or more predefined trust dependent characteristics for which the trust dependent functional control is to be administered;a reconnoitering application including instructions executable by a processor to;reconnoiter one or more trust dependent characteristics associated with a host processing unit;determine a relative trusted state of the host processing unit in dependence on the trust enforcement policy and the trust dependent characteristics reconnoitered from the host processing unit;and, administer the trust dependent functional control over the portable endpoint security device in dependence on the determined relative trusted state of the host processing unit.
- 18A method for administering trust dependent functional control over a portable endpoint security device comprising a trust enforcement policy including one or more predefined trust dependent characteristics for which the trust dependent functional control is to be administered coupled to a reconnoitering application including instructions executable by a processor for;reconnoitering one or more trust dependent characteristics associated with a host processing unit;determining a relative trusted state of the host processing unit in dependence on the trust enforcement policy and the trust dependent characteristics reconnoitered from the host processing unit;and, administering the trust dependent functional control over the portable endpoint security device in dependence on the determined relative trusted state of the host processing unit.
- 35Broadest claimClaim Score 56, average(NHIP)A computer program product for administering trust dependent functional control over a portable endpoint security device embodied in a tangible form comprising instructions executable by a processor for;reconnoitering one or more trust dependent characteristics associated with a host processing unit;determining a relative trusted state of the host processing unit in dependence on a trust enforcement policy and the one or more trust dependent characteristics reconnoitered from the host processing unit;and, administering trust dependent functional control over the portable endpoint security device in dependence on the determined relative trusted state of the host processing unit.
Independent claims3
126 paragraphs in 6 sections, as filed
CROSS-REFERENCE TO RELATED APPLICATIONS
0001This application is a related application to co-pending U.S. patent application Ser. Nos. 10/739,552 filed on Dec. 17, 2003; Ser. No. 10/796,324 filed on Mar. 8, 2004; and Ser. No. 11/383,154 filed on May 12, 2006 to a common inventor and assignee; the aforementioned patent applications are hereby incorporated by reference in their entirety as if fully set forth herein.
FIELD OF INVENTION
0002The present invention relates generally to a data processing system, method and computer program product and more specifically to functionality control in dependence on a relative trusted state of a host processing unit in which a portable endpoint security device is coupled thereto.
BACKGROUND
0003The corporate workforce is becoming increasingly mobile and dependent on accessing electronic information such as emails, documents, financial information, and maintaining contact with business associates while traveling or otherwise being displaced from a central work location. Frequently, workers carry laptops, cell phones, PDA's, Blackberries™ and integrated versions of the latter and former to stay in touch with their home offices. However, in the majority of situations, a worker will have access to a remote computer system owned and/or managed by a third party but is hesitant to use these available resources due to concerns of malware being installed on the remote computer systems; and, the possibility of another recovering sensitive, proprietary and/or personal information left behind in cookies, temporary files, browsing histories and the like.
0004For example, Internet Cafes are becoming ubiquitous in most major cities around the world, as well as in most major hotel chains and larger airports; all of which have computing resources available that would allow a worker to check for important emails, send and receive documents and allow other forms of common electronic commerce if sufficient safeguards were available. Preferably, these safeguards would be disposed in a highly portable device which readily interfaces with these resources, prevents malware from compromising security or data integrity, provides trusted remote access to the worker's private network and further avoids leaving sensitive information behind.
0005In many instances, the available computing resources incorporate sufficient safeguards which are redundant to those contained in the highly portable device, thus negatively impacting a user's productivity, providing unnecessary transactions and adding to the processing burden of the available computing resource. Therefore, a highly portable device which determines the relative trusted state of the available computing resource would be highly advantageous.
SUMMARY
0006This disclosure addresses the deficiencies of the relevant art and provides exemplary systematic, methodic and computer program product embodiments which incorporates in various embodiments, a portable endpoint security device operatively coupled to a host processing unit having an unknown but generally ascertainable trusted state. The various embodiments presented herein provide exemplary mechanisms for determining a relative trusted state of a host processing unit and where permitted by a trust enforcement policy, simplify the usage of the portable end-point security device (PEPS) and improve the overall system performance of the host processing unit while maintaining an adequate level of security.
0007In an exemplary systematic embodiment, a system for administering trust dependent functional control over a portable endpoint security device may be provided. This exemplary systematic embodiment comprises a trust enforcement policy accessible by the portable endpoint security device. The trust enforcement policy includes one or more predefined trust dependent characteristics for which the trust dependent functional control may be administered. A reconnoitering application may be further provided which includes instructions executable by a processor to reconnoiter one or more trust dependent characteristics associated with the host processing unit; determine a relative trusted state of the host processing unit in dependence on the trust enforcement policy and the one or more trust dependent characteristics reconnoitered from the host processing unit; and administer the trust dependent functional control over the portable endpoint security device in dependence on the determined relative trusted state of the host processing unit.
0008In a first related exemplary systematic embodiment, the administered trust dependent functional control over the portable endpoint security device may be one or more of; controlling access to a secure memory area internal to the portable endpoint security device and controlling the transfer of information between a networked resource and the portable endpoint security device.
0009In a second related exemplary systematic embodiment, the administered trust dependent functional control over the portable endpoint security device may be one or more of; limiting access to an internal anti-malware application, displaying graphical indicia of malware detected by the reconnoitering application on the host processing unit, removing the detected malware from the host processing unit and any combination thereof.
0010In a third related exemplary systematic embodiment, the administered trust dependent functional control over the portable endpoint security device may be one or more of; controlling offline usage of temporarily cached information and controlling audit functions internal to the portable endpoint security device.
0011In a fourth related exemplary systematic embodiment, the administered trust dependent functional control over the portable endpoint security device may be one or more of, controlling distribution of an internally maintained application, controlling usage of the internally maintained application, providing change management of the internally maintained application and any combination thereof.
0012In a fifth related exemplary systematic embodiment, the administered trust dependent functional control over the portable endpoint security device may be one or more of, controlling distribution of a document, controlling access to the document and providing change management of the document.
0013In a sixth related exemplary systematic embodiment, the administered trust dependent functional control over the portable endpoint security device may be one or more of; determining if an existing host application has an executable association with an internally maintained file, allowing the host application to access the internally maintained file, executing an internally maintained application, downloading an internally maintained application, executing a remote client application and any combination thereof.
0014In a seventh related exemplary systematic embodiment, at least one of the one or more trust dependent characteristics reconnoitered from the host processing unit may be location dependent, context dependent and any combination thereof.
0015In an eighth related exemplary systematic embodiment, the location dependence may be inferred from one or more of, an IP address, an IP address range, a MAC address, a domain name, a set of GPS coordinates and any combination thereof.
0016In a ninth related exemplary systematic embodiment, the context dependence may be inferred from one or more of, a memory execution stack, a registry entry, a Windows COM object, a Windows DCOM object, a DSOM object, a service, a process and any combination thereof.
0017In a tenth related exemplary systematic embodiment, the context dependence may be inferred from one or more of, a footprint of an operating system, a hardware configuration, an object, a binary file, a security policy, a verification indicia and any combination thereof.
0018In an eleventh related exemplary systematic embodiment, the verification indicia may be one or more of; a cryptogram, a digital credential, a digital signature, a checksum value, a cyclic redundancy check value, a hash value and any combination thereof.
0019In a twelfth related exemplary systematic embodiment, the determined relative trusted state of the host processing unit may be determinative of a level of access a user may be afforded to information contained in or available using the portable endpoint security device.
0020In a thirteenth related exemplary systematic embodiment, the determined relative trusted state may be determinative of a level of required user interaction with the portable endpoint security device.
0021In a fourteenth related exemplary systematic embodiment, the administered trust dependent functional control over the portable endpoint security device may be established for one or more of, internal data manipulation, an application manipulation, an application execution and any combination thereof.
0022In a fifteenth related exemplary systematic embodiment, the application execution includes execution of internal maintained applications when the relative trusted state of the host processing unit may be low and execution of external applications when the relative trusted state of the host processing unit may be high.
0023In a sixteenth related exemplary systematic embodiment, the administered level of functional control over the portable endpoint security device may be scalable in at least partial dependence on the determined relative trusted state of the host processing unit.
0024In an exemplary methodic embodiment, a method for administering trust dependent functional control over a portable endpoint security device comprising a trust enforcement policy including one or more predefined trust dependent characteristics for which the trust dependent functional control may be to be administered coupled to a reconnoitering application may be provided. The exemplary methodic embodiment comprises instructions executable by a processor for;
0025reconnoitering one or more trust dependent characteristics associated with a host processing unit;
0026determining a relative trusted state of the host processing unit in dependence on the trust enforcement policy and the trust dependent characteristics reconnoitered from the host processing unit; and,
0027administering the trust dependent functional control over the portable endpoint security device in dependence on the determined relative trusted state of the host processing unit.
0028In a first related exemplary methodic embodiment, further instructions executable by the processor are provided for performing one or more of, controlling access to a secure memory area internal to the portable endpoint security device and controlling the transfer of information between a networked resource and the portable endpoint security device.
0029In a second related exemplary methodic embodiment, further instructions executable by the processor are provided for performing one or more of, limiting access to an internal anti-malware application, displaying graphical indicia of malware detected by the reconnoitering application on the host processing unit, removing the detected malware from the host processing unit and any combination thereof.
0030In a third related exemplary methodic embodiment, further instructions executable by the processor are provided for performing one or more of, controlling offline usage of temporarily cached information and controlling audit functions internal to the portable endpoint security device.
0031In a fourth related exemplary methodic embodiment, further instructions executable by the processor are provided for performing one or more of, controlling distribution of an internally maintained application, controlling usage of the internally maintained application, providing change management of the internally maintained application and any combination thereof.
0032In a fifth related exemplary methodic embodiment, further instructions executable by the processor are provided for performing one or more of, controlling distribution of a document, controlling access to the document and providing change management of the document.
0033In a sixth related exemplary methodic embodiment, further instructions executable by the processor are provided for performing one or more of, determining if an existing host application has an executable association with an internally maintained file, allowing the host application to access the internally maintained file, executing an internally maintained application, downloading an internally maintained application, executing a remote client application and any combination thereof.
0034In a seventh related exemplary methodic embodiment, at least one of the one or more trust dependent characteristics reconnoitered from the host processing unit may be location dependent, context dependent and any combination thereof.
0035In an eighth related exemplary methodic embodiment, the location dependence may be inferred from one or more of, an IP address, an IP address range, a MAC address, a domain name, a set of GPS coordinates and any combination thereof.
0036In a ninth related exemplary methodic embodiment, the context dependence may be inferred from one or more of, a memory execution stack, a registry entry, a Windows COM object, a Windows DCOM object, a DSOM object, a service, a process and any combination thereof.
0037In a tenth related exemplary methodic embodiment, the context dependence may be inferred from one or more of, a footprint of an operating system, a hardware configuration, an object, a binary file, a security policy, verification indicia and any combination thereof.
0038In an eleventh related exemplary methodic embodiment, the verification indicia may be one or more of, a cryptogram, a digital credential, a digital signature, a checksum value, a cyclic redundancy check value, a hash value and any combination thereof.
0039In a twelfth related exemplary methodic embodiment, the determined relative trusted state of the host processing unit may be determinative of a level of access a user may be afforded to information contained in or available using the portable endpoint security device.
0040In a thirteenth related exemplary methodic embodiment, the determined relative trusted state may be determinative of a level of required user interaction with the portable endpoint security device.
0041In a fourteenth related exemplary methodic embodiment, the administered trust dependent functional control over the portable endpoint security device may be established for one or more of, internal data manipulation, application execution and any combination thereof.
0042In a fifteenth related exemplary methodic embodiment, the internal data manipulation may be one or more of, data, object and application manipulation.
0043In a sixteenth related exemplary methodic embodiment, the application execution includes execution of internal maintained applications when the relative trusted state of the host processing unit may be low and execution of external applications when the relative trusted state of the host processing unit may be high.
0044In a seventeenth related exemplary methodic embodiment, the administered level of functional control over the portable endpoint security device may be scalable in at least partial dependence on the determined relative trusted state of the host processing unit.
0045In an exemplary computer program product (CPP) embodiment, a program for administering trust dependent functional control over a portable endpoint security device may be provided. The program may be embodied in a tangible form comprising instructions executable by a processor for; reconnoitering one or more context dependent characteristics associated with a host processing unit; determining a relative trusted state of the host processing unit in dependence on a trust enforcement policy and the one or more context dependent characteristics reconnoitered from the host processing unit and administering the trust dependent functional control over the portable endpoint security device in dependence on the determined relative trusted state of the host processing unit.
0046In a first related exemplary CPP embodiment, further instructions executable by the processor are provided for performing one or more of; controlling access to a secure memory area internal to the portable endpoint security device and controlling the transfer of information between a networked resource and the portable endpoint security device.
0047In a second related exemplary CPP embodiment, further instructions executable by the processor are provided for performing one or more of, limiting access to an internal anti-malware application, displaying graphical indicia of malware detected by the reconnoitering application on the host processing unit, removing the detected malware from the host processing unit and any combination thereof.
0048In a third related exemplary CPP embodiment, further instructions executable by the processor are provided for performing one or more of; controlling offline usage of temporarily cached information and controlling audit functions internal to the portable endpoint security device.
0049In a fourth related exemplary CPP embodiment, further instructions executable by the processor are provided for performing one or more of; controlling distribution of an internally maintained application, controlling usage of the internally maintained application, providing change management of the internally maintained application and any combination thereof.
0050In a fifth related exemplary CPP embodiment, further instructions executable by the processor are provided for performing one or more of; controlling distribution of a document, controlling access to the document and providing change management of the document.
0051In a sixth related exemplary CPP embodiment, further instructions executable by the processor are provided for performing one or more of; determining if an existing host application has an executable association with an internally maintained file, allowing the host application to access the internally maintained file, executing an internally maintained application, downloading an internally maintained application, executing a remote client application and any combination thereof.
0052In a seventh related exemplary CPP embodiment, at least one of the one or more trust dependent characteristics reconnoitered from the host processing unit may be location dependent, context dependent and any combination thereof.
0053In an eighth related exemplary CPP embodiment, the location dependence may be inferred from one or more of; an IP address, an IP address range, a MAC address, a domain name, a set of GPS coordinates and any combination thereof.
0054In a ninth related exemplary CPP embodiment, the context dependence may be inferred from one or more of, a memory execution stack, a registry entry, a Windows COM object, a Windows DCOM object, a DSOM object, a service, a process and any combination thereof.
0055In a tenth related exemplary CPP embodiment, the context dependence may be inferred from one or more of; a footprint of an operating system, a hardware configuration, an object, a binary file, a security policy, verification indicia and any combination thereof.
0056In an eleventh related exemplary CPP embodiment, the verification indicia may be one or more of; a cryptogram, a digital credential, a digital signature, a checksum value, a cyclic redundancy check value, a hash value and any combination thereof.
0057In a twelfth related exemplary CPP embodiment, the determined relative trusted state of the host processing unit may be determinative of a level of access a user may be afforded to information contained in or available using the portable endpoint security device.
0058In a thirteenth related exemplary CPP embodiment, the determined relative trusted state may be determinative of a level of required user interaction with the portable endpoint security device.
0059In a fourteenth related exemplary CPP embodiment, the administered trust dependent functional control over the portable endpoint security device may be established for one or more of; internal data manipulation, application manipulation, application execution and any combination thereof.
0060The various exemplary systematic, methodic and computer program product embodiments described above are provided in related numeric embodiments for convenience only. No limitation to the various exemplary embodiments is intended by the use of the numeric designations.
BRIEF DESCRIPTION OF THE DRAWINGS
The features and advantages will become apparent from the following detailed description when considered in conjunction with the accompanying drawings. Where possible, the same reference numerals and characters are used to denote like features, elements, components or portions. Optional components or features may be shown in dashed or dotted lines. When applicable, optional components or features are described as such in the detailed description provided below. It is intended that changes and modifications can be made to the described embodiments without departing from the true scope and spirit of the various inventive embodiments.
FIG. <b>1</b>—depicts a generalized and exemplary block diagram of a host processing unit as described in the various embodiments.
FIG. <b>1</b>A—depicts a generalized and exemplary block diagram of a portable endpoint security device.
FIG. <b>2</b>—depicts an exemplary detailed block diagram of various exemplary characteristics used to determine a relative trusted state of the host processing unit as described in the various embodiments.
FIG. <b>3</b>—depicts an exemplary detailed block diagram of the various modules of the portable end-point security device (PEPS) which may be functionally controlled in dependence on a determined relative trusted state of the host processing unit as described in the various embodiments.
FIG. <b>4</b>—depicts an exemplary flow chart of a process for determining the relative trusted state of the host processing unit and the relationship of the various characteristics for administering functional control over various functionalities incorporated the portable end-point security device (PEPS) as described in the various embodiments.
FIG. <b>5</b>—depict an exemplary flow chart of a process for determining whether to utilize applications which may be present on the host processing unit in dependence on the determined relative trusted state of the host processing unit.
DETAILED DESCRIPTION
0068In various embodiments, the ability to provide functional control over one or more integrated features of a portable endpoint security device (PEPS) is provided. Control over the various integrated features is dependent on the determined relative trusted state of a host computer system in which the PEPS is operatively coupled. In general, the greater the determined relative level of trust of the computer system to which the PEPS is operatively coupled, the less reliance is placed on the PEPS, thus simplifying user interactions with the PEPS and improving overall performance by permitting certain of the integrated features to be performed on the host computer system rather than within the secure domain of the PEPS. Since the PEPS may be configured to work with non-traditional computer systems, for example, portable data assistants (PDA), smart phones and other intelligent devices, the term “host processing unit” is used to refer to the broader category of intelligent devices capable of being operatively coupled to a PEPS. For certain installations, the PEPS may be configured as a software token which resides in a protected area of memory of the host processing unit.
0069Where necessary, computer programs, algorithms and routines are envisioned to be programmed in a high level, preferably an object oriented language, for example Java™, C, C++, C#, CORBA or Visual Basic™.
0070Referring to <figref idref="DRAWINGS">FIG. 1</figref>, an exemplary block diagram of a host processing unit <b>100</b> is depicted. The host processing unit <b>100</b> may be configured as a general purpose computer system, laptop, smart phone, PDA or another intelligent device having compatible communications and data formats. The host processing unit <b>100</b> includes a communications infrastructure <b>90</b> used to transfer data, memory addresses where data files are to be found and control signals among the various components and subsystems associated with the host processing unit <b>100</b>.
0071A processor <b>5</b> is provided to interpret and execute logical instructions stored in the main memory <b>10</b>. The main memory <b>10</b> is the primary general purpose storage area for instructions and data to be processed by the processor <b>5</b>. A timing circuit <b>15</b> is provided to coordinate programmatic activities within the host processing unit <b>100</b> and the PEPS <b>160</b> as shown in <figref idref="DRAWINGS">FIG. 2</figref>. The timing circuit <b>15</b> may be used as a watchdog timer, clock or as a counter arrangement and may be programmable.
0072The processor <b>5</b>, main memory <b>10</b> and timing circuit <b>15</b> are directly coupled to the communications infrastructure <b>90</b>. A display interface <b>20</b> is provided to drive a display <b>25</b> associated with the host processing unit <b>100</b>. The display interface <b>20</b> is electrically coupled to the communications infrastructure <b>90</b> and provides signals to the display <b>25</b> for visually outputting both graphical displays and alphanumeric characters. The display interface <b>20</b> may include a dedicated graphics processor and memory (not shown) to support the displaying of graphics intensive media. The display <b>25</b> may be of any type (e.g., cathode ray tube, gas plasma, LCD.)
0073A secondary memory subsystem <b>30</b> is provided which houses retrievable storage units such as a hard disk drive <b>35</b>, a removable storage drive <b>40</b>, and an optional logical media storage drive <b>45</b>. The removable storage drive <b>40</b> may be a replaceable hard drive, optical media storage drive or a solid state flash RAM device. The logical media storage drive <b>45</b> may include a flash RAM device, an EEPROM encoded with one or programs used in the various embodiments described herein, or optical storage media (CD, DVD.)
0074A generalized communications interface <b>55</b> is provided which allows the host processing unit <b>100</b> to communicate over one or more networks <b>85</b>. The network <b>85</b> may be of a wired, optical, or radio frequency type normally associated with computer networks for example, wireless computer networks based on various IEEE standards 802.11x, where x denotes the various present and evolving wireless computing standards, for example WiMax 802.16 and WRANG 802.22.
0075Alternately, digital cellular communications formats compatible with for example GSM, 3G, CDMA, TDMA and evolving cellular communications standards. In a third alternative embodiment, the network <b>85</b> may include hybrids of computer communications standards, cellular standards, cable networks and/or satellite communications standards.
0076The host processing unit <b>100</b> includes an operating system for example, Microsoft™ Windows 2000, XP and later versions thereof; or, if arranged as dedicated network appliance, an embedded operating environment for example, Microsoft Windows CE. The host processing unit <b>100</b> further includes the necessary hardware and software drivers necessary to fully utilize the devices coupled to the communications infrastructure <b>90</b> and one or more programs which enable the host processing unit <b>100</b> to communicate with other intelligent devices and networked resources <b>85</b>′ over the network <b>85</b>.
0077The host processing unit <b>100</b> may include standard user software applications common in office suite type arrangements such as a word processor, spreadsheet, database, presentation, Internet browser and email software. Additional software applications may include remote communications clients for example, Citrix™, virtual private networking (VPN) software, malware protection applications and two or more factor authentication packages. The term “malware,” is used generically to refer to malevolent computer viruses, worms and spyware.
0078In an embodiment, an accessible unique identifier ID <b>65</b> is provided which may be useful for determining whether the host processing unit <b>100</b> in which the PEPS <b>160</b> is operatively coupled is considered “trusted.” The term “trusted” means that the host processing unit <b>100</b> and the applications executed thereby can be trusted to follow their intended programming with a lower possibility of inappropriate activities such as surreptitiously recording passwords, monitoring secure transactions, and/or altering data.
0079In an optional embodiment, the host processing unit <b>100</b> may include a GPS unit <b>60</b> which provides geographical coordinates useful for determining a trusted location. GPS units <b>60</b> are now commonly integrated into a wide range of intelligent devices, (e.g., cellular telephones,) in which the PEPS <b>160</b> may be operatively coupled to or directly integrated within as well.
0080In an optional embodiment, a trusted platform module (TPM) <b>70</b> or equivalent hardware based security device may be coupled to the communications infrastructure <b>90</b>. The TPM <b>70</b> is compatible with the applicable trusted computing group industry standard specifications downloadable from www.trustedcomputinggroup.org.
0081In an embodiment, the PEPS <b>160</b> may be operatively coupled <b>75</b> to the communications interface <b>55</b> by a universal serial bus (USB) connection. However, other arrangements known in the relevant art such as PCMCIA, BlueTooth™, wireless network <b>85</b>, serial RS-232 or infrared optical connections to the communications interface <b>55</b> may be used in combination or as a replacement for the USB connection. In an alternate embodiment, the PEPS <b>160</b> may be configured as a software based token which is maintained in a secure area of the main memory <b>10</b>.
0082Referring to <figref idref="DRAWINGS">FIG. 1A</figref>, an exemplary block diagram of PEPS <b>160</b> is provided. In various embodiments, the PEPS <b>160</b> is disposed in a highly portable form factor similar to common “pen” or “flash” memory drives. In other embodiments, the PEPS <b>160</b> may be incorporated into common flash memory card form factors, for example, CF, SD and XD form factors and maintained as a software token.
0083An optional microprocessor <b>105</b> may be provided to perform cryptographic operations and other functions internally rather than utilizing the processor <b>5</b> associated with the host processing unit <b>100</b>. For example, an ARM7 32-bit processor manufactured by ARM Holdings plc., provides a suitable family of low-power 32-bit RISC microprocessor cores optimized for cost and power-sensitive consumer applications. If present, the processor <b>105</b> is operatively coupled to a communications infrastructure <b>190</b>.
0084A memory subsystem <b>110</b> is operatively coupled to the communications infrastructure <b>190</b>. In various embodiments, the memory subsystem <b>110</b> is partitioned into two or more portions <b>110</b>A, <b>110</b>B. One portion of the partitioned memory <b>110</b> contains the applications and data used in performing the various PEPS functions including but not limited to secure storage, stealth browser and email applications, auditing applications, secure document distribution, license management, application update management, authentication, cryptography, temporarily cached applications and malware protection. A second portion of the memory <b>110</b>B is provided for direct user storage of data. The actual number of partitions provided in the memory subsystem <b>110</b> may be varied to suit various functional requirements.
0085In an embodiment, the PEPS <b>160</b> is configured as a USB peripheral device which utilizes portions of the operating system (e.g., WINSOCK, MSGINA, LOGON, RUNDLL32 in Microsoft Windows™) and the processor <b>5</b> associated with the remote host processing unit <b>100</b> to operate and communicate over the USB connection <b>75</b> and/or network <b>85</b>.
0086An Autorun bootstrap module <b>115</b> is provided which causes the host processing unit <b>100</b> to detect and access the PEPS <b>160</b> to operatively load the necessary executable code into the main memory <b>10</b> of the remote host processing unit <b>100</b>. In an embodiment, the detection of the coupled PEPS <b>160</b> is accomplished using “Plug N Play” technology known in the relevant art. The executable code is loaded into the main memory <b>10</b> of the remote host processing unit <b>100</b> by Autorun bootstrap module <b>115</b> and provides the necessary extensions, files, hooks and/or libraries in order to utilize the remaining functions associated with the PEPS <b>160</b>.
0087In an embodiment, the majority of the processing is performed by the processor <b>5</b> associated with remote host processing unit <b>100</b>A. Additional processing may be performed by the internal processor <b>105</b> for certain cryptographic and other functions. In an optional embodiment, the PEPS <b>160</b> may include a GPS unit <b>120</b> which provides geographical coordinates useful for determining a trusted location and/or host processing unit <b>100</b>.
0088A communications interface <b>155</b> is operatively coupled to the communications infrastructure <b>190</b> to allow the various modules and subsystems associated with the PEPS <b>160</b> to communicate with the host processing unit <b>100</b>.
0089In an embodiment, the PEPS <b>160</b> is intended to be compliant with the U3 platform specifications for a smart device. Information regarding the hardware and software specifications may be downloaded from www.u3.com. The U3 platform provides a uniform programmatic architecture for smart drive computing. The U3 platform enables hardware manufacturers and software developers to create U3 smart products which are compatible with all U3 applications. Software which is compliant with the U3 platform specification allows for the mobile applications and personal workspace portability as described in the various embodiments herein. The U3 platform specification is herein incorporated by reference. One skilled in the art will appreciate that other arrangements may be used in conjunction with or in lieu of the U3 platform.
0090In an embodiment, either the processor <b>5</b> associated with the host processing unit <b>100</b> and/or the processor <b>105</b> associated with the PEPS <b>160</b> may execute the necessary applications as described herein.
0091Lastly, each PEPS <b>160</b> is encoded with a unique identification code ID <b>165</b> which in an embodiment may be burned into an internal EEPROM associated with the PEPS <b>160</b> during manufacturing. In an alternate embodiment, the unique identification code ID <b>165</b> may be installed as a permanent file. The unique identifier <b>165</b> which is used to associate a particular PEPS <b>160</b> with an assigned user and/or an authorized entity.
0092<figref idref="DRAWINGS">FIG. 2</figref> depicts an exemplary detailed block diagram of various exemplary characteristics used to determine a relative trusted state of the host processing unit <b>100</b>. When the portable endpoint security device <b>160</b> is operationally coupled to the host processing unit <b>100</b>, the Autorun bootstrap module <b>115</b> causes the host processing unit <b>100</b> to detect and access the PEPS <b>160</b> to operatively load the necessary executable code, into the main memory <b>10</b> of the remote host processing unit <b>100</b>. The operatively loaded executable code is hereinafter referred to as a reconnoitering application <b>305</b> (<figref idref="DRAWINGS">FIG. 3</figref>.) In a Windows embodiment, loading of the various applications may be performed using an .MSI file, simulated CD ROM bootstrap or third party installation application.
0093The reconnoitering application <b>305</b> is programmed to determine the relative trusted state of the host processing unit based on reconnoitered information related to the five broad categories of hardware configuration <b>205</b>, location information <b>210</b>, executable code information <b>215</b>, security information <b>220</b> and application information <b>225</b>. The hardware configuration information <b>205</b> includes a TPM <b>70</b> or (equivalent smartcard or GSM chip, the hardware devices coupled to the communications infrastructure <b>90</b>, expected processor <b>5</b> information (type, speed, manufacturer,) available main memory <b>10</b>, hard drive <b>35</b> information (type, speed, capacity, manufacturer) and related components and expected device peripherals which may be used to determine the relative level of trust of the host processing unit <b>100</b> based on preestablished policy information. Much of the reconnoitered information may be obtained by receiving information from tools and related applications included with the operating system.
0094For example, in Microsoft Windows XP™ there are a variety of tools available for example; taskmanager.exe; msconfig.exe; msinfo32.exe; which when queried, will provide some or all of the information necessary to determine the relative trusted state of the host processing unit <b>100</b>. Additional information concerning these and other system tools is available at www.microsoft.com (e.g., Windows XP Resource Kit.)
0095The location information <b>210</b> includes IP address range, media access control (MAC) address, domain name, established virtual private network (VPN.) The executable code information <b>215</b> includes executing processes, web services, remote procedure calls including Windows COM and DCOM objects, CORBA DSOM objects, Java applets (remote method invocations) and executing programs. The security information <b>220</b> includes user and system credentials, browser cookies, cryptographic keys, digital certificates, checksum values, cyclic redundancy check values, digital signatures, hashes and one or more unique identifiers associated with the host processing unit <b>100</b>, user or entity or enterprise.
0096The application information <b>225</b> includes a footprint such as a checksum, hash or digital signature, size, and/or version of the operating system, installed programs, file attributes, file extensions, program associations, and objects. Alternately, or in conjunction with the footprint information, an inventory of the installed programs may be used as well. Entries in the operating system's registry may be used to determine which programs, processes, services, applications and/or objects are functionally installed on the host processing unit <b>100</b>. The hardware configuration <b>205</b>, executable code information <b>215</b>, security information <b>220</b> and application information <b>225</b> are considered context dependent <b>230</b>. For purposes of this specification, the term “context dependent,” is defined as; of, or pertaining to one or more characteristics of a process, object, function, application or data set whose meaning is dependent on the surrounding environment.
0097<figref idref="DRAWINGS">FIG. 3</figref> depicts an exemplary detailed block diagram of the various program modules of the PEPS <b>160</b> which may be functionally controlled by the information reconnoitered from the host processing unit <b>100</b> by the reconnoitering application <b>305</b>. As previously discussed, the Autorun bootstrap <b>115</b> loads the reconnoitering application <b>305</b> into the memory <b>10</b> of the host processing unit <b>100</b>. In an embodiment, the reconnoitering application <b>305</b> determines which of the trusted state criteria to use (i.e., location information <b>205</b>, executing code information <b>210</b>, security information <b>215</b>, and/or application information <b>220</b>) to determine the relative trusted state of the host processing unit <b>100</b> based on information prescribed in the trust enforcement policy <b>315</b>.
0098One skilled in the art will appreciate that references to the reconnoitering application <b>305</b> may be made in both singular and plural form. No limitation is intended by such grammatical usage as one skilled in the art will appreciate that multiple programs, objects, subprograms, routines, algorithms, applets, processes, services, etc. may be implemented programmatically to implement the various embodiments described herein.
0099In an embodiment, one or more trust enforcement policies <b>315</b> may be used to prescribe functional control over how the PEPS <b>160</b> interacts with the host processing unit <b>100</b> under a wide variety of operating conditions. For example, a highly trusted host processing unit <b>100</b> may perform almost all the functions of the PEPS <b>160</b> while a host processing unit <b>100</b> having limited or indeterminable trust levels may be limited by the trust enforcement policy <b>315</b> to many functions being performed within the PEPS <b>160</b>, if at all. The trust enforcement policy <b>315</b> may also provide a mechanism in which secure document and/or application distribution may be accomplished in dependence on the level of trust reconnoitered by the reconnoitering application <b>305</b>.
0100In another example, the trust enforcement policy <b>315</b> may prescribe that certain of the more common user applications, such as a word processing application, may be suspect based on variations in the word processing applications' predefined file size and the actual file size reconnoitered from the host processing unit <b>100</b>. The policy may provide for the downloading of a limited version of the word processing program over the network <b>85</b> from a network resource <b>85</b>′ which is then used as an alternative to the suspect local version existing on the host processing unit <b>100</b>. If an external browser is likewise suspect, the trust enforcement <b>315</b> policy may limit the user to performing offline transactions with a cached website which is then resynchronized with the actual website when a location having a higher trust is established with the PEPS <b>160</b>.
0101In an embodiment, the trust enforcement policy <b>315</b> contains pre-determined trust criteria, as examples, trusted domain names, IP address and IP address ranges and/or unique identifiers which are identified by the reconnoitering application <b>305</b> and used to determine the relative trusted state of the host processing unit <b>100</b>. The domain name is intended to include Internet and non-Internet domain names.
0102In another embodiment, the trust enforcement policy <b>315</b> contains host processing unit configuration information which requires a more intensive and dynamic examination to determine the relative trusted state of the host processing unit <b>100</b>. For example, the trust enforcement policy <b>315</b> may require the reconnoitering application <b>305</b> to determine if the host processing unit <b>100</b> has active malware protection, whether the malware protection is up to date and/or whether a firewall is present. The trust enforcement policy <b>315</b> may also include Boolean logical operators to combine the various dynamic trust state criteria. One skilled in the art will appreciate that both the predefined and dynamic characteristics associated with the host processing unit <b>100</b> may be used to determine the relative trusted state of the host processing unit <b>100</b>.
0103In an embodiment, once the reconnoitering application <b>305</b> has determined a relative trusted state of the host processing unit <b>100</b>, the trust enforcement policy <b>315</b> may dispense with certain generally required user and/or PEPS <b>160</b> transactions for ease of use, improved system performance without degrading a required level of security. The changes to the generally required user and/or PEPS <b>160</b> transactions may have a tiered structure which requires certain transactions while dispensing with other transactions having minimal or no beneficial effect.
0104The exerted functional control enforced by the trust enforcement policy <b>315</b> includes a malware scan <b>320</b>, which is generally required for all transactions involving the PEPS <b>160</b>; user authentication <b>325</b>, likewise generally required for all transactions involving the PEPS <b>160</b>; secure storage <b>330</b>, access to secure storage is dependent on user authentication and may be further dependent on other policies <b>350</b>; auditing and tracking <b>335</b>, is generally required for all transactions involving the PEPS <b>160</b>; document distribution <b>340</b>, access to document distribution resources is dependent on user authentication and may further be dependent on other policies <b>350</b>; secure application distribution <b>345</b>, likewise, secure application distribution resources is dependent on user authentication and may further be dependent on other policies <b>350</b> contained within the PEPS <b>160</b>.
0105In an embodiment, the PEPS <b>160</b> may be provided with multiple sets of trust enforcement policies; where each trust enforcement policy is associated with a location and/or context dependent characteristic which is reconnoitered from the host processing unit <b>100</b>. For example, the reconnoitering application <b>305</b> may determine that a particular trusted application is present on the host processing unit <b>100</b> by the presence of a particular registry key entry. Alternately, or in conjunction therewith, the reconnoitering application <b>305</b> may determine that a malware process is executing which requires that the malware be removed or quarantined before allowing further transactions with the PEPS <b>160</b>. In a related embodiment, the user may be alerted to the presence of the malware, for example, by a color coded graphic (e.g., green—no malware detected, yellow—malware detected but not a critical threat or red—critical threat malware detected.) Some examples of a trust dependent functional control arrangement are provided in Table 1 below.
0000<tables id="TABLE-US-00001" num="00001"><table frame="none" colsep="0" rowsep="0" pgwide="1"><tgroup align="left" colsep="0" rowsep="0" cols="1"><colspec colname="1" colwidth="287pt" align="center" /><thead><row><entry namest="1" nameend="1" rowsep="1">TABLE 1</entry></row></thead><tbody valign="top"><row><entry namest="1" nameend="1" align="center" rowsep="1" /></row><row><entry>EXEMPLARY TRUST DEPENDENT FUNCTIONAL CONTROL</entry></row></tbody></tgroup><tgroup align="left" colsep="0" rowsep="0" cols="2"><colspec colname="1" colwidth="112pt" align="left" /><colspec colname="2" colwidth="175pt" align="left" /><tbody valign="top"><row><entry>POLICY CRITERIA</entry><entry>FUNCTIONAL CONTROL</entry></row><row><entry namest="1" nameend="2" align="center" rowsep="1" /></row><row><entry>Active Anti-Malware app. Detected</entry><entry>Bypass malware scan</entry></row><row><entry>Recent malware scan verified</entry><entry>Bypass malware scan</entry></row><row><entry>Trusted domain name detected</entry><entry>Bypass user authentication</entry></row><row><entry>Trusted IP range detected</entry><entry>Bypass user authentication</entry></row><row><entry>Trusted unique ID</entry><entry>Bypass all internal functions unless required by policy(ies)</entry></row><row><entry>GPS coordinates verified</entry><entry>Bypass user authentication</entry></row><row><entry>Digital certificate verified</entry><entry>Bypass user authentication</entry></row><row><entry>Verified cryptographic key</entry><entry>Bypass user authentication</entry></row><row><entry>OS Footprint verified</entry><entry>Use host applications; download application</entry></row><row><entry /><entry>associated with file extension if necessary</entry></row><row><entry>Trusted apps verified</entry><entry>Use host applications; allow secure</entry></row><row><entry /><entry>application distribution.</entry></row><row><entry>Trusted Platform Module detected</entry><entry>Bypass all internal functions unless required by policy(ies)</entry></row><row><entry>Trusted VPN detected</entry><entry>Use detected VPN</entry></row><row><entry>Trusted executing processes</entry><entry>Allow secure apps/document distribution</entry></row><row><entry>Limited or no Trust</entry><entry>Disallow viewing of information in the</entry></row><row><entry /><entry>PEPS vault or secure memory.</entry></row><row><entry>Limited or no Trust</entry><entry>Disallow addition of information to the</entry></row><row><entry /><entry>PEPS vault or secure memory.</entry></row><row><entry>Limited or no Trust</entry><entry>Disallow file exchanges with a central</entry></row><row><entry /><entry>management server.</entry></row><row><entry>Limited or no Trust</entry><entry>Use internal cache of</entry></row><row><entry /><entry>authentication passwords.</entry></row><row><entry>Limited or no Trust</entry><entry>Use internal PEPS applications or remote client only.</entry></row><row><entry namest="1" nameend="2" align="center" rowsep="1" /></row></tbody></tgroup></table></tables>
0106In an exemplary implementation, the generally required malware scan <b>320</b> may be bypassed if the reconnoitering application <b>305</b> detects the presence of an anti-malware application installed on the host processing unit <b>100</b>. The detection process may be based on a pre-determined or known anti-malware application (e.g., Norton Anti-Virus™), a detected executing anti-malware process, or the presence of a recent malware scan log. The executing process may be determined, for example, in a Microsoft Windows XP environment using the taskmanager.exe or msinfo32.exe applications. Similar information is available from resources provided in Linux™, Unix™ and Apple™ operating systems.
0107In another exemplary implementation, user authentication <b>325</b> may be bypassed if an automatically verified digital certificate is located on the host processing unit <b>100</b> and PEPS <b>160</b>. In this implementation, the presence of a digital certificate provides sufficient information to assume the user associated with the PEPS <b>160</b> is the same user identified by the digital certificate.
0108In an embodiment, either the processor <b>5</b> associated with the host processing unit <b>100</b> and/or the processor <b>105</b> associated with the PEPS <b>160</b> may execute the necessary applications as described herein.
0109In a final exemplary implementation, all internal functions of the PEPS <b>160</b> may be bypassed if a trusted and verified unique identifier has been located by the reconnoitering application <b>305</b>. In this exemplary embodiment, the verified unique identifier provides sufficient indicia that the host processing unit <b>100</b> is a trusted platform (e.g., the users own workstation) which allows all functions normally performed by the PEPS <b>160</b> to be performed by the host processing unit <b>100</b>.
0110In an embodiment, a policy manager application <b>310</b> provides the actual trust enforcement policy <b>315</b> within the PEPS <b>160</b> based on information reconnoitered by the reconnoiter application <b>305</b> executing on the host processing unit <b>100</b>. The policy manager application <b>310</b> may be a separate application, method or object associated with the reconnoitering application <b>305</b>. One skilled in the art will appreciate that one or more separate applications may be used to accomplish the trust policy enforcement as described herein. The policy manager <b>310</b> ensures that all transactions (both internal and external) are performed in accordance with the trust enforcement policy <b>315</b>. For example installing a new internal application within the PEPS <b>160</b> may require that a proper digital signature accompany the new internal application prior to allowing its installation.
0111<figref idref="DRAWINGS">FIG. 4</figref> depicts an exemplary flow chart of a process for determining the relative trusted state of the host processing unit and the relationship of the various context dependent characteristics for administering functional control over the PEPS <b>160</b>. The process is initiated <b>400</b> by providing a trust enforcement policy <b>405</b> accessible by the PEPS <b>160</b>. The trust enforcement policy <b>405</b> may, for example, be in the form of an XML file, binary file, text file, database file, dynamic linked library file or an object file. The trust enforcement policy <b>405</b> may include location dependent information and/or context dependent information <b>410</b>.
0112The process continues by providing a reconnoitering application which is executable by a processor <b>415</b>. The processor may be the optional processor <b>105</b> provided for the PEPS <b>160</b> or the processor <b>5</b> installed of the host processing unit <b>415</b>, or both processors.
0113In an embodiment, the reconnoitering application <b>305</b> is automatically executed to simplify user interactions and automate determinations of the relative trusted state of the host processing unit <b>100</b>. The reconnoitering application <b>305</b> accesses one or more trust dependent characteristics associated with the host processing unit <b>420</b>. The trust dependent characteristics include location dependent characteristics, for example information obtained from a network protocol stack or context dependent characteristics, potential security threats, for example the presence of a malevolent tracking cookie. In another embodiment, the trust dependent characteristics may be dependent on logical and/or physical configurations associated with the host processing unit <b>410</b>.
0114The reconnoitering application reconnoiters the host processing unit <b>100</b> in order to obtain the characteristics representative of its relative trusted state. The reconnoitering process may utilize predefined trust dependent characteristics, dynamically determined characteristics or a combination of both predefined and dynamically determined characteristics <b>420</b> based at least in part on information available from the trust enforcement policy <b>405</b>.
0115Once the reconnoitering application <b>415</b> has obtained the trust dependent characteristics prescribed by the trust enforcement policy, a determination is then made as to the relative trusted state of the host processing unit <b>425</b>. The reconnoitering application determines the relative trusted state of the host processing unit <b>425</b> from one or more trust determinate characteristics; as non exclusive examples, IP address or IP address range, MAC address, GPS coordinates, domain name, operating system footprint, an existing object, an existing trusted application, verification indicia (digital certificate, cryptographic key, digital credential, cryptogram, hash, checksum value, cyclic redundancy check value, digital signature, unique identifiers, etc.), registry entry(ies), a browser cookie(s), processes, modules and service, Windows DCOM or COM objects, DSOM objects, detected security policy (e.g., browser and/or operating system security settings, firewall setting, anti-malware applications installed, currently updated operating system version), hardware configuration (e.g., expected TPM <b>70</b> present, expected device peripherals installed, expected main memory size found, expected processor installed, etc.) or Java applet <b>410</b>.
0116Once the relative trusted state of the host processing unit has been determined, administration of the trust dependent functional control over the PEPS <b>160</b> may be accomplished <b>430</b>. The administered trust dependent functional control includes as non-exclusive examples, access to internal secure storage (i.e., vault), documents and/or internal applications; information transfer or exchange between the host processing unit and/or a network resource and the PEPS <b>160</b>; malware detection, graphical display and removal; offline access and usage of temporarily and internally cached information and applications; distribution of trusted internal applications and documents from the PEPS <b>160</b> and/or from a network resource; change management of applications and documents distributed from the PEPS; internal data manipulation; PEPS application, data, policies and binary updates; required user interactions; user level(s) of access to the PEPS <b>160</b>, authentication; usage of host processing unit applications, remote client invocations, PEPS <b>160</b> internal application execution, secure application downloading, and internal audit tracking <b>435</b>. Processing continues until the user terminates the session with a host processing unit thus ending the process <b>440</b>. The level of trust afforded by the determined relative trusted state of the host processing unit is scalable from no trust to complete trust <b>445</b>.
0117Referring to <figref idref="DRAWINGS">FIG. 5</figref>, another exemplary flow chart of a process is depicted. This exemplary process provides a mechanism for determining when and upon which device (PEPS <b>160</b> or local host processing unit <b>100</b>) an application will be executed from in dependence on the relative trusted state afforded by the host processing unit <b>100</b>. The process is initiated <b>500</b> by the reconnoitering application determining whether the host is capable of using a file maintained by the PEPS <b>505</b>.
0118This may be accomplished by the reconnoitering application <b>305</b> determining if an existing file/application association is present in a registry associated with the operating system installed on the host processing unit <b>100</b>. For example, Microsoft Windows™ maintains file extensions, associated applications and object link embedding (OLE) which utilize the format associated with the file extensions in registry entries found under HKEY_ROOT_CLASSES. In a specific example, a file such as MyInfo.TXT when selected will almost universally trigger execution of a text editing program to execute which loads the file MyInfo.TXT into the text editing program.
0119Other techniques may used to determine the presence of a needed application on the host processing unit <b>100</b> for example, searching for the actual application and/or locating a digital certificated associated therewith.
0120If the needed application is determined to be available on or through (via a remote client application) <b>535</b> the host processing unit, the PEPS <b>160</b> verifies that the host processing unit <b>100</b> has a sufficient level of trust to allow access to the file(s) securely maintained by the PEPS <b>515</b>. If a sufficient level of trust has been verified, the user is allowed to run the needed application directly from the host processing unit <b>520</b>. When usage of the application on the host processing unit is no longer needed, access to the file maintained by the PEPS <b>160</b> ends in accordance with (IAW) a secure application usage policy <b>560</b>.
0121However, in many cases, the PEPS <b>160</b> may contain a file having a file extension unknown to the operating system installed on the host processing unit <b>510</b> or alternatively, if the host processing unit <b>100</b> does not have the required level of trust <b>515</b>, the PEPS <b>160</b> then determines if the needed application is available internally <b>525</b>. If the needed application is available internally or available using a remote client (e.g., Citrix™) <b>535</b>, the needed application is then run from the PEPS <b>530</b>. If the needed application is not available <b>525</b>, the needed application is then downloaded to the PEPS <b>160</b> in accordance with (IAW) <b>540</b> the secure application distribution policy <b>345</b>.
0122After execution of the needed application from the PEPS <b>160</b>, a check is made to determine if one or more constraints have been met or limits exceeded <b>545</b>. For example, the secure application distribution policy <b>345</b> may limit the usage of the needed application to a single usage or upon completion of a single remote client session, a defined period of time; after which, the secure application distribution policy <b>345</b> may require that the session be terminated <b>555</b>.
0123Alternately, if the needed application is actually downloaded locally, exceeding the usage limit may require that the downloaded application be deleted from the PEPS <b>550</b>. Other policy considerations may require session termination and/or needed application deletion if degradation in the level of trust is detected between the host processing unit and the PEPS <b>550</b>. The process completes after the downloaded application is deleted and/or a remote client session has been terminated <b>560</b>.
0124Various embodiments have been described in detail with reference to exemplary configurations and processes. It should be appreciated that the specific embodiments described are merely illustrative of the principles underlying the inventive concepts. It is therefore contemplated that various modifications of the disclosed embodiments will, without departing from the spirit and scope of the various embodiments, be apparent to persons of ordinary skill in the art. As such, the foregoing described inventive embodiments are provided as exemplary illustrations and descriptions. They are not intended to limit the various embodiments to any precise form described. In particular, it is contemplated that functional implementation of the inventive embodiments described herein may be implemented equivalently in hardware, software, firmware, and/or other available functional components or building blocks.
0125No specific limitation is intended to a particular arrangement or process sequence. Other variations and embodiments are possible in light of above teachings, and it is not intended that this Detailed Description limit the scope of inventive embodiments, but rather by the Claims following herein.
Contents6
7 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US2009327678A1 | Cited by | United States of America | Pre-grant |
| US12192170B2 | Cited by | United States of America | Applicant |
| US8997174B1 | Cited by | United States of America | Applicant |
| US2015058619A1 | Cited by | United States of America | Pre-grant |
| US9213805B2 | Cited by | United States of America | Applicant |
| US10904293B2 | Cited by | United States of America | Applicant |
| US2016255506A1 | Cited by | United States of America | Pre-grant |
| US8552833B2 | Cited by | United States of America | Applicant |
| US10567403B2 | Cited by | United States of America | Applicant |
| US9497224B2 | Cited by | United States of America | Search report |
| US10089462B2 | Cited by | United States of America | Applicant |
| US9730066B2 | Cited by | United States of America | Search report |
| EP2492836A4 | Cited by | European Patent Office (EPO) | Search report |
| US10313368B2 | Cited by | United States of America | Applicant |
| US11038876B2 | Cited by | United States of America | Applicant |
| US8417941B2 | Cited by | United States of America | Search report |
| US2014317721A1 | Cited by | United States of America | Pre-grant |
| US8843997B1 | Cited by | United States of America | Search report |
| US11775644B2 | Cited by | United States of America | Applicant |
| US8365272B2 | Cited by | United States of America | Applicant |
| US11829467B2 | Cited by | United States of America | Applicant |
| US2015169877A1 | Cited by | United States of America | Pre-grant |
| US9420005B1 | Cited by | United States of America | Applicant |
| US2009307452A1 | Cited by | United States of America | Pre-grant |
| US10417421B2 | Cited by | United States of America | Applicant |
| US9767285B2 | Cited by | United States of America | Search report |
| US2009094679A1 | Cited by | United States of America | Pre-grant |
| US10540494B2 | Cited by | United States of America | Applicant |
| US2007199060A1 | Cited by | United States of America | Pre-grant |
| US8869270B2 | Cited by | United States of America | Search report |
| US2010023782A1 | Cited by | United States of America | Pre-grant |
| US2009055876A1 | Cited by | United States of America | Pre-grant |
| US10666688B2 | Cited by | United States of America | Applicant |
| US11050712B2 | Cited by | United States of America | Applicant |
| US11449613B2 | Cited by | United States of America | Applicant |
| US8701157B1 | Cited by | United States of America | Applicant |
| EP2457192A4 | Cited by | European Patent Office (EPO) | Search report |
| US10601807B2 | Cited by | United States of America | Applicant |
| US9165289B2 | Cited by | United States of America | Applicant |
| US9973501B2 | Cited by | United States of America | Applicant |
| US9306954B2 | Cited by | United States of America | Applicant |
| US8732792B2 | Cited by | United States of America | Applicant |
| US9106683B2 | Cited by | United States of America | Applicant |
| US9749712B2 | Cited by | United States of America | Search report |
| CN102687159A | Cited by | China | Search report |
| US9781164B2 | Cited by | United States of America | Applicant |
| US12301574B2 | Cited by | United States of America | Applicant |
| US10084799B2 | Cited by | United States of America | Applicant |
| US9996689B2 | Cited by | United States of America | Search report |
| US9843595B2 | Cited by | United States of America | Applicant |
| US9497622B2 | Cited by | United States of America | Applicant |
| US9087188B2 | Cited by | United States of America | Search report |
| US11757835B2 | Cited by | United States of America | Applicant |
| US2023376571A1 | Cited by | United States of America | Search report |
| US8332907B2 | Cited by | United States of America | Search report |
| US2008209564A1 | Cited by | United States of America | Pre-grant |
| US2011154021A1 | Cited by | United States of America | Pre-grant |
| US11157976B2 | Cited by | United States of America | Applicant |
| US8484736B2 | Cited by | United States of America | Search report |
| US10417400B2 | Cited by | United States of America | Applicant |
| US10540510B2 | Cited by | United States of America | Applicant |
| US11604861B2 | Cited by | United States of America | Applicant |
| US8631488B2 | Cited by | United States of America | Applicant |
| US2016357964A1 | Cited by | United States of America | Pre-grant |
| US2010212012A1 | Cited by | United States of America | Pre-grant |
| US8689334B2 | Cited by | United States of America | Search report |
| US11259183B2 | Cited by | United States of America | Applicant |
| US10404722B2 | Cited by | United States of America | Applicant |
| US8789202B2 | Cited by | United States of America | Applicant |
| US10951659B2 | Cited by | United States of America | Applicant |
| US10839075B2 | Cited by | United States of America | Applicant |
| US12314396B2 | Cited by | United States of America | Applicant |
| US11757941B2 | Cited by | United States of America | Applicant |
| US8381297B2 | Cited by | United States of America | Applicant |
| US9152789B2 | Cited by | United States of America | Search report |
| US2009307380A1 | Cited by | United States of America | Pre-grant |
| US8239917B2 | Cited by | United States of America | Search report |
| US10904254B2 | Cited by | United States of America | Applicant |
| US10256979B2 | Cited by | United States of America | Applicant |
| US10284603B2 | Cited by | United States of America | Applicant |
| US10397227B2 | Cited by | United States of America | Applicant |
| US9208118B2 | Cited by | United States of America | Search report |
| US12120519B2 | Cited by | United States of America | Applicant |
| US11757885B2 | Cited by | United States of America | Applicant |
| US8364598B2 | Cited by | United States of America | Search report |
| US9516040B2 | Cited by | United States of America | Applicant |
| US9774446B1 | Cited by | United States of America | Search report |
| US10999302B2 | Cited by | United States of America | Applicant |
| US10291656B2 | Cited by | United States of America | Applicant |
| US12380476B2 | Cited by | United States of America | Applicant |
| US2016127906A9 | Cited by | United States of America | Pre-grant |
| US2010037321A1 | Cited by | United States of America | Pre-grant |
| US11036836B2 | Cited by | United States of America | Applicant |
| US7917741B2 | Cited by | United States of America | Search report |
| US2008307488A1 | Cited by | United States of America | Pre-grant |
| US10621344B2 | Cited by | United States of America | Applicant |
| US2011088025A1 | Cited by | United States of America | Pre-grant |
| US2011107423A1 | Cited by | United States of America | Pre-grant |
| US11743297B2 | Cited by | United States of America | Applicant |
| US10152598B2 | Cited by | United States of America | Applicant |
1 member in 1 office; this record represents the family
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 55145106 | United States of America | A | |
| US20060551451 | – | – | – |
Members1
| Document | Office | Kind | |
|---|---|---|---|
| US2008098478A1 | United States of America | A1 |
46 transactions on the USPTO file
Abandoned after 1 non-final rejection and 1 final rejection.
- Non-final rejections
- 1
- Final rejections
- 1
- RCEs
- 0
- Appeals
- 0
Over time
Point at a mark for the transactionTransactions
| Event | Code | |
|---|---|---|
| Miscellaneous Incoming LetterLET. | LET. | |
| Mail Abandonment for Failure to Respond to Office ActionAbandonedMABN2 | MABN2 | |
| Examiner Interview Summary Record (PTOL - 413)EXIN | EXIN | |
| Aband. for Failure to Respond to O. A.AbandonedABN2 | ABN2 | |
| Mail Final Rejection (PTOL - 326)Final rejectionMCTFR | MCTFR | |
| Final RejectionFinal rejectionCTFR | CTFR | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Response after Non-Final ActionA... | A... | |
| Request for Extension of Time - GrantedXT/G | XT/G | |
| Mail Non-Final RejectionNon-final rejectionMCTNF | MCTNF | |
| Non-Final RejectionNon-final rejectionCTNF | CTNF | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Electronic Information Disclosure StatementEIDS. | EIDS. | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Correspondence Address ChangeC.AD | C.AD | |
| PG-Pub Issue NotificationPG-ISSUE | PG-ISSUE | |
| Mail-Petition Decision - GrantedMP033 | MP033 | |
| Petition Decision - GrantedP033 | P033 | |
| Change in Power of Attorney (May Include Associate POA)PA.. | PA.. | |
| Correspondence Address ChangeC.AD | C.AD | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Withdraw Flagged for 5/25W525 | W525 | |
| Flagged for 5/25F525 | F525 | |
| Petition EnteredPET. | PET. | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Application Return from OIPEWROIPE | WROIPE | |
| Application Return TO OIPEROIPE | ROIPE | |
| IFW TSS Processing by Tech Center CompleteTSSCOMP | TSSCOMP | |
| Application Return from OIPEWROIPE | WROIPE | |
| Application Return TO OIPEROIPE | ROIPE | |
| Application Return from OIPEWROIPE | WROIPE | |
| Application Return TO OIPEROIPE | ROIPE | |
| Application Dispatched from OIPEOIPE | OIPE | |
| Application Is Now CompleteCOMP | COMP | |
| Additional Application Filing FeesADDFLFEE | ADDFLFEE | |
| A statement by one or more inventors satisfying the requirement under 35 USC 115, Oath of the ApplicOATHDECL | OATHDECL | |
| Notice Mailed--Application Incomplete--Filing Date AssignedINCD | INCD | |
| Cleared by OIPE CSRL194 | L194 | |
| IFW Scan & PACR Auto Security ReviewSCAN | SCAN | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Electronic Information Disclosure StatementEIDS. | EIDS. | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Initial Exam Team nnIEXX | IEXX |
3 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Information on status: application discontinuationABANDONED -- FAILURE TO RESPOND TO AN OFFICE ACTIONSTCB | STCB | |
| Information on status: application discontinuationABANDONED -- FAILURE TO RESPOND TO AN OFFICE ACTIONSTCB | STCB | |
| AssignmentAS | AS |
Numbers
- Publication
- 20080098478
- Publication, DOCDB
- 2008098478
- Publication, EPODOC
- US2008098478
- Application
- 11551451
- Application, DOCDB
- 55145106
- Application, EPODOC
- US20060551451
Titles
- English
- System, Method and Computer Program Product for Administering Trust Dependent Functional Control over a Portable Endpoint Security Device
Classification
- CPC, 4
- G06F21/34
- G06F21/57
- G06F21/70
- G06F2221/2111
- IPC, 6
- G06F12 14
- H04L9 00
- G06F11 00
- G06F12 16
- G06F15 18
- G08B23 00
- USPC, 3
- 726024000
- 713173000
- 713176000