Techniques for data monitoring to mitigate transitive problem in object-oriented contexts
Abstract
Techniques for mitigating the transitive data problem using a secure asset manager are provided. These techniques include generating a secure asset manager compliant application by tagging source code for the application with a data tag to indicate that a data element associated with the source code is a sensitive data element, accessing a policy file comprising transitive rules associated with the sensitive data element, and generating one or more object files for the application from the source code. These techniques also include storing a sensitive data element in a secure memory region managed by a secure asset manager, and managing the sensitive data element according to a policy associated with the sensitive data element by an application from which the sensitive data element originates, the policy defining transitive rules associated with the sensitive data element.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method for generating a secure asset manager compliant application, the method comprising:
tagging source code for the secure asset manager compliant application with a data tag to indicate that a data element associated with the source code is a sensitive data element; accessing a policy file comprising transitive rules associated with the sensitive data element; and generating one or more object files for the secure asset manager compliant application from the source code.
2 . The method of claim 1 , further comprising signing the one or more object files with a security certificate indicating that the one or more object files has been generated by a trusted provider.
3 . The method of claim 1 , wherein the data tag comprises a unique identifier that identifies which policy must be applied by a secure asset manager to the sensitive data element and any data elements derived therefrom at runtime of the secure asset manager compliant application.
4 . The method of claim 1 , wherein generating the one or more object files for the secure asset manager compliant application comprises compiling the source code with a secure asset manager compliant compiler that is configured to recognize the data tag and to generate a sensitive data object type for managing instances of the sensitive data element.
5 . The method of claim 1 , further comprising linking the one or more object files with at least one other object file or library to create an executable file for a target device that implements a secure asset manager.
6 . The method of claim 1 , wherein the transitive rules associated with the sensitive data element identify a set of trusted applications that are allowed to access and perform one or more operations on the sensitive data element.
7 . The method of claim 6 , wherein the transitive rules associated with the sensitive data element identify which applications may derive data from the sensitive data element.
8 . An apparatus, the apparatus comprising:
a memory; and a processor communicatively coupled to the memory, the processor configured to:
tag source code stored for a secure asset manager compliant application stored in the memory with a data tag to indicate that a data element associated with the source code is a sensitive data element;
access a policy file comprising transitive rules associated with the sensitive data element; and
generate one or more object files for the secure asset manager compliant application from the source code in the memory.
9 . The apparatus of claim 8 , wherein the processor is configured to sign the one or more object files with a security certificate indicating that the one or more object files have been generated by a trusted provider.
10 . The apparatus of claim 8 , wherein the data tag comprises a unique identifier that identifies which policy must be applied by a secure asset manager to the sensitive data element associated with the data tag at runtime of the secure asset manager compliant application.
11 . The apparatus of claim 8 , wherein the processor configured to generate the one or more object files for the secure asset manager compliant application is further configured to compile the source code with a secure asset manager compliant compiler that is configured to recognize the data tag and to generate a sensitive data object type for managing instances of the sensitive data element.
12 . The apparatus of claim 8 , wherein the processor is further configured to link the one or more object files with at least one other object file or library to create an executable file for a target device that implements a secure asset manager.
13 . The apparatus of claim 8 , wherein the transitive rules associated with the sensitive data element identify a set of trusted applications that are allowed to access and perform one or more operations on the sensitive data element.
14 . The apparatus of claim 13 , wherein the transitive rules associated with the sensitive data element identify which applications may derive data from the sensitive data element.
15 . An apparatus, the apparatus comprising:
means for tagging source code for a secure asset manager compliant application with a data tag to indicate that a data element associated with the source code is a sensitive data element; means for accessing a policy file comprising transitive rules associated with the sensitive data element; and means for generating one or more object files for the secure asset manager compliant application from the source code.
16 . The apparatus of claim 15 , further comprising means for signing the one or more object files with a security certificate indicating that the one or more object files have been generated by a trusted provider.
17 . The apparatus of claim 15 , wherein the data tag comprises a unique identifier that identifies which policy must be applied by a secure asset manager to the sensitive data element associated with the data tag at runtime of the secure asset manager compliant application.
18 . The apparatus of claim 15 , wherein the means for generating the one or more object files for the secure asset manager compliant application comprises means for compiling the source code with a secure asset manager compliant compiler that is configured to recognize the data tag and to generate a sensitive data object type for managing instances of the sensitive data element.
19 . The apparatus of claim 15 , further comprising means for linking the one or more object files with at least one other object file or library to create an executable file for a target device that implements a secure asset manager.
20 . The apparatus of claim 15 , wherein the transitive rules associated with the sensitive data element identify a set of trusted applications that are allowed to access and perform one or more operations on the sensitive data element.
21 . The apparatus of claim 20 , wherein the transitive rules associated with the sensitive data element identify which applications may derive data from the sensitive data element.
22 . A non-transitory, computer-readable medium, having stored thereon computer-readable instructions for generating a secure asset manager compliant application, comprising instructions configured to cause a computer to:
tag source code for the secure asset manager compliant application with a data tag to indicate that a data element associated with the source code is a sensitive data element; access a policy file comprising transitive rules associated with the sensitive data element; and generate one or more object files for the secure asset manager compliant application from the source code.
23 . The non-transitory, computer-readable medium of claim 22 , further comprising code to cause the computer to sign the one or more object files with a security certificate indicating that the one or more object files have been generated by a trusted provider.
24 . The non-transitory, computer-readable medium of claim 22 , wherein the data tag comprises a unique identifier that identifies which policy must be applied by a secure asset manager to the sensitive data element associated with the data tag at runtime of the secure asset manager compliant application.
25 . The non-transitory, computer-readable medium of claim 22 , wherein the instructions to cause the computer to generate the one or more object files for the secure asset manager compliant application comprise instructions to cause the computer to compile the source code with a secure asset manager compliant compiler that is configured to recognize the data tag and to generate a sensitive data object type for managing instances of the sensitive data element.
26 . The non-transitory, computer-readable medium of claim 22 , further comprising instructions to cause the computer to link the one or more object files with at least one other object file or library to create an executable file for a target device that implements a secure asset manager.
27 . The non-transitory, computer-readable medium of claim 22 , wherein the transitive rules associated with the sensitive data element identify a set of trusted applications that are allowed to access and perform one or more operations on the sensitive data element.
28 . The non-transitory, computer-readable medium of claim 27 , wherein the transitive rules associated with the sensitive data element identify which applications may derive data from the sensitive data element.Join the waitlist — get patent alerts
Track US2017134390A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.