US2017134390A1PendingUtilityA1

Techniques for data monitoring to mitigate transitive problem in object-oriented contexts

Assignee: QUALCOMM INCPriority: Jun 11, 2015Filed: Jan 13, 2017Published: May 11, 2017
Est. expiryJun 11, 2035(~8.9 yrs left)· nominal 20-yr term from priority
G06F 21/64G06F 2221/2101G06F 21/6218H04L 63/105H04L 63/0823G06F 21/6245G06F 21/604
46
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Techniques for mitigating the transitive data problem using a secure asset manager are provided. These techniques include generating a secure asset manager compliant application by tagging source code for the application with a data tag to indicate that a data element associated with the source code is a sensitive data element, accessing a policy file comprising transitive rules associated with the sensitive data element, and generating one or more object files for the application from the source code. These techniques also include storing a sensitive data element in a secure memory region managed by a secure asset manager, and managing the sensitive data element according to a policy associated with the sensitive data element by an application from which the sensitive data element originates, the policy defining transitive rules associated with the sensitive data element.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method for generating a secure asset manager compliant application, the method comprising:
 tagging source code for the secure asset manager compliant application with a data tag to indicate that a data element associated with the source code is a sensitive data element;   accessing a policy file comprising transitive rules associated with the sensitive data element; and   generating one or more object files for the secure asset manager compliant application from the source code.   
     
     
         2 . The method of  claim 1 , further comprising signing the one or more object files with a security certificate indicating that the one or more object files has been generated by a trusted provider. 
     
     
         3 . The method of  claim 1 , wherein the data tag comprises a unique identifier that identifies which policy must be applied by a secure asset manager to the sensitive data element and any data elements derived therefrom at runtime of the secure asset manager compliant application. 
     
     
         4 . The method of  claim 1 , wherein generating the one or more object files for the secure asset manager compliant application comprises compiling the source code with a secure asset manager compliant compiler that is configured to recognize the data tag and to generate a sensitive data object type for managing instances of the sensitive data element. 
     
     
         5 . The method of  claim 1 , further comprising linking the one or more object files with at least one other object file or library to create an executable file for a target device that implements a secure asset manager. 
     
     
         6 . The method of  claim 1 , wherein the transitive rules associated with the sensitive data element identify a set of trusted applications that are allowed to access and perform one or more operations on the sensitive data element. 
     
     
         7 . The method of  claim 6 , wherein the transitive rules associated with the sensitive data element identify which applications may derive data from the sensitive data element. 
     
     
         8 . An apparatus, the apparatus comprising:
 a memory; and   a processor communicatively coupled to the memory, the processor configured to:
 tag source code stored for a secure asset manager compliant application stored in the memory with a data tag to indicate that a data element associated with the source code is a sensitive data element; 
 access a policy file comprising transitive rules associated with the sensitive data element; and 
 generate one or more object files for the secure asset manager compliant application from the source code in the memory. 
   
     
     
         9 . The apparatus of  claim 8 , wherein the processor is configured to sign the one or more object files with a security certificate indicating that the one or more object files have been generated by a trusted provider. 
     
     
         10 . The apparatus of  claim 8 , wherein the data tag comprises a unique identifier that identifies which policy must be applied by a secure asset manager to the sensitive data element associated with the data tag at runtime of the secure asset manager compliant application. 
     
     
         11 . The apparatus of  claim 8 , wherein the processor configured to generate the one or more object files for the secure asset manager compliant application is further configured to compile the source code with a secure asset manager compliant compiler that is configured to recognize the data tag and to generate a sensitive data object type for managing instances of the sensitive data element. 
     
     
         12 . The apparatus of  claim 8 , wherein the processor is further configured to link the one or more object files with at least one other object file or library to create an executable file for a target device that implements a secure asset manager. 
     
     
         13 . The apparatus of  claim 8 , wherein the transitive rules associated with the sensitive data element identify a set of trusted applications that are allowed to access and perform one or more operations on the sensitive data element. 
     
     
         14 . The apparatus of  claim 13 , wherein the transitive rules associated with the sensitive data element identify which applications may derive data from the sensitive data element. 
     
     
         15 . An apparatus, the apparatus comprising:
 means for tagging source code for a secure asset manager compliant application with a data tag to indicate that a data element associated with the source code is a sensitive data element;   means for accessing a policy file comprising transitive rules associated with the sensitive data element; and   means for generating one or more object files for the secure asset manager compliant application from the source code.   
     
     
         16 . The apparatus of  claim 15 , further comprising means for signing the one or more object files with a security certificate indicating that the one or more object files have been generated by a trusted provider. 
     
     
         17 . The apparatus of  claim 15 , wherein the data tag comprises a unique identifier that identifies which policy must be applied by a secure asset manager to the sensitive data element associated with the data tag at runtime of the secure asset manager compliant application. 
     
     
         18 . The apparatus of  claim 15 , wherein the means for generating the one or more object files for the secure asset manager compliant application comprises means for compiling the source code with a secure asset manager compliant compiler that is configured to recognize the data tag and to generate a sensitive data object type for managing instances of the sensitive data element. 
     
     
         19 . The apparatus of  claim 15 , further comprising means for linking the one or more object files with at least one other object file or library to create an executable file for a target device that implements a secure asset manager. 
     
     
         20 . The apparatus of  claim 15 , wherein the transitive rules associated with the sensitive data element identify a set of trusted applications that are allowed to access and perform one or more operations on the sensitive data element. 
     
     
         21 . The apparatus of  claim 20 , wherein the transitive rules associated with the sensitive data element identify which applications may derive data from the sensitive data element. 
     
     
         22 . A non-transitory, computer-readable medium, having stored thereon computer-readable instructions for generating a secure asset manager compliant application, comprising instructions configured to cause a computer to:
 tag source code for the secure asset manager compliant application with a data tag to indicate that a data element associated with the source code is a sensitive data element;   access a policy file comprising transitive rules associated with the sensitive data element; and   generate one or more object files for the secure asset manager compliant application from the source code.   
     
     
         23 . The non-transitory, computer-readable medium of  claim 22 , further comprising code to cause the computer to sign the one or more object files with a security certificate indicating that the one or more object files have been generated by a trusted provider. 
     
     
         24 . The non-transitory, computer-readable medium of  claim 22 , wherein the data tag comprises a unique identifier that identifies which policy must be applied by a secure asset manager to the sensitive data element associated with the data tag at runtime of the secure asset manager compliant application. 
     
     
         25 . The non-transitory, computer-readable medium of  claim 22 , wherein the instructions to cause the computer to generate the one or more object files for the secure asset manager compliant application comprise instructions to cause the computer to compile the source code with a secure asset manager compliant compiler that is configured to recognize the data tag and to generate a sensitive data object type for managing instances of the sensitive data element. 
     
     
         26 . The non-transitory, computer-readable medium of  claim 22 , further comprising instructions to cause the computer to link the one or more object files with at least one other object file or library to create an executable file for a target device that implements a secure asset manager. 
     
     
         27 . The non-transitory, computer-readable medium of  claim 22 , wherein the transitive rules associated with the sensitive data element identify a set of trusted applications that are allowed to access and perform one or more operations on the sensitive data element. 
     
     
         28 . The non-transitory, computer-readable medium of  claim 27 , wherein the transitive rules associated with the sensitive data element identify which applications may derive data from the sensitive data element.

Join the waitlist — get patent alerts

Track US2017134390A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.