Patent · US Active

Security policy enforcement based on dynamic security context updates

US10949540B2 · kind B2 · utility

3Cited by
1References
23Claims
0Family size

Assignee

Inventors

Key dates

Filing dateMar 20, 2018
Grant dateMar 16, 2021
Priority date
Expiry dateOct 26, 2038

Classification

  • Technology area (CPC G)Physics
  • CPC primaryG06F21/64
  • WIPO fieldComputer technology
  • WIPO sectorElectrical engineering

Abstract

An information handling system (IHS) includes a memory having a BIOS, at least one sensor that generates security related data for the IHS, a controller, and one or more I/O drivers. The memory, at least one sensor and controller operate within a secure environment of the IHS; the I/O driver(s) operate outside of the secure environment. The controller includes a security policy management engine, which is executable during runtime of the IHS to continuously monitor security related data generated by the at least one sensor, determine whether the security related data violates at least one security policy rule specified for the IHS, and provide a notification of security policy violation to the BIOS, if the security related data violates at least one security policy rule. The I/O driver(s) include a security enforcement engine, which is executable to receive the notification of security policy violation from the BIOS, and perform at least one security measure in response thereto.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.