发明名称 COMPUTER DEVICE WITH ANTI-TAMPER RESOURCE SECURITY
摘要 A computer device provides an execution environment that supports a plurality of processes. A plurality of key resources are associated with a security application that may perform process elevation to grant privileged access rights to a user process. A security module controls access to the key resources using an access control list. An anti-tamper mechanism creates a protection group as a local security group and adds a deny access control entry to the access control list. The anti-tamper mechanism intercepts the user process and creates a revised access token identifying the user process as a member of the protection group. The security module matches the protection group in the revised access token of the user process against the deny access control entry in the access control list of the key resources thereby restricting access by the user process even though the user process otherwise has privileges to access those resources.
申请公布号 EP2748755(B1) 申请公布日期 2016.07.13
申请号 EP20120756243 申请日期 2012.08.31
申请人 AVECTO LIMITED 发明人 AUSTIN, MARK
分类号 G06F21/62 主分类号 G06F21/62
代理机构 代理人
主权项
地址