×

Access unit switching through physical mediation

  • US 8,146,138 B2
  • Filed: 12/15/2005
  • Issued: 03/27/2012
  • Est. Priority Date: 12/15/2005
  • Status: Active Grant
First Claim
Patent Images

1. A computer comprising:

  • a processor; and

    a fast trusted access unit switch module stored in a virtual machine monitor of the computer and executable on the processor configured to;

    verify identity of a user of a single account on a computing device including a fast trusted access unit switching module that enables the user to securely switch between a plurality of levels of allowable privilege and access rights;

    determine the plurality of levels of allowable privilege and access rights which afforded to the user of the single account, the plurality of levels of allowable privilege and access rights includes at least a high level and a low level;

    establish a plurality of access units on the computing device with each of the access units capable of having a plurality of levels of privilege and access rights;

    grant access to the user of the single account to interface with the access unit, via the fast trusted access unit switch module, with the low level of privilege and access rights required to interface with the access unit; and

    change the low level of privilege and access rights to the high level of privilege and access rights for the user of the single account when the user of the single account is required to interface with the access unit using the high level of privilege and access rights when the user initiates a first physical action that generates a signal that is provided to an isolation kernel via a trusted path; and

    change the high level of privilege and access right to the low level of privilege and access rights for the user of the single account when the user of the single account is not required to interface with the access unit using the high level of privilege and access rights when the user initiates a second physical action that generates a signal that is provided to the isolation kernel via the trusted path.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×