Kernel-based computer process protection

Verifying the digital signature of the user process through the kernel driver and controlling its access rights solves the security protection problem of the user process in kernel mode and improves the security and data integrity of the computer system.

CN120283230APending Publication Date: 2025-07-08ISLAND TECH INC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202380082389.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2022-11-30
Filing Date
2023-11-29
Publication Date
2025-07-08

AI Technical Summary

Technical Problem

The prior art is difficult to effectively protect user processes and their related resources from malicious attacks, especially in modern computer operating systems, kernel drivers in kernel mode cannot effectively verify and manage access rights and data transmission of user processes.

Method used

Configure protection policies through kernel drivers, verify the digital signature of user processes, control their access rights, and encrypt the decryption keys and messages if necessary, ensuring secure access to legitimate user processes.

Benefits of technology

It realizes effective protection of user processes, prevents unauthorized access and data leakage, and improves the security and data integrity of the computer system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120283230A_ABST
    Figure CN120283230A_ABST
Patent Text Reader

Abstract

In one embodiment, a computer security apparatus includes a kernel driver configured to be executed by a computer in kernel mode, and then execute a process to protect a first computer software application executed by the computer, where protection is performed according to a protection policy, from the process, an instruction to modify the protection policy is received, and the kernel driver is configured to execute the first computer software application in kernel mode. The protection policy is modified in accordance with the instruction and the process is protected in accordance with the protection policy after it has been modified in accordance with the instruction.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention generally relates to computer security. Background Art

[0002] Modern computer operating systems typically maintain separate "user space" and "kernel space" regions of computer memory. Kernel space is directly accessed by operating system components (whose main component is called the "kernel") and by various kernel drivers and hardware device drivers when they are executed by the computer's central processing unit (CPU) in "kernel mode". User space memory is allocated to user processes, which are instances of software applications that are not operating system components (such as web browsers and word processing software), where user processes are typically executed by the CPU in "user mode". Kernel space can be accessed indirectly by user processes only by using system calls, which are requests sent by user processes to the operating system, where such requests are for services performed by the kernel.

[0003] A common kernel task is to protect user processes and their associated resources by simply preventing other user processes from accessing them. However, as malicious parties adopt various means to compromise computer security, new computer security methods should be considered. Summary of the Invention

[0004] In one aspect of the present invention, there is provided a computer security method, which includes protecting a process of a first computer software application executed by a computer, where the protection is performed according to a protection policy, receiving an instruction to modify the protection policy from the process, modifying the protection policy according to the instruction, and protecting the process according to the protection policy after the protection policy has been modified according to the instruction, where the protection, receiving, and modification are performed by a kernel driver executed by the computer.

[0005] In another aspect of the present invention, any one of protection, receiving, and modification is performed after determining that a digital signature is valid, where the digital signature is a digital signature of an executable file of the first computer software application, and where the determination is performed by a kernel driver executed by the computer.

[0006] In another aspect of the present invention, the protection includes detecting an attempt by a process of a second computer software application executed by the computer to access an object associated with the first computer software application, determining whether a digital signature is valid, where the digital signature is a digital signature of an executable file of the second computer software application, and allowing or preventing the second computer software application from accessing the object according to a protection policy, where the protection policy is at least partially based on whether the digital signature is valid, and where the detection, determination, allowance, and prevention are performed by a kernel driver executed by the computer.

[0007] In another aspect of the present invention, protection includes receiving a decryption key from a process of a first computer software application, receiving a request for receiving the decryption key from the process of the first computer software application, determining whether a digital signature is valid, where the digital signature is the digital signature of the first computer software application, and providing or not providing the decryption key to the process according to a protection policy, where the protection policy is at least partially based on whether the digital signature is valid, and where receiving, determining, permitting, providing, and not providing are performed by a kernel driver executed by a computer.

[0008] In another aspect of the present invention, the method further includes encrypting the decryption key after receiving the decryption key from the process of the first computer software application, and decrypting the encrypted decryption key if the digital signature is valid before providing the decryption key to the process of the first computer software application.

[0009] In another aspect of the present invention, protection includes receiving an encrypted message from a process of a first computer software application, where the message is encrypted using the public key of a key pair, determining whether a digital signature is valid, where the digital signature is the digital signature of the executable file of the first computer software application, and if the digital signature is valid, decrypting the encrypted message using the private key of the key pair, encrypting a response to the message using the private key, and providing the encrypted response to the process of the first computer software application, where receiving, determining, decrypting, encrypting, and providing are performed by a kernel driver executed by a computer.

[0010] In another aspect of the present invention, a computer security device is provided, which includes a kernel driver configured to be executed by a computer in kernel mode and then execute a process of protecting a first computer software application executed by the computer, where protection is performed according to a protection policy, receiving an instruction to modify the protection policy from the process, modifying the protection policy according to the instruction, and protecting the process according to the protection policy after the protection policy has been modified according to the instruction.

[0011] In another aspect of the present invention, the kernel driver is configured to perform any one of protection, receiving, and modification after the kernel driver determines that the digital signature is valid, where the digital signature is the digital signature of the executable file of the first computer software application.

[0012] In another aspect of the present invention, the kernel driver is configured to perform protection by detecting an attempt by a process of a second computer software application executed by a computer to access an object associated with a first computer software application, determining whether a digital signature is valid, where the digital signature is the digital signature of the executable file of the second computer software application, and allowing or preventing the second computer software application from accessing the object according to a protection policy, where the protection policy is at least partially based on whether the digital signature is valid.

[0013] In another aspect of the present invention, the kernel driver is configured to perform protection by receiving a decryption key from a process of a first computer software application, receiving a request to receive the decryption key from a process of the first computer software application, determining whether a digital signature is valid, where the digital signature is the digital signature of the first computer software application, and providing or not providing the decryption key to the process according to a protection policy, where the protection policy is at least partially based on whether the digital signature is valid, and where receiving, determining, allowing, providing, and not providing are performed by the kernel driver executed by the computer.

[0014] In another aspect of the present invention, the kernel driver is configured to encrypt the decryption key after receiving the decryption key from a process of a first computer software application, and decrypt the encrypted decryption key before providing the decryption key to a process of the first computer software application if the digital signature is valid.

[0015] In another aspect of the present invention, the kernel driver is configured to perform protection by receiving an encrypted message from a process of a first computer software application, where the message is encrypted using the public key of a key pair, determining whether a digital signature is valid, where the digital signature is the digital signature of the executable file of the first computer software application, and if the digital signature is valid, decrypting the encrypted message using the private key of the key pair, encrypting the response to the message using the private key, and providing the encrypted response to the process of the first computer software application.

[0016] In another aspect of the present invention, the first computer software application is a web browser.

[0017] In another aspect of the present invention, the object is a process or a thread of a process. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] As will be more fully understood and appreciated from the following detailed description taken in conjunction with the accompanying drawings, in which:

[0019] Figure 1 is a simplified conceptual diagram of a system of a computer security system constructed and operated in accordance with an embodiment of the present invention;

[0020] Figure 2 is an operation of an embodiment according to the present invention Figure 1 simplified flowchart of an exemplary method of operating a system;

[0021] Figure 3 is an operation of an embodiment according to the present invention Figure 1 simplified flowchart of an exemplary method of operating a system;

[0022] Figure 4 is a simplified conceptual diagram of a computer security system constructed and operated according to an embodiment of the present invention;

[0023] Figure 5 is Figure 4 simplified flowchart of an exemplary method of operating a system;

[0024] Figure 6 is a simplified conceptual diagram of a computer security system constructed and operated according to an embodiment of the present invention; and

[0025] Figure 7 is an operation of an embodiment according to the present invention Figure 6 simplified flowchart of an exemplary method of operating a system. DETAILED DESCRIPTION

[0026] Now refer to Figure 1 which is a simplified conceptual diagram of a computer security system constructed and operated according to an embodiment of the present invention, and additionally refer to Figure 2 and Figure 3 which is an operation of an embodiment according to the present invention Figure 1 simplified flowchart of an exemplary method of operating a system. In Figure 1 the system and Figure 2 and Figure 3 the method, the kernel driver 100 is configured according to conventional techniques to be executed by the computer 102 in kernel mode, for example where the computer 102 runs Windows TM operating system, which is commercially available from Microsoft Corporation, Redmond, WA.

[0027] According to an embodiment of the present invention, the kernel driver 100 is configured to protect the process 104, where the process 104 is an instance of a computer software application 106 also executed by the computer 102. In one embodiment, the computer software application 106 is a software application that is not an operating system component, such as the Enterprise Browser commercially available from Island Technology, Inc., Dallas, TXTM , or another web browser or word processing software. In another embodiment, the computer software application 106 is an operating system component, such as a kernel driver or a hardware device driver. In one embodiment, the kernel driver 100 is configured to determine that the computer software application 106 is one of one or more specific computer software applications or types of computer software applications that its process kernel driver 100 is configured to protect.

[0028] In addition, according to an embodiment of the present invention, the kernel driver 100 is configured to protect the process 104 according to one or more protection policies (collectively referred to herein as protection policies 108). In one embodiment, the protection policies 108 are preconfigured in the kernel driver 100. In another embodiment, the protection policies 108 are provided to the kernel driver 100 (e.g., by the process 104 or by an administrator of the computer 102). The protection policies 108 may indicate any known type of protection that any known operating system kernel or kernel driver would provide for any process executed by the computer (e.g., by controlling access to the process 104 or any object associated with the process 104, such as its memory space, threads, handles, process environment settings, execution context, process and thread environment blocks, and loaded modules).

[0029] In addition, according to an embodiment of the present invention, the kernel driver 100 is configured to receive instructions 110 (e.g., in the form of a system call) from the process 104 to modify the protection policy 108. In one example, the protection policy 108 does not allow a user process other than the process 104 to request access to locations in the memory of the computer 102 that are allocated to the process 104 (e.g., the memory locations where the executable instructions of the process 104 are stored and the memory locations where the process 104 stores data). Then, the instructions 110 indicate that this protection will be modified to allow the specified user process to receive requests for such access. The kernel driver 100 is also configured to modify the protection policy 108 according to the instructions 110 (preferably after the kernel driver 100 determines that the process 104 is authorized to provide such instructions according to conventional techniques). In one embodiment, the kernel driver 100 determines that the process 104 is so authorized by determining that the digital signature 112 of the computer software application 106 is valid (e.g., where the computer software application 106 is an executable file that is executed by the computer 102 to create the process 104). Then, after the protection policy has been modified according to the instructions 110, the kernel driver 110 continues to protect the process 104 according to the protection policy 108.

[0030] In one embodiment, the kernel driver 100 is configured to identify process 114 as an instance of computer software application 116 also executed by computer 102, so that the kernel driver 100 can determine, based on protection policy 108, whether to allow process 114 to be granted a request to access process 104 or any object associated with process 104. In one embodiment, the kernel driver 100 is configured to determine that computer software application 116 is one of one or more specific computer software applications or computer software application types that the kernel driver 100 is configured to evaluate in this manner. In one embodiment, the kernel driver 100 is configured to determine whether the digital signature 118 of computer software application 116 is valid (e.g., where computer software application 116 is an executable file that is executed by computer 102 to create process 114), where protection policy 108 is at least partially based on whether the digital signature is valid. In the case where computer 102 runs Windows TM operating system, the kernel driver 100 can be configured to monitor access requests to process and thread objects by registering a callback with the OS object operation callback facility (e.g., by using the ObRegisterCallback routine family). The kernel driver 100 can be configured to specifically monitor access to the PsProcessType and PsThreadType objects.

[0031] Now refer to Figure 4 , which is a simplified conceptual diagram of a computer security system constructed and operated in accordance with an embodiment of the present invention, and additionally refer to Figure 5 , which is a simplified flowchart of an exemplary method of operation of a Figure 4 system operated in accordance with an embodiment of the present invention. Figure 4 The system of Figure 1 is substantially similar to the system of Figure 4 unless otherwise described below. In the Figure 5 system and

[0032] In one embodiment, the kernel driver 100 stores the encryption / decryption key 402 in a special registry key according to conventional techniques, and the registry key is protected by the kernel driver 100 against unauthorized process access. When the computer 102 runs Windows TM operating system, this can be accomplished by using the kernel registry filtering infrastructure provided by the CmRegisterCallback routine series to register the kernel driver 100 as a registry filter driver and prevent any process from accessing the special registry key (unless requested by the process 104 and if the protection policy 108 permits).

[0033] Thereafter, for example, when the process 104 wishes to decrypt data that can be decrypted using the decryption key 400, the process 104 sends the encrypted decryption key 400' to the kernel driver 100 and requests its decryption. Then the kernel driver 100 retrieves the encryption / decryption key 402, decrypts the encrypted decryption key 400', and provides the decrypted decryption key 400 to the process 104. In this way, the process 104 does not need to maintain its own copy of the decryption key 400. In one embodiment, as described above, the kernel driver 100 determines whether the digital signature 112 of the executable file of the process 104 is valid and then provides or does not provide the decrypted decryption key 400 to the process 104 according to the protection policy 108, where the protection policy 108 is at least partially based on whether the digital signature is valid. In one embodiment, the encryption / decryption key 402 includes separate encryption and decryption keys to encrypt and decrypt the decryption keys 400 and 400' respectively according to conventional techniques.

[0034] Now refer to Figure 6 , which is a simplified conceptual diagram of a computer security system constructed and operated according to an embodiment of the present invention, and additionally refer to Figure 7 , which is an exemplary method of operation of a Figure 6 system operated according to an embodiment of the present invention. Figure 6 The system is substantially similar to the Figure 1 system, unless otherwise described below. In the Figure 6 system and the Figure 7In the method, the kernel driver 100 is configured to receive a message 600 from a process 104, where before the kernel driver 100 receives the message 600, the message 600 is encrypted according to conventional techniques (e.g., using the public key 602 of a key pair 604, which also includes a private key 606). The kernel driver 100 decrypts the encrypted message 600 (e.g., using the private key 606), encrypts a response 608 (e.g., using the private key 606), and provides the encrypted response 608 to the process 104. In one embodiment, as described above, the kernel driver 100 determines whether the digital signature 112 of the executable file of the process 104 is valid and then provides or does not provide the encrypted response 608 to the process 104 according to a protection policy 108, where the protection policy 108 is at least partially based on whether the digital signature is valid.

[0035] Any aspect of the invention described herein can be implemented in computer hardware and / or computer software embodied in a non-transitory computer-readable medium according to conventional techniques, where the computer hardware includes one or more computer processors, computer memory, I / O devices, and a network interface that interoperates according to conventional techniques.

[0036] It should be understood that the term "processor" or "device" as used herein is intended to include any processing device (such as, for example, a device including a CPU (central processing unit) and / or other processing circuitry). It should also be understood that the term "processor" or "device" can refer to more than one processing device, and various elements associated with the processing device can be shared by other processing devices.

[0037] The term "memory" as used herein is intended to include memory associated with a processor or CPU (such as, for example, RAM, ROM, fixed memory devices (e.g., hard disk drives), removable memory devices (e.g., disks), flash memory, etc.). Such memory can be considered a computer-readable storage medium.

[0038] In addition, the phrase "input / output device" or "I / O device" as used herein is intended to include, for example, one or more input devices (such as a keyboard, mouse, scanner, etc.) for inputting data to a processing unit, and / or one or more output devices (such as speakers, displays, printers, etc.) for presenting results associated with the processing unit.

[0039] Embodiments of the invention can include systems, methods, and / or computer program products. A computer program product can include a computer-readable storage medium (or multiple computer-readable storage media) having computer-readable program instructions thereon for causing a processor to execute aspects of the invention.

[0040] A computer-readable storage medium can be a tangible device that can retain and store instructions for use by an instruction execution device. A computer-readable storage medium can be, by way of example and not limitation, an electronic storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination of the foregoing devices. A non-exhaustive list of more specific examples of computer-readable storage media includes the following: a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), a static random access memory (SRAM), a portable compact disc read-only memory (CD-ROM), a digital versatile disc (DVD), a memory stick, a floppy disk, a mechanically encoded device such as a punch card or raised structures in a groove having instructions recorded thereon, and any suitable combination of the foregoing items. As used herein, a computer-readable storage medium should not be construed as a transitory signal per se (such as a radio wave or other freely propagating electromagnetic wave, an electromagnetic wave propagating through a waveguide or other transmission medium (e.g., a light pulse through an optical fiber cable), or an electrical signal transmitted through a wire).

[0041] The computer-readable program instructions described herein can be downloaded from a computer-readable storage medium to a corresponding computing / processing device, or downloaded to an external computer or external storage device via a network, such as the Internet, a local area network, a wide area network, and / or a wireless network. The network can include copper transmission cables, optical transmission fibers, wireless transmission, routers, firewalls, switches, gateway computers, and / or edge servers. A network adapter card or network interface in each computing / processing device receives the computer-readable program instructions from the network and forwards the computer-readable program instructions for storage in a computer-readable storage medium within the corresponding computing / processing device.

[0042] The computer-readable program instructions for performing the operations of the present invention may be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, state-setting data, or source code or object code written in any combination of one or more programming languages, including object-oriented programming languages (such as Java, Smalltalk, C++ etc.) and traditional procedural programming languages (e.g., the "C" programming language or similar programming languages). The computer-readable program instructions may be executed entirely on the user's computer, partially on the user's computer (as a stand-alone software package), partially on the user's computer and partially on a remote computer, or entirely on the remote computer or server. In the latter case, the remote computer may be connected to the user's computer through any type of network connection (including a local area network (LAN) or a wide area network (WAN)), or may be connected to an external computer (e.g., through the Internet using an Internet service provider). In some embodiments, an electronic circuit system, including, for example, a programmable logic circuit system, a field programmable gate array (FPGA), or a programmable logic array (PLA), may execute the computer-readable program instructions by utilizing the state information of the computer-readable program instructions to personalize the electronic circuit system to perform aspects of the present invention.

[0043] Aspects of the present invention are described herein with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer-readable program instructions.

[0044] These computer-readable program instructions may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus to produce a machine, such that the instructions executed via the processor of the computer or other programmable data processing apparatus create a means for implementing the functions / actions specified in the flowchart and / or one or more block diagrams. These computer-readable program instructions may also be stored in a computer-readable storage medium, which can direct a computer, a programmable data processing apparatus, and / or other devices to function in a particular manner, such that the computer-readable storage medium in which the instructions are stored comprises an article of manufacture including instructions for implementing aspects of the functions / actions specified in the flowchart and / or one or more block diagrams.

[0045] The computer-readable program instructions may also be loaded onto a computer, other programmable data processing apparatus, or other devices to cause a series of operational steps to be performed on the computer, other programmable apparatus, or other devices to produce a computer-implemented process such that the instructions executed on the computer, other programmable apparatus, or other devices implement the functions / acts specified in the flowchart and / or one or more block diagrams.

[0046] The flowchart illustrations and block diagrams in the figures illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in the flowchart illustration or block diagram may represent a module, segment, or portion of computer instructions, which includes one or more executable computer instructions for implementing the specified logical function. In some alternative implementations, the functions marked in the blocks may not occur in the order marked in the figures. For example, two blocks shown in succession may, in fact, be executed substantially concurrently, or the blocks may sometimes be executed in the reverse order, depending upon the functionality involved. It will also be noted that each block of the flowchart illustrations and block diagrams, and combinations of blocks, can be implemented by special purpose hardware-based systems that perform the specified functions or acts, and / or by computer-based systems that include a combination of hardware and software.

[0047] The description of the various embodiments of the present invention has been presented for purposes of illustration, but is not intended to be exhaustive or limited to the disclosed embodiments. Many modifications and variations will be apparent to those of ordinary skill in the art without departing from the scope and spirit of the described embodiments.

Claims

1. A computer security method, comprising: Protecting a process of a first computer software application executed by a computer, wherein the protection is performed according to a protection policy; Receiving an instruction to modify the protection policy from the process; Modifying the protection policy according to the instruction; And After the protection policy has been modified according to the instruction, protecting the process according to the protection policy, wherein the protection, receiving, and modification are performed by a kernel driver executed by the computer.

2. The computer security method according to claim 1, wherein the first computer software application is a web browser.

3. The computer security method according to claim 1, wherein any one of the protection, receiving, and modification is performed after determining that a digital signature is valid, wherein the digital signature is a digital signature of an executable file of the first computer software application, and wherein the determination is performed by the kernel driver executed by the computer.

4. The computer security method according to claim 1, wherein the protection comprises: Detecting an attempt by a process of a second computer software application executed by the computer to access an object associated with the first computer software application; Determining whether a digital signature is valid, wherein the digital signature is a digital signature of an executable file of the second computer software application; And Allowing or preventing access to the object by the second computer software application according to the protection policy, wherein the protection policy is at least partially based on whether the digital signature is valid, wherein the detection, determination, allowing, and preventing are performed by the kernel driver executed by the computer.

5. The computer security method according to claim 4, wherein the object is a process or a thread of a process.

6. The computer security method according to claim 1, wherein the protection comprises: Receiving a decryption key from the process of the first computer software application; Receiving a request from the process of the first computer software application to receive the decryption key; Determining whether a digital signature is valid, wherein the digital signature is a digital signature of the first computer software application; And Providing or not providing the decryption key to the process according to the protection policy, wherein the protection policy is at least partially based on whether the digital signature is valid, wherein the receiving, determination, allowing, providing, and not providing are performed by the kernel driver executed by the computer.

7. The computer security method according to claim 6, wherein After receiving the decryption key from the process of the first computer software application, the decryption key is encrypted, and the method further comprises decrypting the encrypted decryption key if the digital signature is valid before providing the decryption key to the process of the first computer software application.

8. The computer security method according to claim 1, wherein the protection comprises: Receiving an encrypted message from the process of the first computer software application, wherein the message is encrypted using a public key of a key pair; Determine whether a digital signature is valid, where the digital signature is the digital signature of an executable file of the first computer software application; and if the digital signature is valid, then decrypt the encrypted message using the private key of the key pair, encrypt a response to the message using the private key, and provide the encrypted response to the process of the first computer software application, wherein the receiving, determining, decrypting, encrypting, and providing are performed by the kernel driver executed by the computer.

9. A computer security device, comprising: a kernel driver configured to be executed by a computer in kernel mode and then execute a process of protecting a first computer software application executed by the computer, where the protection is performed according to a protection policy, receive an instruction to modify the protection policy from the process, modify the protection policy according to the instruction, and after the protection policy has been modified according to the instruction, protect the process according to the protection policy.

10. The computer security device according to claim 9, wherein the first computer software application is a web browser.

11. The computer security device according to claim 9, wherein, The kernel driver is configured to perform any one of the protection, receiving, and modifying after the kernel driver determines that the digital signature is valid, where the digital signature is the digital signature of an executable file of the first computer software application.

12. The computer security device according to claim 9, wherein the kernel driver is configured to perform the protection by detecting an attempt by a process of a second computer software application executed by the computer to access an object associated with the first computer software application, determining whether a digital signature is valid, where the digital signature is the digital signature of an executable file of the second computer software application, and allowing or preventing access to the object by the second computer software application according to the protection policy, where the protection policy is at least partially based on whether the digital signature is valid.

13. The computer security device according to claim 12, wherein the object is a process or a thread of a process.

14. The computer security device according to claim 9, wherein the kernel driver is configured to perform the protection by receiving a decryption key from the process of the first computer software application; receiving a request from the process of the first computer software application to receive the decryption key; determining whether a digital signature is valid, where the digital signature is the digital signature of the first computer software application; and providing or not providing the decryption key to the process according to the protection policy, where the protection policy is at least partially based on whether the digital signature is valid, wherein the receiving, determining, allowing, providing, and not providing are performed by the kernel driver executed by the computer.

15. The computer security device according to claim 14, wherein, The kernel driver is configured to encrypt the decryption key after receiving the decryption key from the process of the first computer software application, and decrypt the encrypted decryption key if the digital signature is valid before providing the decryption key to the process of the first computer software application.

16. The computer security device according to claim 9, wherein the kernel driver is configured to perform the protection by: Receiving an encrypted message from the process of the first computer software application, wherein the message is encrypted using the public key of a key pair, Determining whether a digital signature is valid, wherein the digital signature is the digital signature of the executable file of the first computer software application, and If the digital signature is valid, then Decrypting the encrypted message using the private key of the key pair, Encrypting a response to the message using the private key, and Providing the encrypted response to the process of the first computer software application.