Digital assets (e.g., files) are protected with a combination of more than one type of applicable security means. Techniques are developed to determine which of the security means to enforce in accordance with an access policy or policies when an access request is received. According to one embodime
Digital assets (e.g., files) are protected with a combination of more than one type of applicable security means. Techniques are developed to determine which of the security means to enforce in accordance with an access policy or policies when an access request is received. According to one embodiment, an interpreter or an access control module intercepts an access request from a requestor to access a secured file. The access control module is configured to determine if the access request is to be granted or denied to enforce security of the file through an access control technique and a cryptographic technique; and when the access request is granted, a key is retrieved to proceed with the access request.
대표청구항▼
I claim: 1. A method for accessing a file in a store, the method comprising: intercepting an access request from a user to access the file; determining if the file is an encrypted file; determining if the user is authorized to access the encrypted file in response to the determination that the file
I claim: 1. A method for accessing a file in a store, the method comprising: intercepting an access request from a user to access the file; determining if the file is an encrypted file; determining if the user is authorized to access the encrypted file in response to the determination that the file is encrypted; evaluating one or more access policies imposed upon the encrypted file or the store with respect to an access privilege of the user in response to the determination that the user is authorized to access the encrypted file; retrieving a key in response to the evaluation indicating that the one or more access policies is met; decrypting the encrypted file using the key; and passing the decrypted file to the user. 2. The method of claim 1, wherein the determining if the user is authorized to access the encrypted file comprises determining if the user is listed on an access control list (ACL). 3. The method of claim 1, wherein the intercepting the access request comprises determining if the file is unsecured. 4. The method of claim 1, wherein the evaluating the one or more access policies comprises evaluating a location of the user. 5. The method of claim 1, wherein the evaluating the one or more access policies comprises evaluating the one or more access policies with respect to a time the access request is made. 6. The method of claim 1, wherein each of the access policies includes rule items; and evaluating the one or more access policies comprises comparing each of the rule items logically with at least one of parameters pertaining to the access privilege of the user. 7. The method of claim 6, wherein said comparing of the rule items logically with at least one of the parameters comprises: producing a success if the comparing indicates a respective one of the parameters is within a definition of a corresponding of the rule items; producing a failure if the comparing indicates a respective one of the parameters is not within or is beyond the definition of the corresponding of the rule items; and repeating the comparing until each rule item has been tested against its respective parameters. 8. The method as recited in claim 7, wherein the comparing of the at least one of the parameters and the rule items is considered successful when each comparing produces a success result. 9. The method as recited in claim 7, wherein the comparing of the at least one of the parameters and the rule items is considered not successful when a failure results from any of the comparing. 10. The method of claim 1, wherein said retrieving a key comprises using a cryptographic technique and prompting to the user for a password. 11. The method of claim 10, wherein using the cryptographic technique comprises using the password to decrypt a file containing the key. 12. The method of claim 1, wherein the retrieving a key comprises automatically receiving the key associated with the user. 13. The method of claim 1, wherein an operation of the method is transparent to the user. 14. A tangible computer-readable medium having stored thereon, computer-executable instructions that, if executed by a computing device, cause the computing device to control access to a file in a store by a method, comprising: intercepting an access request from a user to access the file; determining if the file is an encrypted file; determining if the user is authorized to access the encrypted file in response to the determination that the file is encrypted; evaluating one or more access policies associated with the encrypted file or the store with respect to an access privilege of the user in response the determination that the user is authorized to access the encrypted file; retrieving a key in response to the evaluation indicating that the one or more access policies is met; decrypting the encrypted file using the key; and passing the decrypted file to the user. 15. The tangible computer-readable medium of claim 14, wherein determining if the user is authorized to access the encrypted file comprises determining if the user is listed on an access control list (ACL). 16. The tangible computer-readable medium of claim 14, wherein the intercepting the access request comprises determining if the file is unsecured. 17. The tangible computer-readable medium of claim 14, wherein the evaluating the one or more access policies comprises evaluating a location of the user. 18. The tangible computer-readable medium of claim 14, wherein the evaluating the one or more access policies comprises evaluating the one or more access policies with respect to a time the access request is made. 19. The tangible computer-readable medium of claim 14, wherein each of the access policies includes rule items; and evaluating the one or more access policies comprises comparing each of the rule items logically with at least one of parameters pertaining to the access privilege of the user. 20. The tangible computer-readable medium of claim 19, wherein said comparing of the rule items logically with respective parameters comprises: producing a success if the comparing indicates a respective one of the parameters is within a definition of a corresponding of the rule items; producing a failure if the comparing indicates a respective one of the parameters is not within or is beyond the definition of the corresponding of the rule items; and repeating the comparing until each rule item has been tested against its respective parameters. 21. The tangible computer-readable medium of claim 20, wherein the comparing of the respective parameters and the rule items is successful when each comparing is a success. 22. The tangible computer-readable medium of claim 20, wherein the comparing of the respective parameters and the rule items is not successful when a failure results from any of the comparing. 23. The tangible computer-readable medium of claim 14, wherein the retrieving a key comprises using a cryptographic technique and prompting the user to provide a password. 24. The tangible computer-readable medium of claim 23, wherein said using the cryptographic technique comprises decrypting a file containing the key using the password. 25. The tangible computer-readable medium of claim 14, wherein the retrieving a key comprises automatically receiving the key associated with the user. 26. A tangible computer-readable medium having instructions stored thereon, the instructions comprising: instructions to intercept an access request from a user to access a file in a store; instructions to determine if the file is an encrypted file; instructions to determine if the user is authorized to access the encrypted file in response to the determination that the file is encrypted; instructions to evaluate one or more access policies imposed upon the encrypted file or the store with respect to an access privilege of the user in response to a determination that the user is authorized to access the encrypted file; instructions to retrieve a key in response to the evaluation that indicates that the one or more access policies is met; instructions to decrypt the encrypted file using the key; and instructions to pass the decrypted file to the user. 27. A computer-implemented system comprising: a computer-readable storage medium configured to store a file; and an access control management module which if executed by a computing device of the computer-implemented system, causes the computing device to: intercept an access request from a user to access the file; determine if the file is an encrypted file; determine if the user is authorized to access the encrypted file in response to the determination that the file is encrypted; evaluate one or more access policies imposed upon the encrypted file or the store with respect to an access privilege of the user in response to a determination that the user is authorized to access the encrypted file; retrieve a key in response to an evaluation that indicates one or more access policies is met; decrypt the encrypted file using the key; and pass the decrypted file to the user. 28. A method for accessing a file in a store, the method comprising: intercepting a file access request from a user; determining if the store is a protected store; if the file is stored in the protected store, determining if the user is authorized to access the store; evaluating one or more access policies imposed upon the file or the store with respect to an access privilege of the user in response to a determination that the user is authorized to access the store; retrieving a key in response to the evaluating indicates that the one or more access policies is met; using the key to unsecure the file; and passing the unsecured file to the user. 29. The method of claim 28, wherein the determining if the file is stored in a protected store comprises examining a path where the requested file resides.
연구과제 타임라인
LOADING...
LOADING...
LOADING...
LOADING...
LOADING...
이 특허에 인용된 특허 (314)
Edward M. Scheidt ; Ersin L. Domangue, Access control and authorization system.
Just, Michael K.; Van Oorschot, Paul, Apparatus and method for reducing transmission bandwidth and storage requirements in a cryptographic security system.
Bahl, Paramvir; Venkatachary, Srinivasan; Balachandran, Anand, Authentication methods and systems for accessing networks, authentication methods and systems for accessing the internet.
Strickler Gary E. ; Knapp Herbert William ; Holenstein Bruce D. ; Holenstein Paul J., Bidirectional database replication scheme for controlling ping-ponging.
Peinado,Marcus, Binding a digital license to a portable device or the like in a digital rights management (DRM) system and checking out/checking in the digital license to/from the portable device or the like.
Brownlie,Michael; Hillier,Stephen; Van Oorschot,Paul C., Computer network security system and method having unilateral enforceable security policy provision.
Reed Drummond Shattuck ; Heymann Peter Earnshaw ; Mushero Steven Mark ; Jones Kevin Benard ; Oberlander Jeffrey Todd ; Banay Dan, Computer-based communication system and method using metadata defining a control structure.
Reed Drummond Shattuck ; Heymann Peter Earnshaw ; Mushero Steven Mark ; Jones Kevin Benard ; Oberlander Jeffrey Todd, Computer-based communication system and method using metadata defining a control-structure.
Auerbach Joshua Seth (Ridgefield CT) Chow Chee-Seng (Cupertino CA) Kaplan Marc Adam (Katonah NY) Crigler Jeffrey Charles (McLean VA), Creation and distribution of cryptographic envelope.
Ehrsam William F. (Kingston NY) Elander Robert C. (Saugerties NY) Matyas Stephen M. (Poughkeepsie NY) Meyer Carl H. W. (Kingston NY) Sahulka Richard J. (Woodstock NY) Tuchman Walter L. (Woodstock NY), Cryptographic file security for multiple domain networks.
Yoshino, Kenji; Ishibashi, Yoshihito; Akishita, Toru; Shirai, Taizo; Ito, Takeshi; Hayashi, Shigekazu, Data processing device, data storage device, data processing method, and program providing medium for storing content protected under high security management.
Hecht Matthew S. (Potomac MD) Johri Abhai (Gaithersburg MD) Wei Tsung T. (Gaithersburg MD) Steves Douglas H. (Austin TX), Distributed security auditing subsystem for an operating system.
Ohtsu Toshiyuki,JPX, Dynamic adding system for memory files shared among hosts, dynamic adding method for memory files shared among hosts, and computer-readable medium recording dynamic adding program for memory files sh.
Downs Edgar ; Gruse George Gregory ; Hurtado Marco M. ; Lehman Christopher T. ; Milsted Kenneth Louis ; Lotspiech Jeffrey B., Electronic content delivery system.
Kuroda, Yasutsugu; Kamada, Jun; Iwase, Shoko; Noda, Bintatsu; Ono, Etsuo, Electronic data storage apparatus with key management function and electronic data storage method.
Smith Jeffrey C. ; Bandini Jean-Christophe, Electronic document delivery system in which notification of said electronic document is sent to a recipient thereof.
Tozawa,Jun; Nogami,Hiroshi; Shibayama,Tetsuya; Kataoka,Tomohiro; Fujio,Hiroshi, Encryption and decryption communication semiconductor device and recording/reproducing apparatus.
Elmer Thomas I. (Sunnyvale CA) Nguyen Tuan T. (Milpitas CA) Lin Rung-Pan (San Jose CA), Encryption of streams of addressed information to be used for program code protection.
Shimbo Atsushi,JPX ; Takahashi Toshinari,JPX ; Tomoda Ichiro,JPX ; Murota Masao,JPX, File editing system and shared file editing system with file content secrecy, file version management, and asynchronous.
Eshel Marc M. (Tarrytown NY) Hunt Guerney D. H. (Ithaca NY) Jones Donald N. (Vestal NY) Meyer Christopher (Vestal NY) Schwartz Frederick A. (Binghamton NY), File manager for files shared by heterogeneous clients.
Kumar,Sanjay; Thomas,Stanton L.; Deshpande,Gaurav M.; Murty,Venkataesh V., Fulfillment management system for managing ATP data in a distributed supply chain environment.
Bonn, David Wayne; Marvais, Nick Takaski, Generalized network security policy templates for implementing similar network security policies across multiple networks.
Shimizu Hideo,JPX ; Hori Satomi,JPX ; Endoh Naoki,JPX ; Saisho Toshiaki,JPX, Information processing system having function of securely protecting confidential information.
Asano,Tomoyuki; Osawa,Yoshitomo, Information recording device, information playback device, information recording method, information playback method, and information recording medium and program providing medium used therewith.
Pensak David A. ; Cristy John J. ; Singles Steven J., Information security architecture for encrypting documents for remote access while maintaining access control.
Law,Gary K.; Deitz,David L.; Schleiss,Trevor Duncan; Naidoo,Julian, Integrated electronic signatures for approval of process control and safety system software objects.
Phillips,Robert S.; Davis,Scott H.; Dietterich,Daniel J.; Nyman,Scott E.; Porter,David, Internet-based shared file service with native PC client access and semantics.
Phillips,Robert S.; Davis,Scott H.; Dietterich,Daniel J.; Nyman,Scott E.; Porter,David, Internet-based shared file service with native PC client access and semantics and distributed access control.
Thomsen,Daniel Jay; O'Brien,Richard; Bogle,Jessica; Payne,Charles, Locally adaptable central security management in a heterogeneous network environment.
John E. Parsons, Jr. ; Bradley J. Graziadio ; Oshoma Momoh, Maintaining a first session on a first computing device and subsequently connecting to the first session via different computing devices and adapting the first session to conform to the different com.
Zavalkovsky,Arthur; Elfassy,Nitsan, Method and apparatus for communicating network quality of service policy information to a plurality of policy enforcement points.
McLaughlin Michael D. (San Jose CA) Signa John C. (Sunnyvale CA) Greicar Richard K. (Moss Beach CA) Taylor John M. (London GB2), Method and apparatus for display calibration and control.
Batten-Carew Mark,CAX ; Buchler Marek,CAX ; Hiller Stephen William,CAX ; Otway Josanne Mary,CAX, Method and apparatus for processing administration of a secured community.
Basani, Vijay R.; Mangiapudi, Krishna; Murach, Lynne M.; Karge, Leroy R.; Revsin, Vitaly S.; Bestavros, Azer; Crovella, Mark E.; LaRosa, Domenic J., Method and apparatus for reliable and scalable distribution of data files in distributed networks.
Sames, David L.; Whitmore, Brent S.; Niebuhr, Brian S.; Tally, Gregg W., Method and apparatus for securely and dynamically modifying security policy configurations in a distributed system.
DeMello, Marco A.; Keely, Leroy B.; Byrum, Frank D.; Yaacovi, Yoram; Hughes, Kathryn E., Method and system for binding enhanced software features to a persona.
Hauser Ralf,CHX ; Janson Philippe,CHX ; Molva Refik,FRX ; Tsudik Gene,CHX ; Van Herreweghen Elsie,CHX, Method and system for changing an authorization password or key in a distributed communication network.
Halter Bernard J. (Longmont CO) Bracco Alphonse M. (Reston VA) Johnson Donald B. (Manassas VA) Le An V. (Manassas VA) Matyas Stephen M. (Manassas VA) Prymak ; deceased Rostislaw (late of Dumfries VA , Method and system for multimedia access control enablement.
Krueger, Scott; Goodman, Daniel, Method and system for seamless integration of preprocessing and postprocessing functions with an existing application program.
Chan, Shannon; Jensenworth, Gregory; Goertzel, Mario C.; Shah, Bharat; Swift, Michael M.; Ward, Richard B., Method and system for secure running of untrusted content.
Komuro Teruyoshi,JPX ; Osawa Yoshitomo,JPX ; Shima Hisato ; Asano Tomoyuki,JPX, Method and system for transferring information using an encryption mode indicator.
Lambert Howard Shelton,GBX ; Orchard James Ronald Lewis,GBX, Method for controlling access to electronically provided services and system for implementing such method.
Bala,Vasanth; Smith,Michael D., Method for protecting digital content from unauthorized use by automatically and dynamically integrating a content-protection agent.
Skarbo Rune A. ; Clitheroe Cameron J. ; Lawless Christopher C. ; Kukkal Puneet ; Hochman Stephen D., Method for web based storage and retrieval of documents.
Richard Patrick,CAX ; Csinger Andrew,CAX ; Knipe Bruce,CAX ; Woodward Bruce,CAX, Method of and apparatus for providing secure distributed directory services and public key infrastructure.
Hochberg,Avishai Haim; Marek,Toby Lyn; Cannon,David Maxwell; Martin,Howard Newton; Warren, Jr.,Donald Paul; Haye,Mark Alan, Method, system, and program for retention management and protection of stored objects.
Shamoon,Talal G.; Hill,Ralph D.; Radcliffe,Chris D.; Hwa,John P.; Sibert,W. Olin; Van Wie,David M., Methods and apparatus for persistent control and protection of content.
Arlein,Robert M.; Jai,Ben; Jakobsson,Bjorn Markus; Monrose,Fabian; Reiter,Michael Kendrick, Methods and apparatus for providing privacy-preserving global customization.
Beattie,Douglas D.; Creighton, Jr.,Neal Lewis; Bailey,Christopher T. M.; Remy,David L.; Hamandi,Hani, Methods and systems for automated authentication, processing and issuance of digital certificates.
Vahalia Uresh K. ; Gupta Uday ; Porat Betti ; Tzelnic Percy, Network file server sharing local caches of file access information in data processors assigned to respective file systems.
Schmuck Frank B. ; Zlotek Anthony J. ; Shmueli Boaz,ILX ; Mandler Benjamin,ILX ; Yehudai Zvi Yosef,ILX ; Kish William A., Parallel file system with method using tokens for locking modes.
Matyas, Jr., Stephen Michael; Peyravian, Mohammad; Roginsky, Allen Leonid; Zunic, Nevenko, Secure data storage and retrieval with key management and user authentication.
Rose Anthony M. (66 Drumalbyn Road Bellevue Hill ; Sydney AUX 2023), Securing a computer against undesired write operations to or read operations from a mass storage device.
Davis, Mark C.; Hind, John R.; Peters, Marcia L.; Topol, Brad B., Selective data encryption using style sheet processing for decryption by a group clerk.
William J. Bolosky ; John R. Douceur ; Scott M. Cutshall ; Richard F. Rashid ; Nathan P. Myhrvold ; David A. Goebel, Single instance store for file systems.
Takahashi Toshinari,JPX ; Nogami Hiroyasu,JPX, Software distribution system and software utilization scheme for improving security and user convenience.
Barlow, Doug; Dillaway, Blair; Fox, Barbara; Lipscomb, Terry; Spies, Terrence, System and method for configuring and managing resources on a multi-purpose integrated circuit card using a personal computer.
Rusnak David J. ; Zientara John T., System and method for controlling access rights to and security of digital content in a distributed information system, e.g., Internet.
Carman David W. ; Balenson David M. ; Tajalli Homayoon ; Walker Stephen T., System and method for controlling access to a user secret using a key recovery field.
Richard R. Viets ; David G. Motes ; Paula Budig Greve ; Wayne W. Herberg, System and method for controlling access to documents stored on an internal network.
Viets, Richard R.; Motes, David G.; Greve, Paula Budig; Herberg, Wayne W., System and method for controlling access to documents stored on an internal network.
Lipner Steven B. (Oakton VA) Balenson David M. (Olney MD) Ellison Carl M. (Baltimore MD) Walker Stephen T. (Glenwood MD), System and method for data recovery.
Olsen, Theis; Bundesen, Rune Windfeld; Hougaard, Claes Christian; Nordly, Trygve Thor, System and method for ensuring secure transfer of a document from a client of a network to a printer.
Dennis, Michael W.; Freed, Michele L.; Plastina, Daniel; Flo, Eric R.; Kays, Jr., David E.; Corrington, Robert E., System and method for implementing group policy.
Michael W. Dennis ; Michele L. Freed ; Daniel Plastina ; Eric R. Flo ; David E. Kays, Jr. ; Robert E. Corrington, System and method for implementing group policy.
Kiessig,Rick; Yost,David A.; Mathon,John D., System and method for managing content with event driven actions to facilitate workflow and other features.
Sakurai Hiroshi (Tokyo JPX) Ikeda Nobuyuki (Tokyo JPX) Watabe Akehiro (Tokyo JPX), System and method for processing document information using password protected icons that represent document content.
Premkumar Thomas Devanbu ; Stuart Gerald Stubblebine, System and method for providing assurance to a host that a piece of software possesses a particular property.
Dixon Peggy PakFan ; Shi Danling ; Verburg Richard Lee ; Wood Donald Edwin, System and method for transferring a session from one application server to another without losing existing resources.
Bess, Dwayne Lamarr; Brischke, Harold Allan; Keller, Andrew Charles; Wagner-Krankel, Dale Alan; Tijerina, Jacob Garza; Connolly, Jr., Billy Ray; O'Connor, Karen Ann; McDaniel, James William; Lewis, R, System and method of providing electronic access to one or more documents.
McDonnal William D. (Tigard OR) Lohstroh Shawn (Beaverton OR) Grawrock David (Aloha OR), System for automatic decryption of file data on a per-use basis and automatic re-encryption within context of multi-thre.
Bacha, Hamid; Carroll, Robert Bruce; Mirlas, Lev; Tchao, Sung Wei, System for electronic repository of data enforcing access control on data search and retrieval.
Riedel,Erik; Karamanolis,Christos; Kallahalla,Mahesh; Swaminathan,Ram, System for ensuring data privacy and user differentiation in a distributed file system.
Hahn Samuel S. ; LeGault Kenn ; Wheeler Maxon ; Degenhardt Jon R., System for organizing document icons with suggestions, folders, drawers, and cabinets.
Donaghey, Robert J.; Carielli, Sandra E.; Helinek, Pamela, System for selecting and disseminating active policies to peer device and discarding policy that is not being requested.
Krishnaswamy, Sridhar; Elliott, Isaac K.; Reynolds, Tim E.; Forgy, Glen A.; Solbrig, Erin M., System, method and article of manufacture for a communication system architecture including video conferencing.
Ginter Karl L. ; Shear Victor H. ; Sibert W. Olin ; Spahn Francis J. ; Van Wie David M., Systems and methods for secure transaction management and electronic rights protection.
Ginter Karl L. ; Shear Victor H. ; Spahn Francis J. ; Van Wie David M., Systems and methods for the secure transaction management and electronic rights protection.
Davis Mark Charles ; Gray Steve D. ; Kuehr-McLaren David Gerard ; Morrison Ian A. ; Shoriak Timothy G., Systems, methods and computer program products for authenticating client requests with client certificate information.
Bly Sara A. (Mountain View CA) Hodges Jeffrey D. (Newark CA) Kupfer Michael D. (Mountain View CA) Lewis Brian T. (Palo Alto CA) Tallan Michael L. (Mountain View CA) Tom Stephen B. (San Francisco CA), Updating local copy of shared data in a collaborative system.
Okamoto Toshio,JPX ; Shimbo Atsushi,JPX ; Ishiyama Masahiro,JPX, User identification data management scheme for networking computer systems using wide area network.
Garcia, Denis Jacques Paul; Ouye, Michael Michio; Rossmann, Alain; Crocker, Steven Toye; Gilbertson, Eric; Huang, Weiqing; Humpich, Serge; Vainstein, Klimenty; Ryan, Nicholas Michael, Methods and systems for providing access control to secured data.
Garcia, Denis Jacques Paul; Ouye, Michael Michio; Rossmann, Alain; Crocker, Steven Toye; Gilbertson, Eric; Huang, Weiqing; Humpich, Serge; Vainstein, Klimenty; Ryan, Nicholas Michael, Methods and systems for providing access control to secured data.
Garcia, Denis Jacques Paul; Ouye, Michael Michio; Rossmann, Alain; Crocker, Steven Toye; Gilbertson, Eric; Huang, Weiqing; Humpich, Serge; Vainstein, Klimenty; Ryan, Nicholas Michael, Methods and systems for providing access control to secured data.
Garcia, Denis Jacques Paul; Ouye, Michael Michio; Rossmann, Alain; Crocker, Steven Toye; Gilbertson, Eric; Huang, Weiqing; Humpich, Serge; Vainstein, Klimenty; Ryan, Nicholas Michael, Methods and systems for providing access control to secured data.
Kaushik, Puneet, System and method for providing session-level access management of access requests to a redirected device from a predetermined session.
※ AI-Helper는 부적절한 답변을 할 수 있습니다.