IP Library Granted Patent US 9,197,668
Granted Patent B2
US 9,197,668 · App. 11/330,530 · Granted Nov 24, 2015

Access control to files based on source information

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,197,668
App. No.
11/330,530
Granted
Nov 24, 2015
Kind
B2
Abstract

The present invention is a security tool for protection of data on a mobile computing device. The security tool provides a plurality of security policies to be enforced based on source information for the data and a location associated with a network environment in which a mobile device is operating. The security tool may be either located at the mobile computing device or at the server. The security tool includes a file access module for determining whether files are visible or accessible. The file access module comprises a tag generator, an association module, and a policy enforcement module. The tag generator creates source information for the file being accessed and the policy enforcement module determines what actions, if any, can be performed on the file and under what conditions such as location and network environment, type of file and other factors.

Claims (42)

1. A method for making data accessible by a mobile computing device, comprising:

determining one of a plurality of network environments in which the mobile computing device is operating without regard to a physical geographic location of the mobile computing device;

receiving a request to access a file;

determining source information for the file including identifying privilege information relating to data in the file, wherein the privilege information defines specific access control limitations on the file including the limitations of whether the file can be stored and/or viewed on the mobile computing device and what persons have access rights to the file, wherein the identifying privilege information includes identifying a group or groups of persons with whom a user requesting to access the file is associated;

controlling access to the data in the file based on the determined one network environment in which the mobile computing device is operating and the determined source information for the file; and

allowing access to the data in the file provided only if the privilege information satisfies a predetermined security policy for the determined one network environment.

2. The method of claim 1 wherein the allowing access to the data in the file further includes allowing access based on determining whether a security feature associated with the determined one network environment complies with the predetermined security policy.

3. The method of claim 1 wherein the source information includes a file name and a source address.

4. The method of claim 1 wherein the identifying privilege information relating to data in the file further includes identifying a person or group of persons that can or cannot access the data in the file and identifying actions the person or group of persons may take with the data in the file including the actions of file viewing, file storing or both.

5. The method of claim 3 wherein the source address includes one from the group of a subnet identifier, a server identifier, a folder name, and a file type.

6. The method of claim 5 wherein the source address includes one from the group of an owner of the file, version control information, a hash value, a cyclical redundancy check, and a digital signature.

7. The method of claim 1 wherein the request for file access is one from the group of reading a file, writing a file, viewing a file, emailing a file, transferring a file, and accessing a file using a universal serial bus, a serial port, a parallel port or an infrared interface.

8. The method of claim 1 wherein the step of determining the source information further comprises:

determining the file name;

assigning a unique identification number in a name space to the file;

collecting source information about the file;

creating a record in source data storage; and

storing the unique identification number and the source information in the record.

9. A method for making a file visible on a mobile computing device, comprising:

determining a network location of the mobile computing device based on a network environment in which the mobile computing device is operating without regard to a physical geographic location of the mobile computing device;

identifying at least one security feature associated with the determined network location of the mobile computing device;

retrieving a file name for the file;

determining source information for the file including a source address and privilege information relating to data in the file, wherein the privilege information defines specific access control limitations on the file including the limitations of whether the file can be stored and/or viewed on the mobile computing device and what persons have access rights to the file, wherein the determining privilege information includes determining a group or groups of persons with whom a user requesting to view the file is associated;

setting a security policy for the mobile computing device based on the privilege information at the determined network location and the identified at least one security feature associated with the determined network location; and

making the file visible on the mobile computing device only if the privilege information at the determined network location and the identified at least one security feature associated with the determined network location satisfies the security policy.

10. The method of claim 9 wherein the identifying the at least one security feature associated with the determined network location further includes determining by a server computing system remote from the mobile computing device whether the determined network location is behind a firewall or not.

11. The method of claim 9 wherein the identifying the at least one security feature associated with the determined network location further includes determining whether the mobile computing device has a wired or wireless connection type.

12. The method of claim 9 wherein the source address includes one from the group of a subnet identifier, a server identifier, a folder name, and a file type.

13. The method of claim 12 wherein the source address includes one from the group of an owner of the file, version control information, a hash value, a cyclical redundancy check, and a digital signature.

14. The method of claim 9 wherein the step of determining the source information further comprises:

determining the file name;

assigning a unique identification number in a name space to the file;

collecting source information about the file creating a record in source data storage; and

storing the unique identification number and the source information in the record.

15. The method of claim 9 , further comprising retrieving a second file name for a second file, and determining source information for the second file, and making the second file visible on the mobile computing device based on the determined network location and the determined source information for the second file.

16. An apparatus for protection of data accessible by a mobile computing device operating in one of a plurality of network environments, comprising:

a tag generator for generating source information for a file in response to a request for access to the file, the source information including a file name, a source address and privilege information wherein the privilege information defines specific access control limitations on the file including the limitations of whether the file can be stored and/or viewed on the mobile computing device and what persons have access rights to the file, wherein the privilege information includes an identification of a group or groups of persons with whom a user requesting to access the file is associated;

an association module for managing a name space and providing an unique identification number that identifies a file in response to a signal from the tag generator, the association module coupled to the tag generator; and

a controller coupled to the tag generator and the association module, the controller coupled to a policy enforcement module to provide source information useable by the policy enforcement module to control access to the file, wherein the policy enforcement module operates on a server and controls access to files on the server by the mobile computing device based on the privilege information and a security feature associated with the one of the plurality of network environments in which the mobile computing device is operating complying with a predetermined security policy, without regard to a physical geographic location of the mobile computing device;

whereby the mobile computing device is granted access to the file only if the privilege information and the security feature comply with the predetermined security policy.

17. The apparatus of claim 16 further comprising a file request log for storing source information about files that have been accessed by the mobile computing device, the file request log coupled to the tag generator to receive the source information about the files that have been accessed by the mobile computing device.

18. The apparatus of claim 16 further comprising a source data storage for storing a record of source information, the source data storage coupled to the tag generator to receive the record of source information.

Assignments (16)
RELEASE OF SECURITY INTEREST REEL/FRAME 035656/0251 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: BORLAND SOFTWARE CORPORATION; ATTACHMATE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.)
Reel/Frame 062623/0009 →
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0718 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC); BORLAND SOFTWARE CORPORATION; MICRO FOCUS (US), INC.; SERENA SOFTWARE, INC; ATTACHMATE CORPORATION; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.); NETIQ CORPORATION
Reel/Frame 062746/0399 →
CORRECTIVE ASSIGNMENT TO CORRECT THE TO CORRECT TYPO IN APPLICATION NUMBER 10708121 WHICH SHOULD BE 10708021 PREVIOUSLY RECORDED ON REEL 042388 FRAME 0386. ASSIGNOR(S) HEREBY CONFIRMS THE NOTICE OF SUCCESSION OF AGENCY. Recorded Jul 26, 2018
From: BANK OF AMERICA, N.A., AS PRIOR AGENT
To: JPMORGAN CHASE BANK, N.A., AS SUCCESSOR AGENT
Reel/Frame 048793/0832 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ATTACHMATE CORPORATION; BORLAND SOFTWARE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE, INC.; ENTIT SOFTWARE LLC; ARCSIGHT, LLC; SERENA SOFTWARE, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0718 →
NOTICE OF SUCCESSION OF AGENCY Recorded May 2, 2017
From: BANK OF AMERICA, N.A., AS PRIOR AGENT
To: JPMORGAN CHASE BANK, N.A., AS SUCCESSOR AGENT
Reel/Frame 042388/0386 →
SECURITY INTEREST Recorded May 13, 2015
From: MICRO FOCUS (US), INC.; BORLAND SOFTWARE CORPORATION; ATTACHMATE CORPORATION; NETIQ CORPORATION; NOVELL, INC.
To: BANK OF AMERICA, N.A.
Reel/Frame 035656/0251 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 028252/0316 Recorded Nov 24, 2014
From: CREDIT SUISSE AG
To: NOVELL, INC.
Reel/Frame 034469/0057 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 028252/0216 Recorded Nov 24, 2014
From: CREDIT SUISSE AG
To: NOVELL, INC.
Reel/Frame 034470/0680 →
GRANT OF PATENT SECURITY INTEREST FIRST LIEN Recorded May 23, 2012
From: NOVELL, INC.
To: CREDIT SUISSE AG, AS COLLATERAL AGENT
Reel/Frame 028252/0216 →
GRANT OF PATENT SECURITY INTEREST SECOND LIEN Recorded May 23, 2012
From: NOVELL, INC.
To: CREDIT SUISSE AG, AS COLLATERAL AGENT
Reel/Frame 028252/0316 →
RELEASE OF SECURITY IN PATENTS SECOND LIEN (RELEASES RF 026275/0018 AND 027290/0983) Recorded May 22, 2012
From: CREDIT SUISSE AG, AS COLLATERAL AGENT
To: NOVELL, INC.
Reel/Frame 028252/0154 →
RELEASE OF SECURITY INTEREST IN PATENTS FIRST LIEN (RELEASES RF 026270/0001 AND 027289/0727) Recorded May 22, 2012
From: CREDIT SUISSE AG, AS COLLATERAL AGENT
To: NOVELL, INC.
Reel/Frame 028252/0077 →
GRANT OF PATENT SECURITY INTEREST (SECOND LIEN) Recorded May 13, 2011
From: NOVELL, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 026275/0018 →
GRANT OF PATENT SECURITY INTEREST Recorded May 12, 2011
From: NOVELL, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 026270/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 25, 2007
From: SENFORCE TECHNOLOGIES, INC.
To: NOVELL, INC.
Reel/Frame 020010/0387 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 11, 2006
From: BOUCHER, PETER; WRIGHT, MICHAEL; CRANNY, TIM; NAULT, GABE; SMITH, MERRILL
To: SENFORCE TECHNOLOGIES, INC.
Reel/Frame 017479/0413 →