IP Library Granted Patent US 8,176,562
Granted Patent B1
US 8,176,562 · App. 11/963,701 · Granted May 8, 2012

Privacy protection during remote administration

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,176,562
App. No.
11/963,701
Granted
May 8, 2012
Kind
B1
Abstract

A remote access manager protects the privacy of identified local file system content while a local computer is being accessed by a remote administrator. A local user inputs a privacy policy which identifies restricted access levels for specified files, file types and folders. During remote administration sessions, the remote access manager intercepts attempts to access the local file system, and enforces the privacy policy. Thus, the remote administrator's access to the local file system content is restricted according to the security policy.

Claims (31)

1. A computer implemented method for protecting the privacy of identified content on a local computer while the local computer is being accessed by a remote administrator, the method comprising the steps of:

running a remote administration manager on the local computer, wherein the remote administration manager is operable to automatically traverse the local computer and identify specific local computer content to which access is to be restricted in accordance with a privacy policy for the local computer, the local privacy policy being configurable by a user of the local computer;

identifying, by the remote administration manager running on the local computer, the a locally configured privacy policy for the local computer, the privacy policy specifying at least one restrictive access level to prevent at least one remote administrator with administrator level access to the local computer from accessing specific local file system content during remote administration sessions;

during at least one remote administration session by the at least one remote administrator with administrator level access to the local computer, detecting, by the remote administration manager, an attempt by the at least one remote administrator to access the specific local file system content; and

preventing, by the remote administration manager, the detected attempt by the at least one remote administrator to access the specific local file system content, thereby enforcing the local privacy policy.

2. The method of claim 1 wherein identifying a privacy policy for the local computer further comprises: receiving input from a user of the local computer specifying at least a part of the privacy policy.

3. The method of claim 1 wherein identifying a privacy policy for the local computer further comprises: automatically traversing at least a part of the local file system; and automatically identifying, by the local computer, specific local file system content to which access is to be restricted according to the privacy policy.

4. The method of claim 1 wherein identifying a privacy policy for the local computer further comprises: automatically identifying, by the local computer, specific local file system content to which access is to be restricted according to the privacy policy, the identified specific local file system content comprising at least one type from a group of types consisting of: at least one specific file, at least one specific file type, at least one specific file within at least one specifically identified folder and at least one specific file type within at least one specifically identified folder.

5. The method of claim 1 wherein identifying a privacy policy for the local computer further comprises: receiving an indication from a user of the local computer specifying at least one restrictive access level to be applied to at least some local file system content according to the privacy policy, the at least one restrictive access level being from a group consisting of: invisible, non-readable, non-executable, read-only, locked, content-masked and name-masked.

6. The method of claim 1 wherein identifying a privacy policy for the local computer further comprises: receiving an indication from a user of the local computer specifying at least one particular remote administrator for whom access to at least some file system content is to be restricted according to the privacy policy.

7. The method of claim 1 further comprising: receiving an indication from a user to override a restriction on a remote administrator's access to local file system content; and responsive to the received indication, allowing the restricted access.

8. The method of claim 1 wherein enforcing the privacy policy further comprises: intercepting attempts by the at least one remote administrator to access local file system content; and restricting the at least one remote administrator's access to local file system content according to the security policy.

9. The method of claim 1 wherein enforcing the privacy policy further comprises: prior to the at least one remote administration session by the at least one remote administrator, encrypting identified file system content; and after the at least one remote administration session by the at least one remote administrator, decrypting the identified file system content.

10. At least one non-transitory computer readable medium storing a computer program product for, when executed by a processor, protecting the privacy of identified content on a local computer while the local computer is being accessed by a remote administrator, the computer program product comprising:

program code for running a remote administration manager on the local computer, wherein the remote administration manager is operable to automatically traverse the local computer and identify specific local computer content to which access is to be restricted in accordance with a privacy policy for the local computer, the local privacy policy being configurable by a user of the local computer;

program code for identifying, by the remote administration manager running on the local computer, the a locally configured privacy policy for the local computer, the privacy policy specifying at least one restrictive access level to prevent at least one remote administrator with administrator level access to the local computer from accessing specific local file system content during remote administration sessions; program code for, during at least one remote administration session by the at least one remote administrator with administrator level access to the local computer, detecting, by the remote administration manager, an attempt by the at least one remote administrator to access the specific local file system content; and

program code for preventing, by the remote administration manager, the detected attempt by the at least one remote administrator to access the specific local file system content, thereby enforcing the local privacy policy.

11. The computer program product of claim 10 wherein the program code for identifying a privacy policy for the local computer further comprises: program code for receiving input from a user of the local computer specifying at least a part of the privacy policy.

12. The computer program product of claim 10 wherein the program code for identifying a privacy policy for the local computer further comprises: program code for automatically traversing at least a part of the local file system; and program code for automatically identifying, by the local computer, specific local file system content to which access is to be restricted according to the privacy policy.

13. The computer program product of claim 10 wherein the program code for identifying a privacy policy for the local computer further comprises: program code for automatically identifying, by the local computer, specific local file system content to which access is to be restricted according to the privacy policy, the identified specific local file system content comprising at least one type from a group of types consisting of: at least one specific file, at least one specific file type, at least one specific file within at least one specifically identified folder and at least one specific file type within at least one specifically identified folder.

14. The computer program product of claim 10 wherein the program code for identifying a privacy policy for the local computer further comprises: program code for receiving an indication from a user of the local computer specifying at least one restrictive access level to be applied to at least some local file system content according to the privacy policy, the at least one restrictive access level being from a group consisting of: invisible, non-readable, non-executable, read-only, locked, content-masked and name-masked.

15. The computer program product of claim 10 wherein the program code for identifying a privacy policy for the local computer further comprises: program code for receiving an indication from a user of the local computer specifying at least one particular remote administrator for whom access to at least some file system content is to be restricted according to the privacy policy.

16. The computer program product of claim 10 further comprising: program code for receiving an indication from a user to override a restriction on a remote administrator's access to local file system content; and program code for responsive to the received indication, allowing the restricted access.

17. The computer program product of claim 10 wherein the program code for enforcing the privacy policy further comprises: program code for intercepting attempts by the at least one remote administrator to access local file system content; and program code for restricting the at least one remote administrator's access to local file system content according to the security policy.

18. The computer program product of claim 10 wherein the program code for enforcing the privacy policy further comprises: program code for, prior to the at least one remote administration session by the at least one remote administrator, encrypting identified file system content; and program code for, after the at least one remote administration session by the at least one remote administrator, decrypting the identified file system content.

19. A computer system for protecting the privacy of identified local content while the computer system is being accessed by a remote administrator, the computer system comprising:

means for running a remote administration manager on the local computer, wherein the remote administration manager is operable to automatically traverse the local computer and identify specific local computer content to which access is to be restricted in accordance with a privacy policy for the local computer, the local privacy policy being configurable by a user of the local computer;

means for identifying, by the remote administration manager running on the local computer, the a locally configured privacy policy for the local computer, the privacy policy specifying at least one restrictive access level to prevent at least one remote administrator with administrator level access to the local computer from accessing specific local file system content during remote administration sessions;

means for, during at least one remote administration session by the at least one remote administrator with administrator level access to the local computer, detecting, by the remote administration manager, an attempt by the at least one remote administrator to access the specific local file system content; and

means for preventing, by the remote administration manager, the detected attempt by the at least one remote administrator to access the specific local file system content, thereby enforcing the local privacy policy.

20. The computer system of claim 19 wherein the means for enforcing the privacy policy further comprise: means for intercepting attempts by the at least one remote administrator to access local file system content; and means for restricting the at least one remote administrator's access to local file system content according to the security policy.

Assignments (5)
NOTICE OF SUCCESSION OF AGENCY (REEL 050926 / FRAME 0560) Recorded Sep 13, 2022
From: JPMORGAN CHASE BANK, N.A.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 061422/0371 →
SECURITY AGREEMENT Recorded Sep 13, 2022
From: NORTONLIFELOCK INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062220/0001 →
CHANGE OF NAME Recorded Jun 18, 2020
From: SYMANTEC CORPORATION
To: NORTONLIFELOCK INC.
Reel/Frame 053306/0878 →
SECURITY AGREEMENT Recorded Nov 4, 2019
From: SYMANTEC CORPORATION; BLUE COAT LLC; LIFELOCK, INC,; SYMANTEC OPERATING CORPORATION
To: JPMORGAN, N.A.
Reel/Frame 050926/0560 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 5, 2008
From: HERNACKI, BRIAN; SATISH, SOURABH; BROWN, TIMOTHY G.
To: SYMANTEC CORPORATION
Reel/Frame 020467/0946 →