IP Library Granted Patent US 8,863,305
Granted Patent B2
US 8,863,305 · App. 12/552,927 · Granted Oct 14, 2014

File-access control apparatus and program

Inventors: Koji Okada (Tokyo, JP); Tatsuro Ikeda (Fuchu, JP); Masataka Yamada (Fuchu, JP); Minoru Nishizawa (Fuchu, JP); Takanori Nakamizo (Chofu, JP); Toshio Okamoto (Tokyo, JP)
Assignees: Kabushiki Kaisha Toshiba; Toshiba Solutions Corporation
G06F21/6209G06F21/31H04L2463/101
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,863,305
App. No.
12/552,927
Granted
Oct 14, 2014
Kind
B2
Abstract

In a file-access control system according to an embodiment of this invention, control data in accordance with actions made is imparted, as an obligation-type policy, to a document file. Next, a policy evaluation control unit evaluates and executes the obligation-type policy imparted to the document file in accordance with the action to the document file. The execution of the obligation-type policy includes the controlling of a document application on the basis of an obligation fulfillment action. Therefore, an active control can be performed in accordance with any manipulation made to the document, and the access to the document can be changed.

Claims (58)

1. A file-access control apparatus designed to control accesses to a document file, comprising:

a storage device capable of storing document contents, each including an inhibition-type policy and an obligation-type policy;

an evaluation controller;

a document application controller;

a decryption/signature verification controller;

an event controller;

an authentication server; and

an external service controller;

wherein the decryption/signature verification controller determines whether a document content and access control policy has been encrypted or contains a digital signature, the decryption/signature verification controller decrypts the document content using key data if the content is encrypted or verify the digital signature using a verification key if it contains the digital signature;

wherein the event controller send the event data and the document file to the evaluation-data acquisition device, after determining legitimacy of the document content;

wherein the evaluation controller includes:

an evaluation data acquisition device configured to acquire document content and executability data items from the event controller, the document application controller and the external service controller, respectively, and to hold the executability data items, the executability data items being status executability data of the document application controller and the external service controller, the evaluation data acquisition device further send a user authentication request to the authentication server to authenticate an end-user;

an authentication-result acquisition device configured to acquire a result of authentication of the user and user attribute data, on the basis of a prescribed evaluation data list, upon receiving, from the document application controller, event data representing an action made by the user and a document file stored in the storage device;

a sending device configured to send evaluation data composed of the executability data, the result of authentication and user attribute data, the event data, the inhibition-type policy, and the obligation-type policy on the basis of a prescribed evaluation data list, upon receiving the executability data from the executability data acquisition means;

a comparing device configured to compare the authentication result, user attribute data and event data, all included in the evaluation data sent, respectively with the authentication result, user attribute data and event data, all prescribed in the inhibition-type policy, and for sending evaluation result showing the permission or inhibition prescribed in the inhibition-type policy, when the items included in the evaluation data are identical to the items included in the inhibition-type policy;

an obligation-type policy evaluation control device for comparing the executability data, event data and evaluation result, all included in the valuation data, with the executability data, event data and evaluation result, all included in the obligation-type policy, and for sending control data including an obligation fulfillment subject and an obligation fulfillment action prescribed in the obligation-type policy, when the items included in the evaluation data are identical to the items included in the obligation-type policy;

a control management device for sending the control data to a subject represented by the obligation fulfillment subject upon receiving the control data, on the basis of the obligation fulfillment subject included in the control data; and

a document-application control device for controlling the document application controller, on the basis of the obligation fulfillment action included in the control data sent from the control management device when the represented subject is the document-application control device, and

wherein the executability data indicates whether the document application controller and the external service controller can be controlled or cannot be controlled in accordance with whether the document application controller operates and the external service trait controller is in service.

2. The file-access control apparatus according to claim 1 , wherein the policy evaluation control device further includes a policy changing device for changing the inhibition-type policy or the obligation-type policy, stored in the storage device, on the basis of the obligation fulfillment action included in the control data sent from the control management device when the represented subject is the policy changing device.

3. The file-access control apparatus according to claim 2 , wherein the policy evaluation control device further includes an external service control device for controlling the external service controller on the basis of the obligation fulfillment action included in the control data sent from the control management device when the represented subject is the external service control device.

4. The file-access control apparatus according to claim 1 , wherein the policy evaluation control device further includes an external service control device for controlling the external service controller on the basis of the obligation fulfillment action included in the control data sent from the control management device.

5. A file-access control apparatus designed to control accesses to a document file, comprising:

a storage device capable of storing document contents, each including an inhibition-type policy and an obligation-type policy;

an evaluation controller;

a document application controller;

a decryption/signature verification controller;

an event controller;

an authentication server; and

an external service controller,

wherein the decryption/signature verification controller determines whether a document content and access control policy has been encrypted or contains a digital signature, the decryption/signature verification controller decrypts the document content using key data if the content is encrypted or verify the digital signature using a verification key if it contains the digital signature;

wherein the event controller send the event data and the document file to the evaluation- data acquisition device, after determining legitimacy of the document content;

wherein the evaluation controller includes:

an evaluation data acquisition device configured to acquire document content and executability data items from the event controller, the document application controller and the external service controller, respectively, and to hold the executability data items, the executability data items being executability data of the document application controller and the external service controller, the evaluation data acquisition device further send a user authentication request to the authentication server to authenticate an end-user;

an authentication-result acquisition device configured to acquire a result of authentication of the user and user attribute data, on the basis of a prescribed evaluation data list, upon receiving, from the document application controller, event data representing an action made by the user and a document file stored in the storage device;

a sending device configured to send evaluation data composed of the executability data, the result of authentication and user attribute data, the event data, the inhibition-type policy, and the obligation-type policy on the basis of a prescribed evaluation data list, upon receiving the executability data from the executability data acquisition device;

a comparing device configured to compare the authentication result, user attribute data and event data, all included in the evaluation data sent, respectively with the authentication result, user attribute data and event data, all prescribed in the inhibition-type policy, and to send evaluation result showing the permission or inhibition prescribed in the inhibition-type policy, when the items included in the evaluation data are identical to the items included in the inhibition-type policy;

an obligation-type policy evaluation control device configured to compare the executability data, event data and evaluation result, all included in the valuation data, with the executability data, event data and evaluation result, all included in the obligation-type policy, and to send control data including an obligation fulfillment subject and an obligation fulfillment action prescribed in the obligation-type policy, when the items included in the evaluation data are identical to the items included in the obligation-type policy;

a control management device configured to send the control data to a subject represented by the obligation fulfillment subject upon receiving the control data, on the basis of the obligation fulfillment subject included in the control data; and

a document-application control device configured to control the document application controller, on the basis of the obligation fulfillment action included in the control data sent from the control management device when the represented subject is the document-application control device, and

wherein the executability data indicates whether the document application controller and the external service controller can be controlled or cannot be controlled in accordance with whether the document application controller operates and the external service controller is in service.

6. The file-access control apparatus according to claim 5 , wherein the policy evaluation control device further includes a policy changing device configured to change the inhibition-type policy or the obligation-type policy, either stored in the storage device, on the basis of the obligation fulfillment action included in the control data sent from the control management device when the represented subject is the policy changing device.

7. The file-access control apparatus according to claim 6 , wherein the policy evaluation control device further includes an external service control device configured to control the external service controller on the basis of the obligation fulfillment action included in the control data sent from the control management device when the represented subject is the external service control device.

8. The file-access control apparatus according to claim 5 , wherein the policy evaluation control device further includes an external service control device configured to control the external service controller on the basis of the obligation fulfillment action included in the control data sent from the control management device.

9. A non-transitory computer-readable medium storing computer readable instructions thereon which when executed by a file-access control apparatus, having a storage device that stores a document file including a document content, an inhibition-type policy, an obligation-type policy, a document application controller, a decryption/signature verification controller, an event controller, an authentication server, and an external service controller and which is configured to control access to the document file, cause the file-access control apparatus to perform a method comprising:

the decryption/signature verification controller determines whether a document content and access control policy has been encrypted or contains a digital signature, the decryption/signature verification controller decrypts the document content using key data if the content is encrypted or verify the digital signature using a verification key if it contains the digital signature;

the event controller send the event data and the document file to an evaluation-data acquisition device, after determining legitimacy of the document content;

acquiring document content and executability data items from the event controller, the document application controller and the external service controller, respectively, and holding the executability data items, the executability data items being executability data of the document application controller and the external service controller, the evaluation data acquisition device further send a user authentication request to the authentication server to authenticate an end-user;

acquiring result of authentication of the user and user attribute data, on the basis of a prescribed evaluation data list, upon receiving, from the document application controller, event data representing an action made by the user and a prescribed document file;

sending evaluation data composed of the executability data, result of authentication and user attribute data, the event data, the inhibition-type policy, and the obligation-type policy on the basis of a prescribed evaluation data list, upon receiving the executability data from an executability data acquisition controller;

comparing the authentication result, user attribute data and event data, all included in the evaluation data sent, respectively with the authentication result, user attribute data and event data, all prescribed in the inhibition-type policy, and sending evaluation result showing the permission or inhibition prescribed in the inhibition-type policy, when the items included in the evaluation data are identical to the items included in the inhibition-type policy;

comparing the executability data, event data and evaluation result, all included in the valuation data, with the executability data, event data and evaluation result, all included in the obligation-type policy, and sending control data including an obligation fulfillment subject and an obligation fulfillment action prescribed in the obligation-type policy, when the items included in the evaluation data are identical to the items included in the obligation-type policy;

sending the control data to a subject represented by the obligation fulfillment subject upon receiving the control data, on the basis of the obligation fulfillment subject included in the control data; and

controlling the document application controller, on the basis of the obligation fulfillment action included in the control data sent when the represented subject is the document-application controlling,

wherein the executability data indicates whether the document application controller and the external service controller can be controlled or cannot be controlled in accordance with whether the document application controller operates and the external service controller is in service.

10. The file-access control apparatus according to claim 2 , wherein

the obligation fulfillment subject identifies either the document application controller or the external service controller, and

the executability data items indicate whether the document-application control device or the external service control device can control the obligation fulfillment subject.

Assignments (5)
CHANGE OF CORPORATE NAME AND ADDRESS Recorded Feb 8, 2021
From: TOSHIBA SOLUTIONS CORPORATION
To: TOSHIBA DIGITAL SOLUTIONS CORPORATION
Reel/Frame 055259/0587 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY'S ADDRESS PREVIOUSLY RECORDED ON REEL 048547 FRAME 0098. ASSIGNOR(S) HEREBY CONFIRMS THE CHANGE OF ADDRESS. Recorded May 28, 2019
From: TOSHIBA SOLUTIONS CORPORATION
To: TOSHIBA SOLUTIONS CORPORATION
Reel/Frame 051297/0742 →
CHANGE OF ADDRESS Recorded Mar 8, 2019
From: TOSHIBA SOLUTIONS CORPORATION
To: TOSHIBA SOLUTIONS CORPORATION
Reel/Frame 048547/0098 →
CHANGE OF NAME Recorded Mar 8, 2019
From: TOSHIBA SOLUTIONS CORPORATION
To: TOSHIBA DIGITAL SOLUTIONS CORPORATION
Reel/Frame 048547/0215 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 30, 2009
From: OKADA, KOJI; IKEDA, TATSURO; YAMADA, MASATAKA; NISHIZAWA, MINORU; NAKAMIZO, TAKANORI; OKAMOTO, TOSHIO
To: KABUSHIKI KAISHA TOSHIBA; TOSHIBA SOLUTIONS CORPORATION
Reel/Frame 023448/0425 →
Priority Claims (1)
JP 2007-280800 · Oct 29, 2007 · national
Continuity (2)
Continuation PCTJP2008069671 · Oct 29, 2008
Related Publication 20100043070A1 · Feb 18, 2010