METHOD AND APPARATUS FOR PROVIDING RIGHTS MANAGEMENT AT FILE SYSTEM LEVEL
An approach is presented for providing rights management at file system level. A virtual file system rights management application receives a request to access a protected file. The rights management application binds the access request to the protected file in the file system, determines credentials associated with the request for accessing the protected file according to the binding and causes, at least in part, verification of the credentials according to a rights management system associated with the protected file. Based, at least in part, on the determination, the rights management application causes decryption of the protected content.
1 . A method comprising:
receiving a request at a file system to access a protected file;
binding the access request to the protected file in the file system;
determining credentials associated with the request for accessing the protected file according to the binding;
causing, at least in part, verification of the credentials according to a rights management system associated with the protected file; and
causing, at least in part, decryption of the protected file based, at least in part, on the verification.
2 . A method of claim 1 , wherein the request is received from an application, a loader, a system process, or a combination thereof, the method further comprising:
causing, at least in part, transfer of decrypted content from the protected file to the application, the loader, the system process, or the combination thereof.
3 . A method of claim 1 , further comprising:
initiating a rights management application,
wherein the rights management application verifies the credentials and causes decryption of the protected file based, at least on the verification.
4 . A method of claim 1 , further comprising:
determining whether the verification of the credentials has failed; and
returning an error status based, at least in part, on the failure.
5 . A method of claim 1 , wherein the rights management system is hardware-based, software-based, or a combination thereof.
6 . A method of claim 1 , wherein the file system is a virtual file system.
7 . A method of claim 1 , wherein the protected file is a data file, an executable file, or a combination thereof.
8 . A method of claim 1 , further comprising:
storing decrypted content of the protected file in a buffer; and
providing access to the buffer in response to the request.
9 . An apparatus comprising:
at least one processor; and
at least one memory including computer program code,
the at least one memory and the computer program code configured to, with the at least one processor, cause the apparatus to perform at least the following,
receive a request at a file system to access a protected file;
bind the access request to the protected file in the file system;
determine credentials associated with the request for accessing the protected file according to the binding;
cause, at least in part, verification of the credentials according to a rights management system associated with the protected file; and
cause, at least in part, decryption of the protected file based, at least in part, on the verification.
10 . An apparatus of claim 9 , wherein the request is received from an application, a loader, a system process, or a combination thereof, the apparatus is further caused to:
cause, at least in part, transfer of decrypted content from the protected file to the application, the loader, the system process, or the combination thereof.
11 . An apparatus of claim 9 , wherein the apparatus is further caused to:
initiate a rights management application,
wherein the rights management application verifies the credentials and causes decryption of the protected file based, at least on the verification.
12 . An apparatus of claim 9 , wherein the apparatus is further caused to:
determine whether the verification of the credentials has failed; and
return an error status based, at least in part, on the failure.
13 . An apparatus of claim 9 , wherein the rights management system is hardware-based, software-based, or a combination thereof.
14 . An apparatus of claim 9 , wherein the file system is a virtual file system.
15 . An apparatus of claim 9 , wherein the protected file is a data file, an executable file, or a combination thereof.
16 . An apparatus of claim 9 , wherein the apparatus is further caused to:
store decrypted content of the protected file in a buffer; and
provide access to the buffer in response to the request.
17 . A computer-readable storage medium carrying one or more sequences of one or more instructions which, when executed by one or more processors, cause an apparatus to at least perform the following steps:
receive a request at a file system to access a protected file;
bind the access request to the protected file in the file system;
determine credentials associated with the request for accessing the protected file according to the binding;
cause, at least in part, verification of the credentials according to a rights management system associated with the protected file; and
cause, at least in part, decryption of the protected file based, at least in part, on the verification.
18 . A computer-readable storage medium of claim 17 , wherein the apparatus is caused, at least in part, to further perform:
cause, at least in part, transfer of decrypted content from the protected file to the application, the loader, the system process, or the combination thereof.
19 . A computer-readable storage medium of claim 17 , wherein the apparatus is caused, at least in part, to further perform:
initiate a rights management application,
wherein the rights management application verifies the credentials and causes decryption of the protected file based, at least on the verification.
20 . A computer-readable storage medium of claim 17 , wherein the apparatus is caused, at least in part, to further perform:
determine whether the verification of the credentials has failed; and
return an error status based, at least in part, on the failure.