IP Library Granted Patent US 9,165,160
Granted Patent B1
US 9,165,160 · App. 14/176,895 · Granted Oct 20, 2015

System for and methods of controlling user access and/or visibility to directories and files of a computer

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,165,160
App. No.
14/176,895
Granted
Oct 20, 2015
Kind
B1
Abstract

A system includes a file access manager driver and a kernel file system driver stack in a kernel-mode address space of an operating system (OS). The system also includes session processes, a public file whitelist; a public file whitelist manager; a user/group file whitelist, which is a private whitelist; and a user/group file whitelist manager in a user-mode address space of the OS. A method includes receiving a request for access and/or visibility to a directory and/or file and then determining whether the request is allowed to execute based on whether the file access manager driver identifies that the directory and/or file is allowed in either public or private whitelists.

Claims (31)

1. A method for controlling user access to directories and files of a computer, the method comprising:

storing a plurality of file whitelists in memory, wherein each file whitelist identifies one or more users and one or more files accessible by the users;

executing instructions stored in memory, wherein execution of the instructions by a processor:

determines that an administrator has performed an act of publishing one or more previously unpublished files, wherein the act of publishing specifies that the previously unpublished files are to be published to one or more users, and

identifies which of the plurality of file whitelists are associated with the specified users; and

automatically adding, based on the act of publishing to the specified users, the previously unpublished files to one or more file whitelists identified as being associated with the specified users, wherein the identified file whitelists are updated with the previously unpublished files.

2. The method of claim 1 , wherein the stored file whitelists comprise file whitelists specific to a single user.

3. The method of claim 1 , wherein the stored file whitelists comprise file whitelists specific to a group of one or more users.

4. The method of claim 1 , wherein the stored file whitelists comprise a public file whitelist that identifies files accessible to all users.

5. The method of claim 1 , wherein the stored file whitelists comprise at least one file whitelist that identifies the associated one or more files as a directory of files.

6. The method of claim 1 , wherein the stored file whitelists comprise at least one file whitelist that identifies the associated one or more files by reference to a blacklist of restricted files, wherein the associated one or more files are identified as files not on the blacklist.

7. The method of claim 1 , wherein the specified one or more users are identified by reference to a group of one or more users, and wherein the identified file whitelists are specific to the group.

8. The method of claim 7 , further comprising identifying file whitelists specific to each user in the group and automatically adding the previously unpublished files to the identified file whitelists specific to each user in the group.

9. An apparatus for controlling user access to directories and files of a computer, the apparatus comprising:

memory for storing a plurality of file whitelists, wherein each file whitelist identifies one or more users and one or more files accessible by the users;

a processor for executing instructions stored in memory, wherein execution of the instructions by the processor:

determines that an administrator has performed an act of publishing one or more previously unpublished files, wherein the act of publishing specifies that the previously unpublished files are to be published to one or more users, and

identifies which of the plurality of file whitelists are associated with the specified users,

wherein the one or more file whitelists identified as being associated with the specified users stored in memory are updated by automatic addition, based on the act of publishing to the specified users, of the previously unpublished files.

10. The apparatus of claim 9 , wherein the stored file whitelists comprise file whitelists specific to a single user.

11. The apparatus of claim 9 , wherein the stored file whitelists comprise file whitelists specific to a group of one or more users.

12. The apparatus of claim 9 , wherein the stored file whitelists comprise a public file whitelist that identifies files accessible to all users.

13. The apparatus of claim 9 , wherein the stored file whitelists comprise at least one file whitelist that identifies the associated one or more files as a directory of files.

14. The apparatus of claim 9 , wherein the stored file whitelists comprise at least one file whitelist that identifies the associated one or more files by reference to a blacklist of restricted files, wherein the associated one or more files are identified as files not on the blacklist.

15. The apparatus of claim 9 , wherein the specified one or more users are identified by reference to a group of one or more users, and wherein the identified file whitelists are specific to the group.

16. The apparatus of claim 15 , wherein the processor executes further instructions to identify file whitelists specific to each user in the group and automatically add the previously unpublished files to the identified file whitelists specific to each user in the group.

17. A non-transitory computer-readable storage medium, having embodied thereon a program executable by a processor to perform a method for controlling user access to directories and files of a computer, the method comprising:

storing a plurality of file whitelists, wherein each file whitelist identifies one or more users and one or more files accessible by the users;

determining that an administrator has performed an act of publishing one or more previously unpublished files, wherein the act of publishing specifies that the previously unpublished files are to be published to one or more users;

identifying which of the plurality of file whitelists are associated with the specified users; and

automatically adding, based on the act of publishing to the specified users, the previously unpublished files to one or more file whitelists identified as being associated with the specified users, wherein the identified file whitelists are updated with the previously unpublished files.

Assignments (5)
RELEASE OF LIEN ON PATENTS Recorded Aug 5, 2024
From: BARINGS FINANCE LLC
To: RPX CORPORATION
Reel/Frame 068328/0278 →
PATENT SECURITY AGREEMENT Recorded May 13, 2021
From: RPX CORPORATION
To: BARINGS FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 056241/0453 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 1, 2021
From: HOPTO, INC.
To: RPX CORPORATION
Reel/Frame 055795/0700 →
CHANGE OF NAME Recorded Jun 24, 2015
From: GRAPHON CORPORATION
To: HOPTO INC.
Reel/Frame 036010/0945 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 10, 2014
From: TIDD, WILLIAM
To: GRAPHON CORPORATION
Reel/Frame 032187/0301 →