IP Library Granted Patent US 10,382,488
Granted Patent B1
US 10,382,488 · App. 15/237,087 · Granted Aug 13, 2019

Systems and methods for enforcing access-control policies

Inventors: Lei Gu (Bedford, MA); Keith Newstadt (West Newton, MA)
Assignee: Symantec Corporation
H04L63/20H04L63/102H04L65/4084H04L2463/101
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,382,488
App. No.
15/237,087
Granted
Aug 13, 2019
Kind
B1
Abstract

A computer-implemented method for enforcing access-control policies may include (i) identifying streaming content that is being transmitted from a media server to a media playback system, (ii) determining that a supervised user is within exposure range of the media playback system and could be exposed to the streaming content, (iii) receiving a sample of the content from a sampling system that is remote from the media playback system, (iv) identifying an access-control policy that defines a content-access restriction for the supervised user, (v) determining, based on an analysis of the sample of the content, that the access-control policy applies to the content, and (vi) in response to determining that the access-control policy applies to the content, enforcing the access-control policy by applying the content-access restriction to the streaming content. Various other methods, systems, and computer-readable media are also disclosed.

Claims (93)

1. A computer-implemented method for enforcing access-control policies, at least a portion of the method being performed by a computing device comprising at least one processor, the method comprising:

identifying, by the computing device, streaming content that is being transmitted from a media server to a media playback system;

determining, by the computing device, that a supervised user is within exposure range of the media playback system, and thereby determining that the supervised user is within exposure range of the streaming content;

receiving, by the computing device, a sample of the content from a sampling system that:

is within the exposure range of the media playback system;

is physically separated from the media playback system; and

samples the content being transmitted from the media server to the media playback system;

identifying, by the computing device, an access-control policy that defines a content-access restriction for the supervised user;

determining, based on an analysis of the sample of the content by the computing device, that the access-control policy applies to the content; and

in response to determining that the access-control policy applies to the content, enforcing the access-control policy by applying the content-access restriction to the streaming content.

2. The method of claim 1 , wherein determining that the supervised user is within the exposure range of the media playback system comprises at least one of:

identifying the supervised user by collecting biometric information;

receiving identifying information of the supervised user from a networked device;

receiving login information of the supervised user from the media playback system;

detecting a device that belongs to the supervised user; and

determining that a location of the supervised user is within the exposure range.

3. The method of claim 2 , wherein determining that the location of the supervised user is within the exposure range comprises at least one of:

using a motion sensor to detect the location of the supervised user; and

determining that a location of the device that belongs to the supervised user is within the exposure range.

4. The method of claim 1 , wherein receiving the sample of the content from the sampling system comprises:

determining the sampling system is within the exposure range of the media playback system by receiving, from the sampling system, information indicating that the sampling system has detected playback of the content;

instructing the sampling system to sample the content; and

correlating the received sample with the content.

5. The method of claim 1 , wherein determining that the access-control policy applies to the content comprises matching the sample of the content to a known content.

6. The method of claim 1 , wherein determining that the access-control policy applies to the content comprises:

converting the sample of the content to textual data; and

performing a content analysis on the textual data.

7. The method of claim 6 , wherein performing the content analysis on the textual data comprises at least one of:

text mining the textual data for patterns;

categorizing the patterns into at least one content category; and

determining that the access-control policy applies to the content category.

8. The method of claim 1 , wherein enforcing the access-control policy comprises at least one of:

preventing transmission of the content from the media server to the media playback system; and

alerting an administrator that the supervised user is within the exposure range of the streaming content.

9. A system for enforcing access-control policies, the system comprising:

at least one memory device that stores one or more computer-readable instructions; and

a computing device comprising at least one hardware processor that executes the one or more computer-readable instructions to:

identify, by a computing device, streaming content that is being transmitted from a media server to a media playback system;

determine, by the computing device, that a supervised user is within exposure range of the media playback system, and thereby determining that the supervised user is within exposure range of the streaming content;

receive, by the computing device, a sample of the content from a sampling system that:

is within the exposure range of the media playback system;

is physically separated from the media playback system; and

samples the content being transmitted from the media server to the media playback system;

identify, by the computing device, an access-control policy that defines a content-access restriction for the supervised user;

determine, based on an analysis of the sample of the content by the computing device, that the access-control policy applies to the content; and

in response to determining that the access-control policy applies to the content, enforce the access-control policy by applying the content-access restriction to the streaming content.

10. The system of claim 9 , wherein the hardware processor executes the one or more computer-readable instructions to determine that the supervised user is within the exposure range of the media playback system by at least one of:

identifying the supervised user by collecting biometric information;

receiving identifying information of the supervised user from a networked device;

receiving login information of the supervised user from the media playback system;

detecting a device that belongs to the supervised user; and

determining that a location of the supervised user is within the exposure range.

11. The system of claim 10 , wherein determining that the location of the supervised user is within the exposure range comprises at least one of:

using a motion sensor to detect the location of the supervised user; and

determining that a location of the device that belongs to the supervised user is within the exposure range.

12. The system of claim 9 , wherein the hardware processor executes the one or more computer-readable instructions to receive the sample of the content from the sampling system by:

determining the sampling system is within the exposure range of the media playback system by receiving, from the sampling system, information indicating that the sampling system has detected playback of the content;

instructing the sampling system to sample the content; and

correlating the received sample with the content.

13. The system of claim 9 , wherein the hardware processor executes the one or more computer-readable instructions to determine that the access-control policy applies to the content by matching the sample of the content to a known content.

14. The system of claim 9 , wherein the hardware processor executes the one or more computer-readable instructions to determine that the access-control policy applies to the content by:

converting the sample of the content to textual data; and

performing a content analysis on the textual data.

15. The system of claim 14 , wherein performing the content analysis on the textual data comprises at least one of:

text mining the textual data for patterns;

categorizing the patterns into at least one content category; and

determining that the access-control policy applies to the content category.

16. The system of claim 9 , wherein the hardware processor executes the one or more computer-readable instructions to enforce the access-control policy by at least one of:

preventing transmission of the content from the media server to the media playback system; and

alerting an administrator that the supervised user is within the exposure range of the streaming content.

17. A non-transitory computer-readable medium comprising one or more computer-executable instructions that, when executed by at least one processor of a computing device, cause the computing device to:

identify, by the computing device, streaming content that is being transmitted from a media server to a media playback system;

determine, by the computing device, that a supervised user is within exposure range of the media playback system, and thereby determine that the supervised user is within exposure range of the streaming content;

receive, by the computing device, a sample of the content from a sampling system that:

is within the exposure range of the media playback system;

is physically separated from the media playback system; and

samples the content being transmitted from the media server to the media playback system;

identify, by the computing device, an access-control policy that defines a content-access restriction for the supervised user;

determine, based on an analysis of the sample of the content by the computing device, that the access-control policy applies to the content; and

in response to determining that the access-control policy applies to the content, enforce the access-control policy by applying the content-access restriction to the streaming content.

18. The non-transitory computer-readable medium of claim 17 , wherein the computer-executable instructions cause the computing device to determine that the supervised user is within the exposure range of the media playback system by at least one of:

identifying the supervised user by collecting biometric information;

receiving identifying information of the supervised user from a networked device;

receiving login information of the supervised user from the media playback system;

detecting a device that belongs to the supervised user; and

determining that a location of the supervised user is within the exposure range.

19. The non-transitory computer-readable medium of claim 18 , wherein determining that the location of the supervised user is within the exposure range comprises at least one of:

using a motion sensor to detect the location of the supervised user; and

determining that a location of the device that belongs to the supervised user is within the exposure range.

20. The non-transitory computer-readable medium of claim 17 , wherein the computer-executable instructions cause the computing device to receive the sample of the content from the sampling system by:

determining the sampling system is within the exposure range of the media playback system by receiving, from the sampling system, information indicating that the sampling system has detected playback of the content;

instructing the sampling system to sample the content; and

correlating the received sample with the content.

Assignments (6)
CHANGE OF NAME Recorded Feb 6, 2023
From: NORTONLIFELOCK INC.
To: GEN DIGITAL INC.
Reel/Frame 062714/0605 →
NOTICE OF SUCCESSION OF AGENCY (REEL 050926 / FRAME 0560) Recorded Sep 13, 2022
From: JPMORGAN CHASE BANK, N.A.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 061422/0371 →
SECURITY AGREEMENT Recorded Sep 13, 2022
From: NORTONLIFELOCK INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062220/0001 →
CHANGE OF NAME Recorded Feb 14, 2020
From: SYMANTEC CORPORATION
To: NORTONLIFELOCK INC.
Reel/Frame 051935/0228 →
SECURITY AGREEMENT Recorded Nov 4, 2019
From: SYMANTEC CORPORATION; BLUE COAT LLC; LIFELOCK, INC,; SYMANTEC OPERATING CORPORATION
To: JPMORGAN, N.A.
Reel/Frame 050926/0560 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2016
From: GU, LEI; NEWSTADT, KEITH
To: SYMANTEC CORPORATION
Reel/Frame 039436/0691 →