IP Library Granted Patent US 10,592,683
Granted Patent B1
US 10,592,683 · App. 15/957,878 · Granted Mar 17, 2020

Applying an authorization policy across multiple application programs with requests submitted through an HTTP-based API

Inventors: Keng Lim (Atherton, CA); Poon Fung (Cupertino, CA)
Assignee: NextLabs, Inc.
G06F21/6218G06F16/986G06F21/604G06F16/93G06F16/9535G06F17/2229H04L67/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,592,683
App. No.
15/957,878
Granted
Mar 17, 2020
Kind
B1
Abstract

A technique and system provide protection to information or documents via an authorization policy that is applied to multiple application programs and authorization requests are submitted through a REST API over HTTP or HTTPS. Methods, techniques, and systems control access to protected information or documents and use of content in protected information or documents to support information management policies.

Claims (83)

1. A method comprising:

providing a document repository having a plurality of protected documents;

providing a policy server having a first plurality of policies, wherein the first plurality of policies controls access to the plurality of protected documents;

providing a secured viewing server having access to the document repository, wherein the secured viewing server provides access to the plurality of protected documents from a web browser;

providing a content access governor having a second plurality of policies, wherein the second plurality of policies comprises a subset of the first plurality of policies;

providing a data protection client having a third plurality of policies, wherein the data protection client has access to the document repository, wherein the third plurality of policies comprises a subset of the first plurality of policies;

at the policy server, sending a policy in the first plurality of policies to the content access governor, wherein the policy controls access to a protected document in the document repository;

at the policy server, sending the policy to the data protection client;

at a web browser, logging on to the secured viewing server by a first user;

at the web browser, opening the protected document by the first user;

at the secured viewing server, receiving a first request to open the protected document;

at the secured viewing server, sending a query to the content access governor with information relevant to the first request, wherein the secured viewing server invokes a content access governor application programming interface to send the query, wherein the information relevant to the first request comprises information about the open action, the protected document and the first user;

at the content access governor, selecting a first subset of policies from the second plurality of policies relevant to the open action, the protected document and the first user;

at the content access governor, evaluating the first subset of policies to produce a first decision on whether the first request is allowed;

at the content access governor, sending the first decision to the secured viewing server in response to the query;

at the secured viewing server, when the first request is allowed, obtaining a plurality of rights granted to the first user on the protected document from the content access governor;

at the secured viewing server, when the first request is allowed, sending the protected document to the web browser in response to the first request according to the plurality of rights granted;

at the web browser, when the first request is allowed, loading the protected document in the web browser, wherein loading the protected document implements the plurality of rights granted to the first user on the protected document;

at the secured viewing server, when the first request is not allowed, sending a message in response to the first request to the web browser indicating the first user is not allowed to open the protected document;

at the web browser, when the first request is not allowed, not rendering the protected document in the web browser;

at the data protection client, receiving a second request to open the protected document, wherein the second request comprises an open action and information about the protected document and a second user;

at the data protection client, selecting a second subset of policies from the third plurality of policies relevant to the open action, the protected document and the second user;

at the data protection client, evaluating the second subset of policies to produce a second decision on whether the second request is allowed; and

at the data protection client, responding to the second request with the second decision, wherein the second decision is used to control access to the protected document by the second user, wherein the policy is applied to control access to the protected document.

2. The method of claim 1 wherein the document repository is a file server.

3. The method of claim 1 wherein the document repository is a cloud storage.

4. The method of claim 1 wherein the data protection client is a policy enforcer.

5. The method of claim 1 wherein the data protection client is a rights management client running on a desktop computer.

6. The method of claim 1 wherein the data protection client is a rights managed application running on a mobile computing device.

7. The method of claim 1 wherein the at the web browser, opening the protected document by the first user further comprising:

presenting a list of protected documents in the web browser, wherein the list of protected documents comprises the protected documents.

8. The method of claim 1 wherein the content access governor application programming interface implements a representational state transfer style architecture.

9. The method of claim 1 wherein the content access governor application programming interface sends the query via HTTPS.

10. The method of claim 1 wherein the first subset of policies comprises the policy.

11. The method of claim 1 wherein the second subset of policies comprises the policy.

12. The method of claim 1 wherein the plurality of rights granted comprises a view right.

13. The method of claim 1 wherein the at the secured viewing server, when the first request is allowed, sending the protected document to the web browser in response to the first request according to the plurality of rights granted further comprising:

decrypting the protected document before sending content of the protected document to the web browser.

14. The method of claim 1 wherein the at the secured viewing server, when the first request is allowed, sending the protected document to the web browser in response to the first request according to the plurality of rights granted further comprising:

converting the protected document into a converted document that is in a format suitable for display in the web browser;

constructing a code fragment to modify a web browser feature, wherein modifying the web browser feature implements in part the plurality of rights granted to the first user on the protected document;

constructing a HTML document to deliver the converted document and the code fragment to the web browser; and

sending the HTML document to the web browser in response to the first request.

15. A method comprising:

providing a document repository having a plurality of protected documents;

providing a policy server having a first plurality of policies, wherein the first plurality of policies controls access to the plurality of protected documents;

providing a rights managed application running on a mobile computing device, wherein the rights managed application having a second plurality of policies, wherein the second plurality of policies comprises a subset of the first plurality of policies;

providing a rights management server having access to the document repository, wherein the rights management server provides access to the plurality of protected documents from the rights managed application;

providing a data protection client having a third plurality of policies, wherein the data protection client has access to the document repository, wherein the third plurality of policies comprises a subset of the first plurality of policies;

at the policy server, sending a policy in the first plurality of policies to the rights managed application, wherein the policy controls access to a protected document in the document repository;

at the policy server, sending the policy to the data protection client;

at the rights managed application, opening the protected document by a first user, wherein the opening the protected document invokes an open operation;

at the rights managed application, selecting a first subset of policies from the second plurality of policies relevant to the open operation, the protected document and the first user;

at the rights managed application, evaluating the first subset of policies to produce a first decision on whether the open operation is allowed;

at the rights managed application, when the open operation is allowed, analyzing the first subset of policies to produce a plurality of rights granted to the first user on the protected document;

at the rights managed application, when the open operation is allowed, opening the protected document in the rights managed application;

at the rights managed application, when the open operation is allowed,

implementing an application program feature consistent with the plurality of rights granted;

at the rights managed application, when the open operation is allowed, rendering content of the protected document on the rights managed application;

at the rights managed application, when the open operation is not allowed, denying the open operation, wherein the protected document is not opened in the rights managed application;

at the data protection client, receiving a request to open the protected document, wherein the request comprises an open action and information about the protected document and a second user;

at the data protection client, selecting a second subset of policies from the third plurality of policies relevant to the open action, the protected document and the second user;

at the data protection client, evaluating the second subset of policies to produce a second decision on whether the request is allowed; and

at the data protection client, responding to the request with the second decision, wherein the second decision is used to control access to the protected document by the second user, wherein the policy is applied to control access to the protected document.

16. The method of claim 15 wherein the document repository is a file server.

17. The method of claim 15 wherein the document repository is a cloud storage.

18. The method of claim 15 wherein the document repository is a document management system.

19. The method of claim 15 wherein the data protection client is a policy enforcer.

20. The method of claim 15 wherein the data protection client is a rights management client running on a desktop computer.

21. The method of claim 15 wherein the data protection client is a content access governor.

22. The method of claim 15 wherein the at the policy server, sending a policy in the first plurality of policies to the rights managed application, wherein the policy controls access to a protected document in the document repository further comprising:

sending the policy to the rights management by the policy server; and

sending the policy to the rights managed application by the rights management server.

23. The method of claim 15 wherein the first subset of policies comprises the policy.

24. The method of claim 15 wherein the second subset of policies comprises the policy.

25. The method of claim 15 wherein the plurality of rights granted comprises a view right.

26. The method of claim 15 wherein the at the rights managed application, when the open operation is allowed, opening the protected document in the rights managed application further comprising:

retrieving the protected document in the document repository.

27. The method of claim 15 wherein the at the rights managed application, when the open operation is allowed, opening the protected document in the rights managed application further comprising:

at the rights management server, retrieving the protected document in the document repository; and

at the rights managed application, downloading the protected document from the rights management server.

28. The method of claim 15 wherein the at the rights managed application, when the open operation is allowed, opening the protected document in the rights managed application further comprising:

decrypting the protected document to provide the rights managed application access to content of the protected document.

Assignments (1)
SECURITY AGREEMENT Recorded Jun 30, 2020
From: NEXTLABS, INC
To: ROSEBUD CAPITAL, LLC
Reel/Frame 053095/0330 →
Continuity (2)
Continuation In Part 15291653 · Oct 12, 2016
Provisional Application 62240391 · Oct 12, 2015
Cited By (200+)
US 12,192,775 US 12,192,776 US 12,192,777 US 12,192,778 US 12,200,500 US 12,207,097 US 12,212,973 US 12,212,974 US 12,219,364 US 12,219,365 US 12,225,386 US 12,231,902 US 12,231,903 US 12,231,904 US 12,231,905 US 12,231,906 US 12,238,526 US 12,238,527 US 12,245,044 US 12,245,045 US 12,245,046 US 12,250,558 US 12,250,559 US 12,256,225 US 12,256,226 US 12,256,227 US 12,256,228 US 12,262,211 US 12,262,212 US 12,262,213 US 12,262,214 US 12,262,215 US 12,262,217 US 12,267,688 US 12,267,692 US 12,273,726 US 12,273,727 US 12,273,728 US 12,273,729 US 12,273,730 US 12,273,731 US 12,273,734 US 12,279,126 US 12,279,127 US 12,284,526 US 12,284,527 US 12,284,528 US 12,287,906 US 12,289,601 US 12,289,602 US 12,289,603 US 12,289,604 US 12,294,865 US 12,294,866 US 12,294,867 US 12,299,502 US 12,302,111 US 12,302,112 US 12,302,113 US 12,302,114 US 12,302,115 US 12,302,119 US 12,307,305 US 12,309,598 US 12,309,599 US 12,309,600 US 12,309,601 US 12,309,602 US 12,309,603 US 12,309,604 US 12,309,605 US 12,309,608 US 12,317,089 US 12,317,090 US 12,317,093 US 12,323,811 US 12,323,812 US 12,323,813 US 12,323,814 US 12,323,815 US 12,328,589 US 12,328,590 US 12,328,591 US 12,328,592 US 12,335,742 US 12,335,743 US 12,342,174 US 12,348,973 US 12,348,974 US 12,348,975 US 12,348,976 US 12,353,877 US 12,363,548 US 12,363,549 US 12,363,550 US 12,369,039 US 12,369,040 US 12,369,043 US 12,375,930 US 12,375,931 US 12,375,932 US 12,375,933 US 12,382,297 US 12,382,298 US 12,382,299 US 12,382,300 US 12,382,302 US 12,382,303 US 12,386,684 US 12,389,232 US 12,389,233 US 12,395,851 US 12,395,852 US 12,395,853 US 12,395,854 US 12,395,856 US 12,395,857 US 12,401,694 US 12,402,013 US 12,402,014 US 12,405,948 US 12,413,984 US 12,425,869 US 12,425,870 US 12,432,569 US 12,432,570 US 12,432,571 US 12,437,057 US 12,439,263 US 12,439,264 US 12,439,265 US 12,439,270 US 12,445,855 US 12,445,856 US 12,445,857 US 12,445,858 US 12,452,680 US 12,452,681 US 12,452,682 US 12,452,683 US 12,452,684 US 12,452,686 US 12,457,501 US 12,464,364 US 12,464,365 US 12,464,366 US 12,464,371 US 12,470,938 US 12,470,939 US 12,470,940 US 12,470,944 US 12,477,349 US 12,481,748 US 12,483,897 US 12,483,898 US 12,490,102 US 12,490,103 US 12,490,104 US 12,490,105 US 12,495,305 US 12,495,306 US 12,495,307 US 12,498,998 US 12,501,270 US 12,501,271 US 12,501,272 US 12,501,273 US 12,501,275 US 12,507,073 US 12,507,074 US 12,507,075 US 12,507,076 US 12,511,415 US 12,513,528 US 12,520,162 US 12,526,640 US 12,531,736 US 12,536,318 US 12,538,134 US 12,543,048 US 12,549,953 US 12,549,954 US 12,549,955 US 12,562,906 US 12,563,402 US 12,563,403 US 12,563,404 US 12,563,407 US 12,568,380 US 12,574,742 US 12,574,743 US 12,574,744 US 12,574,745 US 12,574,746 US 12,574,754 US 12,574,755 US 12,581,314 US 12,581,315 US 12,581,316 US 12,587,865