IP Library Granted Patent US 12,284,225
Granted Patent B2
US 12,284,225 · App. 16/553,057 · Granted Apr 22, 2025

Context-aware content object security

Inventors: Alok Ojha (Newark, CA); Sivaramakrishnan Subramanian (San Jose, CA); Kechen Huang (Menlo Park, CA)
Assignee: Box, Inc.
H04L63/205H04L63/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,284,225
App. No.
16/553,057
Granted
Apr 22, 2025
Kind
B2
Abstract

As a default, a global permissions model is established. The global permissions model serves for applying a first set of resource access permissions to shared content objects. Additionally, a set of context-aware access policies that govern user interactions over the shared content object is established. When a particular user requests an interaction over a shared content object, then interaction attributes associated with the request are gathered. The context-aware access policies are applied to the request by determining a set of extensible access permissions that are derived from the interaction attributes. The context-aware access policies are enforced by overriding the first set of resource access permissions with dynamically-determined access permissions. When a particular access request is denied, a response is generated in accordance with the set of extensible access permissions and the user is notified. In some cases, the access request is permitted, but only after the user provides a justification.

Claims (40)

1. A method for context-aware content object security, the method comprising:

applying a first set of resource access permissions to a shared content object;

maintaining one or more context-aware access policies that govern user interactions over the shared content object;

gathering one or more interaction attributes associated with a particular user interaction over the shared content object;

applying the one or more context-aware access policies to the one or more interaction attributes to determine and store, in computer memory, a set of extensible access permissions associated with the particular user interaction over the shared content object; and

overriding the first set of resource access permissions to the shared content object with the set of extensible access permissions retrieved from the computer memory and associated with the particular user interaction over the shared content object, in response to a determination that the set of extensible access permissions conflicts with the first set of resource access permissions.

2. The method of claim 1 , further comprising:

generating a response to the particular user interaction, the response being generated in accordance with the set of extensible access permissions.

3. The method of claim 2 , wherein the response corresponds to at least one of taking no action, allowing an interaction, allowing the interaction with a justification, or blocking the interaction.

4. The method of claim 3 , wherein at least a portion of the response is presented to a user at a user interface.

5. The method of claim 1 , wherein the one or more context-aware access policies comprise extensible permissions rules.

6. The method of claim 5 , wherein the extensible permissions rules are evaluated against at least a portion of the one or more interaction attributes to determine the set of extensible access permissions.

7. The method of claim 1 , wherein a context associated with the particular user interaction is characterized by one or more of the one or more interaction attributes, wherein the one or more interaction attributes are retrieved by parsing an interaction event message received in response to the particular user interaction over the shared content object.

8. The method of claim 1 , wherein the one or more interaction attributes comprise at least one of one or more event attributes, one or more object attributes, or one or more user attributes.

9. The method of claim 1 , wherein at least one of the one or more context-aware access policies is specified by a user at a user interface.

10. A non-transitory computer readable medium having stored thereon a sequence of instructions which, when stored in memory and executed by one or more processors causes the one or more processors to perform a set of acts for context-aware content object security, the set of acts comprising:

applying a first set of resource access permissions to a shared content object;

maintaining one or more context-aware access policies that govern user interactions over the shared content object;

gathering one or more interaction attributes associated with a particular user interaction over the shared content object;

applying the one or more context-aware access policies to the one or more interaction attributes to determine and store, in computer memory, a set of extensible access permissions associated with the particular user interaction over the shared content object; and

overriding at least some of the first set of resource access permissions to the shared content object with the set of extensible access permissions retrieved from the computer memory and associated with the particular user interaction over the shared content object, in response to a determination that the set of extensible access permissions conflict with the first set of resource access permissions.

11. The non-transitory computer readable medium of claim 10 , further comprising instructions which, when stored in memory and executed by the one or more processors causes the one or more processors to perform acts of:

generating a response to the particular user interaction, the response being generated in accordance with the set of extensible access permissions.

12. The non-transitory computer readable medium of claim 11 , wherein the response corresponds to at least one of taking no action, allowing an interaction, allowing the interaction with a justification, or blocking the interaction.

13. The non-transitory computer readable medium of claim 12 , wherein at least a portion of the response is presented to a user at a user interface.

14. The non-transitory computer readable medium of claim 10 , wherein the one or more context-aware access policies comprise extensible permissions rules.

15. The non-transitory computer readable medium of claim 14 , wherein the extensible permissions rules are evaluated against at least a portion of the one or more interaction attributes to determine the set of extensible access permissions.

16. The non-transitory computer readable medium of claim 10 , wherein a context associated with the particular user interaction is characterized by one or more of the one or more interaction attributes, wherein the one or more interaction attributes are retrieved by parsing an interaction event message received in response to the particular user interaction over the shared content object.

17. The non-transitory computer readable medium of claim 10 , wherein the one or more interaction attributes comprise at least one of one or more event attributes, one or more object attributes, or one or more user attributes.

18. A system for context-aware content object security, the system comprising:

a storage medium having stored thereon a sequence of instructions; and

one or more hardware-based processors that execute the sequence of instructions to cause the one or more hardware-based processors to perform a set of acts, the set of acts comprising,

applying a first set of resource access permissions to a shared content object;

maintaining one or more context-aware access policies that govern user interactions over the shared content object;

gathering one or more interaction attributes associated with a particular user interaction over the shared content object;

applying the one or more context-aware access policies to the one or more interaction attributes to determine and store, in computer memory, a set of extensible access permissions associated with the particular user interaction over the shared content object; and

overriding at least some of the first set of resource access permissions to the shared content object with the set of extensible access permissions retrieved from the computer memory and associated with the particular user interaction over the shared content object, in response to a determination that the set of extensible access permissions conflict with the first set of resource access permissions.

19. The system of claim 18 , further comprising instructions which, when stored in memory and executed by the one or more hardware-based processors causes the one or more hardware-based processors to perform acts of:

generating a response to the particular user interaction, the response being generated in accordance with the set of extensible access permissions.

20. The system of claim 19 , wherein the response corresponds to at least one of taking no action, allowing an interaction, allowing the interaction with a justification, or blocking the interaction.

Assignments (2)
SECURITY INTEREST Recorded Jul 26, 2023
From: BOX, INC.
To: WELLS FARGO BANK, NATIONAL ASSOCIATION
Reel/Frame 064389/0686 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 16, 2020
From: OJHA, ALOK; SUBRAMANIAN, SIVARAMAKRISHNAN; HUANG, KECHEN
To: BOX, INC.
Reel/Frame 052129/0881 →
Continuity (3)
Provisional Application 62723314 · Aug 27, 2018
Provisional Application 62723435 · Aug 27, 2018
Related Publication 20200092337A1 · Mar 19, 2020
References Cited (28)
US 10552590B2 · Hamlin et al. · 2020 [cited by applicant]
US 10726152B1 · Durham et al. · 2020 [cited by applicant]
US 10902072B2 · Anders et al. · 2021 [cited by applicant]
US 10979432B1 · Frank et al. · 2021 [cited by applicant]
US 20030018890A1 · Hale et al. · 2003 [cited by applicant]
US 20090307746A1 · Di et al. · 2009 [cited by applicant]
US 20140208425A1 · Palomaki · 2014 [cited by applicant]
US 20150089575A1 · Vepa · 2015 [cited by examiner]
US 20150227756A1 · Barbas · 2015 [cited by examiner]
US 20160070758A1 · Thomson · 2016 [cited by examiner]
US 20160117495A1 · Li et al. · 2016 [cited by applicant]
US 20180114015A1 · Nuseibeh et al. · 2018 [cited by applicant]
US 20180124609A1 · Ciano · 2018 [cited by examiner]
US 20200092337A1 · Ojha et al. · 2020 [cited by applicant]
International Search Report and Written Opinion dated Dec. 11, 2019 for PCT Appln. No. PCT/US19/48435. [cited by applicant]
Non-Final Office Action dated Jun. 8, 2021 for U.S. Appl. No. 16/553,063. [cited by applicant]
Notice of Allowance dated Jun. 24, 2022 for U.S. Appl. No. 16/553,063. [cited by applicant]
Final Office Action dated Oct. 7, 2021 U.S. Appl. No. 16/553,063. [cited by applicant]
Non-Final Office Action dated Jun. 8, 2021 U.S. Appl. No. 16/553,063. [cited by applicant]
European Search Report dated Sep. 20, 2021 for related EP Application No. 19853611.2. [cited by applicant]
Non-Final Office Action for U.S. AppIn No. U.S. Appl. No. 16/553,063 dated Mar. 3, 2022. [cited by applicant]
De Filippi, P., et al., “Cloud Computing: Centralization and Data Sovereignty,” dated 2012, electronic copy available at: https://ssrn.com/abstract=2167372. [cited by applicant]
Chen, Y., et al. “What's New About Cloud Computing Security?” Electrical Engineering and Computer Sciences University of California at Berkeley, Technical Report No. UCB/EECS-2010-5, http://www.eecs.berkeley.edu/Pubs/Te… [cited by applicant]
J. Alqatawna, E. Rissanen and B. Sadighi, “Overriding of Access Control in XACML,” Eighth IEEE International Workshop on Policies for Distributed Systems and Networks (POLICY'07), 2007, pp. 87-95 (Year: 2007). [cited by applicant]
Non-Final Office Action for U.S. Appl. No. 16/948,828 dated Jul. 22, 2022. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 16/553,063 dated Sep. 21, 2022. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 16/948,828 dated Nov. 16, 2022. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 16/553,063 dated Feb. 1, 2023. [cited by applicant]