IP Library Granted Patent US 7,467,409
Granted Patent B2
US 7,467,409 · App. 10/898,298 · Granted Dec 16, 2008

Aggregating trust services for file transfer clients

Assignee: Microsoft Corporation
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,467,409
App. No.
10/898,298
Granted
Dec 16, 2008
Kind
B2
Abstract

A trust evaluation framework exposes a common interface that may be used by file transfer clients in the process of retrieving or downloading a file. Using the common interface, each file transfer client can take advantage of multiple trust providers to evaluate the incoming file. In this way, disparate file transfer clients can present a common user experience for downloading or retrieving files. In addition, trust providers may be updated or added to the system without modifying the installed file transfer clients. This enables the user experience to be incrementally improved without updating the installed programs.

Claims (31)

1. A system for evaluating an attachment, comprising:

a host computer;

a trust service manager on the host computer configured to expose a common interface through which one or more file transfer client evaluates an attachment utilizing a plurality of trust providers, the trust service manager comprising:

a commitment component, the commitment component being operative to cause the attachment to be committed to an identified transfer client and to invoke a check policy component;

the check policy component being configured to invoke one or more of the plurality of trust providers to evaluate the attachment prior to the attachment being committed by the commitment component, wherein the check policy component is further configured to determine an aggregate trust score for the attachment based on the evaluations of the trust providers, wherein if the aggregated trust score for the attachment fails a threshold, then:

the check policy component determines if an antivirus utility is installed and up to date on the host computer, wherein, based upon the aggregate trust score and the availability and up to date condition of the antivirus utility on the host computer, the check policy component assigns a final safety level for the attachment;

a prompt user component;

an execute component; and

a save component, wherein the save component is configured to retain information related to where the attachment came from.

2. The system recited in claim 1 , wherein the plurality of trust providers comprises an anti-virus utility.

3. The system recited in claim 1 , wherein the plurality of trust providers comprises a digital signature verification utility.

4. The system recited in claim 1 , wherein the plurality of trust providers comprises a utility to determine whether any applicable updates have been applied to the attachment.

5. The system recited in claim 1 , wherein the file transfer client is a utility operative to retrieve the attachment from a remote location.

6. The system recited in claim 1 , wherein the commitment component is operative to cause the attachment to be launched on the identified transfer client utilizing the execute component.

7. The system recited in claim 1 , wherein the commitment component is operative to cause the attachment to be saved to the identified transfer client utilizing the save component.

8. The system recited in claim 1 , wherein the prompt user component prompts a user for a security determination if the final safety level does not satisfy a security threshold.

9. The system recited in claim 1 , wherein the check policy component is configured to invoke one or more of the trust providers to evaluate the attachment after the attachment has been committed by the commitment component.

10. The system recited in claim 9 , wherein the commitment component is operative to cause the attachment to be launched on the identified transfer client utilizing the execute component.

11. The system recited in claim 9 , wherein the commitment component is operative to cause the attachment to be saved to the identified transfer client utilizing the save component.

12. A computer storage media having computer-executable instructions for evaluating an attachment, the instructions comprising:

in response to a retrieval of the attachment being initiated by a host computer, invoking a trust service manager configured to expose a common interface through which one or more file transfer client evaluates an attachment utilizing a plurality of trust providers, the trust service manager comprising:

a commitment component, the commitment component being operative to cause the attachment to be committed to an identified transfer client and to invoke a check policy component;

the check policy component being configured to invoke one or more of the plurality of trust providers to evaluate the attachment prior to the attachment being committed by the commitment component, wherein the check policy component is further configured to determine an aggregate trust score for the attachment based on the evaluations of the trust providers, wherein if the aggregated trust score for the attachment fails a threshold, then:

the check policy component determines if an antivirus utility is installed and up to date on the host computer, wherein, based upon the aggregate trust score and the availability and up to date condition of the antivirus utility on the host computer, the check policy component assigns a final safety level for the attachment;

a prompt user component;

an execute component; and

a save component, wherein the save component is configured to retain information related to where the attachment came from.

13. The computer storage media recited in claim 12 , wherein the commitment component is operative to cause the attachment to be launched on the file transfer client utilizing the execute component based on a satisfactory final safety level.

14. The computer storage media recited in claim 12 , wherein the commitment component is operative to cause the attachment to be saved to the local device utilizing the save component based on a satisfactory final safety level.

15. The computer storage media recited in claim 12 , further comprising, if the final safety level does not satisfy a security threshold, prompting a user utilizing the prompt user component for a security determination.

16. The computer storage media recited in claim 12 , further comprising, if the final safety level satisfies a security threshold, committing the attachment on the file transfer client utilizing the save component without prompting a user.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 9, 2014
From: MICROSOFT CORPORATION
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 034541/0477 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 23, 2004
From: REASOR, STERLING M.; ODINS-LUCAS, ZEKE B.; SHELDON, MICHAEL G. Q.
To: MICROSOFT CORPORATION
Reel/Frame 015625/0069 →
Continuity (2)
Provisional Application 6052941300 · Dec 12, 2003
Related Publication 20050132227A1 · Jun 16, 2005