IP Library › Granted Patent US 7,694,148
Granted Patent B2
US 7,694,148 · App. 12/401,680 · Granted Apr 6, 2010

Method and system for managing the display of sensitive content in non-trusted environments

Assignee: International Business Machines Corporation
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,694,148
App. No.
12/401,680
Granted
Apr 6, 2010
Kind
B2
Abstract

A method ( 10 ) for managing the display of sensitive content in non-trusted environments can include the steps of interrogating ( 12 ) a list of policies associated with a given user and a physical device, determining ( 14 ) a location of the physical device, comparing ( 18 ) the location of the physical device with a list of trusted locations, and enforcing ( 20 ) a plurality of rules contained in the policy by limiting or restricting access to sensitive information based on the location.

Claims (27)

1. A system for managing a presentation of sensitive content in non-trusted environments, comprising:

a memory;

a display; and

a processor coupled to the memory and the display, wherein the processor is programmed to:

interrogate a list of one or more corporate policies associated with a given user and a physical device, the policy data being acquired locally from the physical device or dynamically via access to a corporate network, each corporate policy prohibiting or restricting access to corporate data in a non-trusted environment;

determine a location of the physical device;

determine whether the user and the physical device is in a trusted or non-trusted environment by comparing the determined location of the physical device with a list of trusted locations, the list of trusted locations being embedded within the policy data or stored separately;

access a subscription-based service that maintains an organization list of individuals and machine identification information indicating that a listed individual or machine is associated with a predetermined organization;

determine that an individual or machine identified on the list associated with a competitive organization is within a predetermined proximity of the physical device, and in response thereto, transmitting an alert to the physical device; and

enforce a plurality of rules contained in the corporate policy for managing the presentation of sensitive content by blocking a visual presentation or audible presentation of at least one object in portions of the presentation if the physical device is not located in a trusted location or if an individual or a machine identified on the competitive organization list is within a predetermined proximity of the physical device.

2. The system of claim 1 , wherein the processor is further programmed to provide a reminder of the policy regarding confidential material to the given user in response to an attempt to access sensitive information on the physical device.

3. The system of claim 1 , wherein the processor is further programmed to request authentication from the given user in response to an attempt to access sensitive information in an open application on the physical device.

4. The system of claim 3 , wherein the processor requests authentication by requesting at least one among the provision of a unique password for the given user, a unique accessing device, or a unique biometric characteristic of the given user.

5. The system of claim 1 , wherein the processor determines the location by using at least one among a global positioning system and a terrestrial wireless infrastructure system to provide the location of the physical device.

6. The system of claim 1 , wherein the processor enforces the policies by at least one among blacking out a visual object in a display during the presentation, replacing a visual object with innocuous content during the presentation, visually hiding the at least one object from the given user during the presentation and inserting audio ‘white noise’ gaps in an audio object.

7. A machine-readable storage, having stored thereon a computer program having a plurality of code sections executable by a machine for causing the machine to perform the steps of:

interrogating a list of one or more corporate policies associated with a given user and a physical device, the policy data being acquired locally from the physical device or dynamically via access to a corporate network, each corporate policy prohibiting or restricting access to corporate data in a non-trusted environment;

determining a location of the physical device;

determining whether the user and the physical device is in a trusted or non-trusted environment by comparing the determined location of the physical device with a list of trusted locations, the list of trusted locations being embedded within the policy data or stored separately;

providing access to a subscription-based service that maintains an organization list of individuals and machine identification information indicating that a listed individual or machine is associated with a predetermined organization;

determining that an individual or machine identified on the list associated with a competitive organization is within a predetermined proximity of the physical device, and in response thereto, transmitting an alert to the physical device; and

enforcing a plurality of rules contained in the corporate policy for managing the presentation of sensitive content by blocking a visual presentation or audible presentation of at least one object in portions of the presentation if the physical device is not located in a trusted location or if an individual or a machine identified on the competitive organization list is within a predetermined proximity of the physical device.

8. The machine-readable storage of claim 7 , wherein the computer program further comprises a plurality of code sections for causing the machine to provide a reminder of the policy regarding confidential material to the given user in response to an attempt to access sensitive information on the physical device.

9. The machine-readable storage of claim 7 , wherein the computer program further comprises a plurality of code sections for causing to request authentication from the given user in response to an attempt to access sensitive information in an open application on the physical device.

10. The machine-readable storage of claim 9 , wherein the computer program requests authentication by requesting at least one among a provision of a unique password for the given user, a unique accessing device, or a unique biometric characteristic of the given user.

11. The machine-readable storage of claim 7 , wherein the computer program determines a location by using at least one among a global positioning system and a terrestrial wireless infrastructure system to provide the location of the physical device.

12. The machine-readable storage claim 7 , wherein the computer program enforces the policy by at least one among blacking out a visual object in a display during the presentation, replacing a visual object with innocuous content during the presentation, visually hiding the at least one object from the given user during the presentation and inserting audio ‘white noise’ gaps in an audio object.

Continuity (2)
Continuation 1073040000 · Dec 8, 2003
Related Publication 20090172408A1 · Jul 2, 2009