IP Library Granted Patent US 7,814,021
Granted Patent B2
US 7,814,021 · App. 10/706,871 · Granted Oct 12, 2010

Managed distribution of digital assets

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,814,021
App. No.
10/706,871
Granted
Oct 12, 2010
Kind
B2
Abstract

A technique for establishing usage control over digital assets such as computer files. The system model not only tracks authorized users' access to files, but monitors passage of such files to uncontrollable removable storage media or through network connections and the like which may indicate possible abuse of access rights. In accordance with a preferred embodiment, an autonomous independent agent process running at a point of use, such a background process in a client operating system kernel, interrupts requests for access to resources. The agent process senses low level system events, filters, and aggregates them. A policy engine analyzes sequences of aggregate events to determine when policy violations occur.

Claims (36)

1. An agent process for controlling access to digital assets in a network of data processing devices, the process comprising:

defining a security perimeter that includes two or more data processing devices in the network, each of the data processing devices including an operating system kernel, and at least one of the data processing devices being a user client device having access to a digital asset;

defining one or more policy violation predicates implementing policy logic to control access to the digital asset by an end user of the user client device;

sensing atomic events within the operating system kernel of the user client device, the atomic events being low level kernel events and being sensed upon actions relating to authorized access to the digital asset by the end user of the user client device;

aggregating multiple atomic level events sensed within the user client device to determine a combined event; and

asserting a policy violation predicate, at the user client device, upon an occurrence of a combined event that violates the policy logic, the policy logic violation corresponding to a risk of use of the digital asset outside of the security perimeter.

2. A process as in claim 1 wherein the step of asserting the policy violation predicate is implemented in the operating system kernel of the client user device.

3. A process as in claim 1 additionally comprising:

preventing a user from accessing the digital asset if the policy predicate indicates a violated policy.

4. A process as in claim 3 wherein the preventing step includes an IRP intercept.

5. A process as in claim 1 wherein the combined event is a time sequence of multiple atomic level events.

6. A process as in claim 1 additionally comprising:

prompting a user to document a reason for a policy violation, prior to granting access to the digital asset.

7. A process as in claim 1 additionally comprising:

asserting multiple policy violation predicates prior to indicating a risk of use of the digital asset outside of the security perimeter.

8. A process as in claim 2 that operates independently of application software.

9. A process as in claim 1 additionally comprising:

notifying a user of a policy violation, and then permitting access to the digital asset.

10. A process as in claim 2 wherein the sensing, aggregating, and asserting steps operate in real time.

11. A process as in claim 1 additionally comprising:

determining the identity of a particular file in the asset access event.

12. A system for controlling access to digital assets in a network of data processing devices, the system comprising:

a digital asset usage policy server storing one or more digital asset usage policies programmed to be applied to a security perimeter, the security perimeter comprising two or more data processing devices, each of the data processing devices including an operating system kernel, at least one of the data processing devices being a user client device having access to a digital asset, and the one or more digital asset usage policies implementing policy logic to control access to the digital asset by an end user of the user client device;

an atomic event sensor, the sensor located within the operating system kernel within the user client device and programmed to sense atomic events within the operating system kernel, the atomic events being low level kernel events and being sensed by the sensor upon actions relating to authorized access to the digital asset by the end user of the user client device;

an atomic level event aggregator programmed to determine the occurrence of an aggregate event that comprises more than one atomic level asset access event sensed within the user client device; and

a policy violation detector programmed to determine whether an aggregate event has occurred that violates the policy logic, the policy logic violation corresponding to a risk of use of the digital asset outside the security perimeter.

13. A system as in claim 12 wherein the policy violation detector is located in the operating system kernel of the user client device.

14. A system as in claim 12 wherein the policy violation detector is programmed to determine a violated policy type.

15. A system as in claim 14 wherein the policy violation detector includes an IRP intercept.

16. A system as in claim 12 wherein the combined event is a time sequence of multiple atomic level events.

17. A system as in claim 12 further including a user interface within the client device programmed to require the end user to document a reason for a policy violation prior to granting access to the digital asset.

18. A system as in claim 12 wherein the policy violation detector is additionally programmed to assert multiple policy violation predicates prior to indicating a risk of use of the digital asset outside of the security perimeter.

19. A system as in claim 13 that is programmed to operate independently of application software.

20. A system as in claim 12 wherein the user client device includes a user interface programmed to notify the end user of a policy violation and to permit access to the digital asset once a reason for the violation is provided by the end user.

21. A system as in claim 12 wherein the sensor, aggregator and detector are programmed to operate in real time.

22. A system as in claim 12 wherein the detector is additionally programmed to determine the identity of a particular file in the atomic level asset event.

Assignments (20)
SECURITY INTEREST Recorded Jan 6, 2026
From: ALERT LOGIC, INC.; DIGITAL GUARDIAN LLC; ECRIME MANAGEMENT STRATEGIES, INC.; FORTRA, LLC; GLOBALSCAPE, INC.; TRIPWIRE, INC.
To: ACQUIOM AGENCY SERVICES LLC, AS COLLATERAL AGENT
Reel/Frame 074233/0632 →
TERMINATION AND RELEASE OF FIRST LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 58892/0766 Recorded Nov 24, 2025
From: JEFFERIES FINANCE LLC
To: DIGITAL GUARDIAN LLC
Reel/Frame 073783/0619 →
EXTENDED FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: DIGITAL GUARDIAN LLC
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 073663/0844 →
EXTENDED RCF FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: DIGITAL GUARDIAN LLC
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 073663/0050 →
TERMINATION AND RELEASE OF SECOND LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 58892/0945 Recorded Nov 21, 2025
From: ACQUIOM AGENCY SERVICES LLC
To: DIGITAL GUARDIAN LLC
Reel/Frame 073663/0411 →
NEW MONEY FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: ALERT LOGIC, INC.; DIGITAL GUARDIAN LLC; ECRIME MANAGEMENT STRATEGIES, INC.; FORTRA, LLC; GLOBALSCAPE, INC.; TRIPWIRE, INC.; VERA SECURITY, INC.
To: ARES CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 073683/0534 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 14, 2025
From: GOLUB CAPITAL MARKETS LLC (AS EXISTING AGENT)
To: ACQUIOM AGENCY SERVICES LLC (AS SUCCESSOR COLLATERAL AGENT)
Reel/Frame 072471/0665 →
RELEASE OF SECURITY INTEREST Recorded May 3, 2022
From: GOLUB CAPITAL LLC
To: DIGITAL GUARDIAN LLC
Reel/Frame 059802/0303 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 28, 2022
From: DIGITAL GUARDIAN, LLC
To: GOLUB CAPITAL MARKETS LLC, AS COLLATERAL AGENT
Reel/Frame 058892/0945 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 28, 2022
From: DIGITAL GUARDIAN, LLC
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 058892/0766 →
SECOND AMENDED AND RESTATED INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 2, 2021
From: DIGITAL GUARDIAN LLC
To: GOLUB CAPITAL LLC, AS ADMINISTRATIVE AGENT
Reel/Frame 055207/0012 →
AMENDED AND RESTATED INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 29, 2019
From: DIGITAL GUARDIAN LLC
To: GOLUB CAPITAL LLC, AS ADMINISTRATIVE AGENT
Reel/Frame 050305/0418 →
CHANGE OF NAME Recorded May 21, 2019
From: DIGITAL GUARDIAN, INC.
To: DIGITAL GUARDIAN LLC
Reel/Frame 049240/0514 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jun 23, 2018
From: DIGITAL GUARDIAN, INC.
To: GOLUB CAPITAL LLC, AS ADMINISTRATIVE AGENT
Reel/Frame 046419/0207 →
RELEASE OF SECURITY INTEREST Recorded Dec 19, 2016
From: BRIDGE BANK, NATIONAL ASSOCIATION
To: DIGITAL GUARDIAN, INC. (FORMERLY VERDASYS INC.)
Reel/Frame 040672/0221 →
CHANGE OF NAME Recorded Apr 22, 2015
From: VERDASYS INC.
To: DIGITAL GUARDIAN, INC.
Reel/Frame 035479/0083 →
SECURITY AGREEMENT Recorded Dec 28, 2012
From: VERDASYS INC.
To: BRIDGE BANK, NATIONAL ASSOCIATION
Reel/Frame 029549/0302 →
RELEASE OF SECURITY INTEREST Recorded Dec 7, 2012
From: ORIX VENTURES, LLC
To: VERDASYS INC.
Reel/Frame 029425/0592 →
SECURITY AGREEMENT Recorded Oct 17, 2008
From: VERDASYS INC.
To: ORIX VENTURE FINANCE LLC
Reel/Frame 021701/0187 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 17, 2004
From: STAMOS, NICHOLAS; BIRNBAUM, SETH N.; REVESZ, JR., TOMAS; BUCCELLA, DONATO; MACDONALD, KEITH A.; CARSON, DWAYNE A.; FLETCHER, WILLIAM E.
To: VERDASYS, INC.
Reel/Frame 015464/0973 →