IP Library Granted Patent US 8,387,877
Granted Patent B2
US 8,387,877 · App. 13/219,086 · Granted Mar 5, 2013

Systems and methods for the secure control of data within heterogeneous systems and networks

Inventor: Patrick Shomo (Huntingtown, MD)
Assignee: Patrick Shomo
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,387,877
App. No.
13/219,086
Granted
Mar 5, 2013
Kind
B2
Abstract

Systems and methods for managing data rights are provided. A first label associated with a first data object may be received, and the first label may be converted into a first universal label based at least in part upon one or more predefined rules for the conversion of the first label into the first universal label. Additionally, a second label associated with a second data object may be received, and the second label may be converted into a second universal label based at least in part upon one or more predefined rules for the conversion of the second label into the second universal label. A combined universal label applicable to both the first data object and the second data object may be generated from the first universal label and the second universal label.

Claims (37)

1. A method for electronically managing data rights, the method comprising:

receiving a first label associated with a first data object;

converting the first label into a first universal label having a universal format based at least in part upon one or more predefined rules for the conversion of the first label into the first universal label;

receiving a second label associated with a second data object;

converting the second label into a second universal label having the universal format based at least in part upon one or more predefined rules for the conversion of the second label into the second universal label; and

generating, from the first universal label and the second universal label, a combined universal label applicable to both the first data object and the second data object,

wherein the above operations are performed by one or more computers.

2. The method of claim 1 , wherein the first data object and the second data object comprise separate data objects that are combined.

3. The method of claim 1 , wherein at least one of converting the first label to the first universal label or converting the second label to the second universal label comprises electronically mapping information associated with the label to the universal label format.

4. The method of claim 1 , further comprising:

associating one or more markers with at least one of the first label or the second label prior to converting the label into a universal label.

5. The method of claim 4 , wherein associating one or more markers comprises associating one or more markers comprising data associated with one or more of a version of the label, declassification information for the label, or originator information for the label.

6. The method of claim 1 , further comprising:

selecting, from a plurality of potential conversion rules, the one or more predefined rules for the conversion of one of the first label or the second label.

7. The method of claim 6 , wherein selecting the one or more predefined rules comprises selecting the one or more predefined rules based at least in part on security information associated with the label.

8. The method of claim 6 , wherein selecting the one or more predefined rules comprises selecting the one or more predefined rules based at least in part on environmental information associated with the applicable data object.

9. The method of claim 1 , further comprising:

receiving a third label associated with a subject seeking access to at least one of the first data object or the second data object;

obtaining one or more predefined rules for the conversion of the third label to a third universal label having the universal format;

converting the third label into the third universal label;

evaluating the combined universal label and the third universal label; and

determining whether the subject is allowed to access the requested data object based at least in part on the evaluation.

10. The method of claim 9 , wherein evaluating the combined universal label and the third universal label comprises comparing a security level associated with the combined universal label to a security level associated with the third universal label.

11. A system for electronically managing data rights, comprising:

at least one database configured to store one or more predefined rules for the conversion of labels to universal labels having a universal format; and

one or more label makers configured to (i) receive a first label associated with a first data object, (ii) convert the first label into a first universal label based at least in part on the one or more predefined rules, (iii) receive a second label associated with a second data object, (iv) convert the second label into a second universal label based at least in part on the one or more predefined rules, and (v) generate, from the first universal label and the second universal label, a combined universal label applicable to both the first data object and the second data object.

12. The system of claim 11 , wherein the first data object and the second data object comprise separate data objects that are combined.

13. The system of claim 11 , wherein the one or more label makers are configured to convert one of the first label or the second label by electronically mapping information associated with the label to the universal label format.

14. The system of claim 11 , wherein:

the one or more predefined rules stored in the at least one database are dynamically updated.

15. The system of claim 11 , wherein the one or more label makers are further configured to associate one or more markers with at least one of the first label or the second label prior to converting the label into a universal label.

16. The system of claim 15 , wherein the one or more markers comprise data associated with one or more of a version of the label, declassification information for the label, or originator information for the label.

17. The system of claim 11 , wherein an entity associated with the one or more databases is configured to select, from a plurality of potential conversion rules, the one or more predefined rules for conversion of one of the first label or the second label.

18. The system of claim 17 , wherein the entity selects the one or more predefined rules based on one or more of (i) security information associated with the label or (ii) environmental information associated with the applicable data object.

19. The system of claim 11 , wherein the one or more label makers are further configured to (i) receive a third label associated with a subject seeking access to at least one of the first data object or the second data object and (ii) convert the third label into a third universal label based at least in part on the one or more predefined rules, and further comprising:

a label evaluator configured to (i) receive the combined universal label and the third universal label from the one or more label makers, (ii) evaluate the combined universal label and the third universal label, and (iii) determine whether the subject is allowed to access the requested data object based at least in part on the evaluation.

20. The system of claim 19 , wherein the evaluation of the combined universal label and the third universal label comprises a comparison of a security level associated with the combined universal label to a security level associated with the third universal label.

Continuity (3)
Continuation 11743082 · May 1, 2007
Provisional Application 60796986 · May 1, 2006
Related Publication 20110307963A1 · Dec 15, 2011