IP Library Granted Patent US 9,038,145
Granted Patent B2
US 9,038,145 · App. 14/137,023 · Granted May 19, 2015

Method and system for restricting access to user resources

Inventors: Ralph William Brown (Boulder, CO); Milo S. Medin (Redwood City, CA); Robert Keller (Menlo Park, CA); David Temkin (San Francisco, CA)
Assignee: At Home BondHolders' Liquidating Trust
G06F21/10H04L12/1836H04L12/1845H04L12/1854H04L12/1877H04L12/2801H04L12/2856H04L12/2861H04L12/287H04L12/2883H04L29/06H04L63/0807H04L63/101H04N21/2225H04N21/23106H04L67/2842H04L67/18H04L67/2885H04L69/329
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,038,145
App. No.
14/137,023
Granted
May 19, 2015
Kind
B2
Abstract

A user's set top box (STB), or other client, executes a shell and has an application program interface (API) by which certain features of the client can be controlled. The client is in communication with a walled garden proxy server (WGPS). The client sends a request to the WGPS to access a service provided by a site in the garden. The site sends the client a message containing code calling a function in the API. The WGPS traps the message from the site and looks up the site in a table to determine the access control list (ACL) for the site. The WGPS includes the ACL in the header of the hypertext transport protocol (HTTP) message to the client. The shell receives the message and extracts the ACL. If the code lacks permission, the shell stops execution.

Claims (41)

1. A computer program product comprising:

a non-transitory computer usable storage medium having computer executable instructions embodied therein for managing access to an application program interface (API) comprising a plurality of functions, the computer executable instructions comprising instructions for:

receiving a message containing code calling a function in the API and data indicating API function execution rights for the message;

determining whether the data indicate that the message has a right to execute the called function;

executing the called function responsive to the data indicating that the message has the right to execute the called function; and

sending a response to an originator of the message indicating whether the code successfully executed the function in the API.

2. The computer program product of claim 1 , wherein the data indicating API function execution rights comprise:

a value identifying an API function that can be executed by the originator of the message.

3. The computer program product of claim 1 , wherein the data indicating API function execution rights comprise:

a value restricting API functions that can be executed by the originator of the message based on time.

4. The computer program product of claim 1 , wherein the called function API is associated with television viewing.

5. The computer program product of claim 4 , wherein the called function is associated with determining television viewing privileges of a particular television viewer of a plurality of television viewers.

6. The computer program product of claim 1 , wherein the data indicating API function execution rights are stored in a header of the received message.

7. The computer program product of claim 1 , wherein the data indicating API function execution rights comprise a bit map specifying API function execution rights of the originator of the received message.

8. A computer for managing access to an application program interface (API) comprising a plurality of functions, the computer comprising:

a processor for executing computer program instructions; and

a non-transitory computer usable storage medium having computer program instructions embodied therein, the computer program instructions comprising instructions for:

receiving a message containing code calling a function in the API and data indicating API function execution rights for the message;

determining whether the data indicate that the message has a right to execute the called function;

executing the called function responsive to the data indicating that the message has the right to execute the called function; and

sending a response to an originator of the message indicating whether the code successfully executed the function in the API.

9. The computer of claim 8 , wherein the data indicating API function execution rights comprise:

a value identifying an API function that can be executed by the originator of the message.

10. The computer of claim 8 , wherein the data indicating API function execution rights comprise:

a value restricting API functions that can be executed by the originator of the message based on time.

11. The computer of claim 8 , wherein the called function is associated with television viewing.

12. The computer of claim 11 , wherein the called function is associated with determining television viewing privileges of a particular television viewer of a plurality of television viewers.

13. The computer of claim 8 , wherein the data indicating API function execution rights are stored in a header of the received message.

14. The computer of claim 8 , wherein the data indicating API function execution rights comprise a bit map specifying API function execution rights of the originator of the received message.

15. A method of using a computer processor to manage access to an application program interface (API) comprising a plurality of functions, comprising:

receiving a message containing code calling a function in the API and data indicating API function execution rights for the message;

determining, by the computer processor, whether the data indicate that the message has a right to execute the called function;

executing the called function responsive to the data indicating that the message has the right to execute the called function; and

sending a response to an originator of the message indicating whether the code successfully called the function in the API.

16. The method of claim 15 , wherein the data indicating API function execution rights comprise:

a value identifying an API function that can be executed by the originator of the message.

17. The method of claim 15 , wherein the data indicating API function execution rights comprise:

a value restricting API functions that can be executed by the originator of the message based on time.

18. The method of claim 15 , wherein the called function is associated with television viewing.

19. The method of claim 18 , wherein the called function is associated with determining television viewing privileges of a particular television viewer of a plurality of television viewers.

20. The method of claim 15 , wherein the data indicating API function execution rights are stored in a header of the received message.

Continuity (7)
Continuation 13480439 · May 24, 2012
Continuation 12901081 · Oct 8, 2010
Continuation 12166088 · Jul 1, 2008
Continuation 10836544 · Apr 30, 2004
Continuation 09427778 · Oct 26, 1999
Continuation In Part 08811586 · Mar 5, 1997
Related Publication 20140109198A1 · Apr 17, 2014