IP Library Granted Patent US 9,710,659
Granted Patent B2
US 9,710,659 · App. 14/834,461 · Granted Jul 18, 2017

Methods and systems for enforcing, by a kernel driver, a usage restriction associated with encrypted data

Inventor: William R. Ackerly (Washington, DC)
Assignee: Virtru Corporation
G06F21/602G06F9/468G06F21/6281H04L63/0428G06F2221/2107G06F2221/2141H04L63/0892H04L2463/101
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,710,659
App. No.
14/834,461
Granted
Jul 18, 2017
Kind
B2
Abstract

A method of providing a restricted set of application programming interfaces includes decrypting, by a secure object information reader executing on a computing device, an encrypted data object using information associated with the encrypted data object to generate a decrypted data object, the information received from an access control management system. The method includes intercepting, by a kernel driver executing on the computing device, from a process executing on the computing device, a request to access the decrypted data object. The method includes identifying, by the kernel driver, using the information associated with the encrypted data object, a usage requirement restricting a set of operations available to the process in accessing the decrypted data object. The method includes providing, by the kernel driver, to the process, a restricted set of application programming interfaces with which to interact with the decrypted data object, as permitted by the restricted set of operations.

Claims (26)

1. A method of providing a restricted set of application programming interfaces comprising:

decrypting, by a secure object information reader executing on a computing device, an encrypted data object using information associated with the encrypted data object to generate a decrypted data object, the information received from an access control management system;

intercepting, by a kernel driver executing on the computing device, from a process executing on the computing device, a request to access the decrypted data object;

retrieving, by the kernel driver, from the information received from the access control management system, a usage requirement restricting a set of operations available to the process in accessing the decrypted data object;

identifying, by the kernel driver, in the retrieved usage requirement, an operation a user of the computing device is authorized to execute; and

providing, by the kernel driver, to the process, a restricted set of application programming interfaces with which to interact with the decrypted data object, the restricted set including the authorized operation identified in the retrieved usage requirement.

2. A method of providing a restricted set of application programming interfaces comprising:

decrypting, by a secure object information reader executing on a computing device, an encrypted data object using information associated with the encrypted data object, the information received from an access control management system and including at least one usage restriction;

intercepting, by a kernel driver executing on the computing device, from a user of the computing device, a request to access the decrypted data object;

identifying, by the kernel driver, a process associated with the decrypted data object in a file type association mapping;

launching, by the kernel driver, the identified process on the computing device into a protected memory space;

intercepting, by the kernel driver, a request from the identified process for a type of access to the decrypted data object;

retrieving, by the kernel driver, from the information received from the access control management system, the at least one usage requirement;

identifying, by the kernel driver, in the retrieved at least one usage requirement, an operation a user of the computing device is authorized to execute;

determining, by the kernel driver, based on the identified authorized operation in the retrieved at least one usage requirement, that the at least one usage restriction permits the type of access requested; and

providing, by the kernel driver, to the process, an application programming interface with which to access the decrypted data object.

3. A method of providing a restricted set of application programming interfaces comprising:

decrypting, by a secure object information reader executing on a computing device, an encrypted data object using information associated with the encrypted data object, the information received from an access control management system and including at least one usage restriction;

intercepting, by a kernel driver executing on the computing device, from a user of the computing device, a request to access the decrypted data object;

identifying, by the kernel driver, a process associated with the decrypted data object in a file type association mapping;

launching, by the kernel driver, the identified process on the computing device into a protected memory space;

intercepting, by the kernel driver, a request from the identified process for a type of access to the decrypted data object;

retrieving, by the kernel driver, from the information received from the access control management system, the at least one usage requirement;

determining, by the kernel driver, using the retrieved at least one usage requirement, that the at least one usage restriction does not permit the type of access; and

rejecting, by the kernel driver, the process request for access.

4. The method of claim 3 , further comprising, identifying, by the kernel driver, in the retrieved at least one usage requirement, an operation a user of the computing device is authorized to execute.

Assignments (4)
RELEASE OF SECURITY INTEREST Recorded Feb 7, 2024
From: FIRST-CITIZENS BANK & TRUST COMPANY
To: VIRTRU CORPORATION
Reel/Frame 066412/0348 →
SECURITY INTEREST Recorded Feb 6, 2024
From: VIRTRU CORPORATION
To: STIFEL BANK
Reel/Frame 066398/0565 →
SECURITY INTEREST Recorded Oct 6, 2021
From: VIRTRU CORPORATION
To: SILICON VALLEY BANK
Reel/Frame 057718/0099 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 25, 2015
From: ACKERLY, WILLIAM R.
To: VIRTRU CORPORATION
Reel/Frame 036416/0155 →
Continuity (2)
Provisional Application 62042968 · Aug 28, 2014
Related Publication 20160063258A1 · Mar 3, 2016