IP Library Granted Patent US 12,333,032
Granted Patent B2
US 12,333,032 · App. 18/444,484 · Granted Jun 17, 2025

Data access control systems and methods

Inventors: Daniel Joseph Sturtevant (Cambridge, MA); Christopher Lalancette (Ayer, MA); Michael Nathan Lack (Arlington, VA); Paul B. Schneck (Potomac, MD)
Assignee: DataSphere, LLC
G06F21/62G06F21/31G06F21/604G06F21/606G06F21/6209G06F21/6218G06F21/85H04L63/0807
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,333,032
App. No.
18/444,484
Granted
Jun 17, 2025
Kind
B2
Abstract

Various hardware and software configurations are described herein which provide improved security and control over protected data. In some embodiments, a computer includes a main motherboard card coupled to all input/output devices connected to the computer, and a trusted operating system operates on the main motherboard which includes an access control module for controlling access to the protected data in accordance with rules. The trusted operating system stores the protected data in an unprotected form only on the memory devices on the main motherboard. The computer may also have a computer card coupled to the main motherboard via a PCI bus, on which is operating a guest operating system session for handling requests for data from software applications on the computer. A tamper detection mechanism is provided in the computer for protecting against attempts to copy the unprotected form of the protected data onto memory devices other than the one or more memory devices used by the motherboard or computer card.

Claims (41)

1. A method for controlling access to protected content or data, the method comprising:

receiving, at a computer device from a remote user device, a request to access the protected content or data stored in a trusted operating system at the computer device, wherein the request comprises an indication of a first version of an electronic ticket granted to a user, and wherein the first version of the electronic ticket includes access control rules;

retrieving, at the computer device, a second version of the electronic ticket, wherein the second version of electronic ticket includes state information that is not in the first version of the electronic ticket, and wherein the second version is stored in a portion of memory that is not accessible by the user;

determining, at the computer device, and based at least in part on the access control rules and the state information, whether the request to access the protected content or data should be granted,

wherein—

when it is determined that the request should be granted, enabling access to the protected content or data, and

when it is determined that the request should not be granted, denying access to the protected content or data.

2. The method of claim 1 , further comprising determining, at the computer device, in response to the request, that the first version of the electronic ticket is valid based on the state information.

3. The method of claim 1 wherein the request is encrypted using a public key associated with the computer device, and wherein the method further comprises decrypting, by the computer device, the request using a private key stored in the portion of memory that is not accessible to the user.

4. The method of claim 1 wherein the request further comprises credentials associated with the remote user device and the user, the credentials including a user identifier associated with the user of the remote user device and a network resource identifier, and wherein the access control rules include both a user identifier rule and a network resource rule.

5. The method of claim 4 wherein determining whether the request to access the protected content or data should be granted comprises comparing, at the computer device, as defined by the access control rules, the user identifier from the credentials and/or the network resource identifier from the credentials to the user identifier rule and the network resource rule in the access control rules.

6. The method of claim 4 wherein enabling access to the protected content or data comprises transmitting the access request to a server computing device associated with the network resource identifier.

7. The method of claim 4 wherein the user device identifier includes an IP address of the user device, the device identifier rule includes an IP address range, and wherein determining whether the request to access the protected content or data should be granted comprises determining if the IP address of the user device is within the IP address range.

8. The method of claim 1 wherein the access control rules include a file sharing protocol identifier and a document identifier.

9. A non-transitory computer-readable storage medium storing content that, when executed by a computer device, causes the computer device to perform operations for protecting data, the operations comprising:

receiving, at the computer device from a user device remote from the computer device, a request to access protected content or data stored in a trusted operating system at the computer device, wherein the request comprises an indication of a first version of an electronic ticket granted to a user at the user device, and wherein the first version of the electronic ticket includes access control rules;

retrieving, at the computer device, a second version of the electronic ticket, wherein the second version of electronic ticket includes state information that is not in the first version of the electronic ticket, and wherein the second version is stored in a portion of memory that is not accessible by the user;

determining, at the computer device, and based at least in part on the access control rules and the state information, whether the request to access the protected content or data should be granted,

wherein—

when it is determined that the request should be granted, enabling access to the protected content or data, and

when it is determined that the request should not be granted, denying access to the protected content or data.

10. The non-transitory computer-readable storage medium of claim 9 wherein the operations further comprise determining, at the computer device, in response to the request, that the electronic ticket granted to the user is valid based on the state information.

11. The non-transitory computer-readable storage medium of claim 9 wherein the request is encrypted using a public key associated with the computer device, and wherein the operations further comprise decrypting, by the computer device, the request using a private key stored in the portion of memory that is not accessible to the user.

12. The non-transitory computer-readable storage medium of claim 9 wherein the request further comprises a device identifier associated with the user device, wherein the device identifier includes an IP address of the user device, wherein the access control rules include a device identifier rule that includes an IP address range, and wherein determining whether the request to access the protected content or data should be granted comprises determining if the IP address of the user device is within the IP address range.

13. The non-transitory computer-readable storage medium of claim 9 wherein the request further comprises a network resource identifier, wherein the access control rules include a network resource rule, and wherein determining whether the request to access the protected content or data should be granted comprises comparing the network resource identifier to the network resource rule.

14. The non-transitory computer-readable storage medium of claim 13 wherein the network resource identifier comprises a file sharing protocol identifier and a document identifier.

15. A computing system, comprising:

one or more processors;

at least one memory; and

an access control component configured to perform operations for protecting data, the operations comprising:

receiving, at the computing system from a remote computing device, a request to access protected content or data stored in the at least one memory, wherein the request comprises an indication of a first version of an electronic ticket granted to a user at the remote computing device, and wherein the first version of the electronic ticket includes one or more access control rules;

retrieving, at the computing system, a second version of the electronic ticket, wherein the second version of electronic ticket includes state information associated that is not in the first version of the electronic ticket, and wherein the second version is stored in a portion of the at least one memory that is not accessible to the user;

determining, at the computing system, and based at least in part on the one or more access control rules and the state information, whether the request to access the protected content or data should be granted,

wherein—

when it is determined that the request should be granted, enabling access to the protected content or data, and

when it is determined that the request should not be granted, denying access to the protected content or data.

16. The computing system of claim 15 wherein the operations further comprise determining, in response to the request, that the electronic ticket granted to the user is valid based on the state information.

17. The computing system of claim 15 wherein the request is encrypted using a public key associated with the computing system, and the operations further comprise decrypting the request using a private key stored in the portion of the at least one memory that is not accessible to the user.

18. The computing system of claim 15 wherein the request further comprises a device identifier associated with the remote computing device, wherein the device identifier includes an IP address of the remote computing device, wherein the one or more access control rules include a device identifier rule that includes an IP address range, and wherein determining whether the request to access the protected content or data should be granted comprises determining if the IP address of the remote computing device is within the IP address range.

19. The computing system of claim 15 wherein the request further comprises credentials associated with the remote computing device and the user, the credentials including a user identifier associated with the user of the remote computing device and a network resource identifier, and wherein the one or more access control rules include both the user identifier rule and the network resource rule.

20. The computing system of claim 19 wherein determining whether the request to access the protected content or data should be granted comprises comparing, at the computing system, as defined by the one or more access control rules, the user identifier from the credentials and/or the network resource identifier from the credentials to the user identifier rule and the network resource rule in the one or more access control rules.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 9, 2025
From: INTELLECTUAL VENTURES ASSETS 198 LLC
To: DATASPHERE, LLC
Reel/Frame 071248/0632 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 28, 2025
From: INTELLECTUAL VENTURES II LLC
To: INTELLECTUAL VENTURES ASSETS 198 LLC
Reel/Frame 070664/0183 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 19, 2025
From: VERIFIDES TECHNOLOGY CORP.
To: ZOFILLIP PRO GROUP LLC
Reel/Frame 070555/0686 →
MERGER Recorded Mar 19, 2025
From: ZOFILLIP PRO GROUP LLC
To: INTELLECTUAL VENTURES II LLC
Reel/Frame 070555/0858 →
Continuity (9)
Continuation 17948112 · Sep 19, 2022
Continuation 16816032 · Mar 11, 2020
Continuation 16102573 · Aug 13, 2018
Continuation 15656966 · Jul 21, 2017
Continuation 14923344 · Oct 26, 2015
Continuation 14307394 · Jun 17, 2014
Continuation 11756824 · Jun 1, 2007
Provisional Application 60803683 · Jun 1, 2006
Related Publication 20240346161A1 · Oct 17, 2024
References Cited (47)
US 3893087A · Baker · 1975 [cited by applicant]
US 5715403A · Stefik · 1998 [cited by applicant]
US 5748738A · Bisbee et al. · 1998 [cited by applicant]
US 5917912A · Ginter et al. · 1999 [cited by applicant]
US 5933498A · Schneck et al. · 1999 [cited by applicant]
US 6263432B1 · Sasmazel · 2001 [cited by examiner]
US RE39621E · Kobayashi · 2007 [cited by applicant]
US 7613847B2 · Kjos et al. · 2009 [cited by applicant]
US 7788713B2 · Grobman et al. · 2010 [cited by applicant]
US 7890769B2 · Chen et al. · 2011 [cited by applicant]
US 8800008B2 · Sturtevant et al. · 2014 [cited by applicant]
US 9171176B2 · Sturtevant et al. · 2015 [cited by applicant]
US 9740872B2 · Sturtevant et al. · 2017 [cited by applicant]
US 10049225B2 · Sturtevant et al. · 2018 [cited by applicant]
US 10599859B2 · Sturtevant et al. · 2020 [cited by applicant]
US 11449622B2 · Sturtevant et al. · 2022 [cited by applicant]
US 11941134B2 · Sturtevant et al. · 2024 [cited by applicant]
US 20030101322A1 · Gardner · 2003 [cited by applicant]
US 20030149854A1 · Yoshino et al. · 2003 [cited by applicant]
US 20030149880A1 · Shamsaasef et al. · 2003 [cited by applicant]
US 20040230794A1 · England et al. · 2004 [cited by applicant]
US 20050116030A1 · Wada et al. · 2005 [cited by applicant]
US 20060004837A1 · Genovker et al. · 2006 [cited by applicant]
US 20060041761A1 · Neumann et al. · 2006 [cited by applicant]
US 20060146057A1 · Blythe · 2006 [cited by applicant]
US 20070043896A1 · Daruwala et al. · 2007 [cited by applicant]
US 20180018472A1 · Sturtevant et al. · 2018 [cited by applicant]
WO WO2007140487 · 2007 [cited by applicant]
International Search Authority: United States Patent and Trademark Office, International Search Report, PCT Application PCT/US2007/070244, mailed Apr. 1, 2008, 2 pages. [cited by applicant]
International Search Authority: United States Patent and Trademark Office, Written Opinion of the International Searching Authority, PCT Application PCT/US2007/070244, mailed Apr. 1, 2008, 3 pages. [cited by applicant]
Ohzone et al., “Random Access Memories,” in ISSCC 80, IEEE International Conference, Feb. 15, 1980, pp. 236-237. [cited by applicant]
United States Patent and Trademark Office, Advisory Action, U.S. Appl. No. 11/756,824, mailed Oct. 25, 2012, 3 pages. [cited by applicant]
United States Patent and Trademark Office, Final Office Action, U.S. Appl. No. 11/756,824, mailed Jul. 5, 2013, 27 pages. [cited by applicant]
United States Patent and Trademark Office, Final Office Action, U.S. Appl. No. 11/756,824, mailed Jun. 7, 2012, 24 pages. [cited by applicant]
United States Patent and Trademark Office, Final Office Action, U.S. Appl. No. 11/756,824, mailed Sep. 9, 2010, 17 pages. [cited by applicant]
United States Patent and Trademark Office, Non-Final Office Action, U.S. Appl. No. 11/756,824, mailed Dec. 24, 2012, 28 pages. [cited by applicant]
United States Patent and Trademark Office, Non-Final Office Action, U.S. Appl. No. 11/756,824, mailed Sep. 1, 2011, 18 pages. [cited by applicant]
United States Patent and Trademark Office, Non-Final Office Action, U.S. Appl. No. 11/756,824, filed Mar. 30, 2010, 12 pages. [cited by applicant]
United States Patent and Trademark Office, Non-Final Office Action, U.S. Appl. No. 14/307,394, mailed Nov. 20, 2014, 18 pages. [cited by applicant]
United States Patent and Trademark Office, Non-Final Office Action, U.S. Appl. No. 14/923,344, mailed Nov. 4, 2016, 15 pages. [cited by applicant]
United States Patent and Trademark Office, Non-Final Office Action, U.S. Appl. No. 15/656,966, mailed Nov. 1, 2017, 7 pages. [cited by applicant]
United States Patent and Trademark Office, Non-Final Office Action, U.S. Appl. No. 16/102,573, mailed Aug. 8, 2019, 7 pages. [cited by applicant]
United States Patent and Trademark Office, Notice of Allowance, U.S. Appl. No. 11/756,824, mailed Mar. 17, 2014, 11 pages. [cited by applicant]
United States Patent and Trademark Office, Notice of Allowance, U.S. Appl. No. 14/307,394, mailed Jun. 22, 2015, 13 pages. [cited by applicant]
United States Patent and Trademark Office, Notice of Allowance, U.S. Appl. No. 14/923,344, mailed Apr. 20, 2017, 15 pages. [cited by applicant]
United States Patent and Trademark Office, Notice of Allowance, U.S. Appl. No. 15/656,966, mailed Apr. 12, 2018, 9 pages. [cited by applicant]
United States Patent and Trademark Office, Notice of Allowance, U.S. Appl. No. 16/102,573, mailed Nov. 15, 2019, 8 pages. [cited by applicant]