Bubble-protected system for automatic decryption of file data on a per-use basis and automatic re-encryption
Abstract
A machine system includes bubble protection for protecting the information of certain classes of files from unauthorized access by way of unauthorized classes of programs at unauthorized periods of time. The machine system additionally may have OTF mechanisms for automatic decryption of confidential file data on a per-use basis and automatic later elimination of the decrypted data by scorching and/or re-encrypting is disclosed. The system can operate within a multi-threaded environment. The machine system additionally may have a digital signature mechanism for protecting file data from unauthorized tampering. The machine system additionally may have a volume-encryption mechanism for protecting plaintext versions of file data from exposure in events of power outages.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A machine system for protecting information from unauthorized access by way of unauthorized programs, said machine system comprising:
(a) data-providing means for providing data of an identified one of two or more digital data files ,where each of said files is identifiable by a file name; (b) an interceptable access mechanism through which data of an identified file of the data-providing means is accessed by identifiable, requesting programs; (c) bubble-control means coupled to intercept data access attempts made through said interceptable access mechanism by said identifiable, requesting programs, (c.1) wherein the bubble-control means includes deny/approve means for testing the intercepted data access attempts and responsively denying or approving data access to the data of an identified subset of said files based on one or both of the identity of one or more access-attempting programs and the time of the access attempt.
2 . A machine system according to claim 1 wherein said data-providing means includes:
(a.1) nonvolatile storage means for storing the two or more digital data files.
3 . A machine system according to claim 2 wherein:
(a.2) said data-providing means further includes volatile storage means for temporarily storing plaintext data derived from a selected one the two or more digital data files;
(a.1a) the two or more digital data files stored in said nonvolatile storage means include confidential data portions that are encrypted under a volume-encryption key; and
(d) said machine system further includes volume-encryption means for decrypting the confidential data portions selected one of the digital data files stored in said nonvolatile storage means after approval of access to the selected file by said deny/approve means, and for transmitting the decrypted confidential data to the volatile storage means.
4 . A machine system according to claim 1 wherein:
(b.1) said interceptable access mechanism operates within a dynamically-link loaded environment.
5 . A machine system according to claim 1 wherein:
(c.2) the bubble-control means intercepts file-OPEN requests made by said identifiable, requesting programs.
6 . A machine system according to claim 1 wherein:
(c.2) the bubble-control means posts a security alert message to a network upon denial of a file access request.
7 . A machine system according to claim 1 wherein the deny/approve means includes:
(c.1a) extension test means for comparing an extension portion of the name of a requested file with an extensions registry associating such extensions with corresponding programs that use files with such extensions; and
(c.1b) quick-approval means for returning an access approval when the requesting program is associated through the extensions registry with the extension portion of the name of the requested file.
8 . A machine system according to claim 7 wherein the deny/approve means further includes:
(c.1c) list searching means for searching one or more bubble lists, where the bubble lists define a deny or approve decision based on the satisfaction of one or more pre-defined first conditions by the identities of one or more programs that caused the data access attempt and the satisfaction of one or more predefined second conditions by the identity of the requested data file.
9 . A machine system according to claim 1 wherein the deny/approve means further includes:
(c.1b) list searching means for searching one or more bubble lists, where the bubble lists define a deny or approve decision based on the satisfaction of one or more pre-defined first conditions by the identities of one or more programs that caused the data access attempt and the satisfaction of one or more pre defined second conditions by the identity of the requested data file.
10 . A machine system according to claim 9 wherein the bubble lists include one or more linked trunk_lists, wherein each linked trunk_list has one or more file-name blocks and an end-of-trunk_list marker, and wherein the list searching means comprises:
(c.1b1) linked-trunk_list following means for searching along one or more of the linked trunk_lists for a target-query block having a file-name definition satisfied by the identity of the requested data file.
11 . A machine system according to claim 10 wherein each target-query block points to a corresponding causation-query branch_list, wherein each causation-query branch_list has one or more causation-query blocks and an end-of-branch_list marker, and wherein the list searching means comprises:
(c.1b2) causation-query branch_list following means for searching along one or more of the linked causation-query branch_lists for a causation-query block having a program-name definition satisfied by the identities of the one or more programs that caused the data access attempt.
12 . A machine system according to claim 11 wherein:
each causation-query block has a master/slave condition field for indicating whether an identified program that caused the data access attempt and satisfies the program-name definition of the causation-query block needs to be a proximate cause of the data access attempt or if it can be a non-proximate cause of the data access attempt; and
the deny/approve means is responsive to said master/slave condition field.
13 . A machine system according to claim 11 wherein:
each causation-query block has an alert data field for defining an alert action to be taken or not in the case of a denial; and
the deny/approve means is responsive to said alert data field.
14 . A machine system according to claim 11 wherein:
each causation-query block has a deny/approve field for defining whether an access approval or denial decision should be reached in the case of a condition satisfaction between the program-name definition and the an identified program that caused the data access attempt; and
the deny/approve means is responsive to said deny/approve field.
15 . A machine system according to claim 11 wherein:
each target-query block has a default alert data field for defining a default alert action to be taken or not in the case of a denial; and
the deny/approve means is responsive to said default alert data field.
16 . For use in a machine system having a data-providing means that provides data of an identified one of plural digital data files, where each of said files is identifiable by a file name, a machine-implemented method for protecting the information of said files from unauthorized access by way of unauthorized ones of identifiable programs, said method comprising the steps of:
(a) intercepting data access attempts made by access requesting programs for data in an identified one of said files; (b) first testing each intercepted data access attempt for satisfaction of a first predefined condition that defines one or both of the identity of one or more of the access requesting programs and the time of the access request; (c) second testing each intercepted data access attempt for satisfaction of a second predefined condition that defines the identity of the requested file; and (d) in response to said first and second testing steps, denying or approving access to the data of the requested file.
17 . A machine-implemented method according to claim 16 wherein:
(a.1) said intercepting step occurs within a dynamically-link loaded environment.
18 . A machine-implemented method according to claim 16 wherein said first predefined condition of the first testing step includes:
(b. 1 ) matching of the identity of at least one of the access requesting programs with a predefined first causation-query.
19 . A machine-implemented method according to claim 18 wherein said first predefined condition of the first testing step includes:
(b.2) matching of the identity of the at least one access requesting program with a predefined level of responsibility for causing the corresponding data access attempt to be made.
20 . A machine-implemented method according to claim 19 wherein said predefined level of responsibility is either MASTER or SLAVE.
21 . A machine-implemented method according to claim 16 wherein said first predefined condition of the first testing step calls for:
(b.1) a combination of plural programs responsible for the access request wherein a first such program is a MASTER and the other is a SLAVE of the first program.
22 . A machine-implemented method according to claim 16 wherein said second predefined condition of the second testing step includes:
(c.1) a target-query test that matches the identity of the requested file with a predefined second search query.
23 . A machine-implemented method according to claim 16 wherein
(d.1) an affirmative satisfaction of said first and second testing steps logically links to a specific one of an access DENY and an access APPROVE action; and
(d.2) nonsatisfaction of said first and second testing steps logically links to a default access denial action.
24 . A machine-implemented method according to claim 23 wherein
(d.3) if an affirmative satisfaction of said first and second testing steps logically links to a specific access DENY action, a corresponding logical link is further established to a specific alert action that is associated with the specific access DENY action.
25 . A machine-implemented method according to claim 24 wherein
(d.4) if nonsatisfaction of said first and second testing steps occurs, a corresponding logical link is further established to a default alert action that is associated with the corresponding default access denial action.
26 . A machine-implemented method according to claim 25 further comprising the step of:
(e) in response to a denial of the requested access, posting a correspondingly-leveled security alert message.
27 . A machine-implemented method according to claim 26 wherein
(e.1) in accordance with a prespecified level for the to-be posted security alert message, said posting is to one or more of:
(e.1a) a local terminal of a machine that originated the denied request for access;
(e.1b) a local network of the machine that originated the denied request for access; and
(e.1c) an enterprise wide network of the machine that originated the denied request for access, said enterprise wide network being larger than and including said local network.
28 . A machine system for maintaining confidential information generally in encrypted form while allowing for decryption of such confidential information into temporary plaintext form, said machine system comprising:
(a) a memory for storing a plurality of digital data files where said plurality of files includes a first file containing first data representing a pre-encrypted form of confidential first information, where said plurality of files can further include a second file containing second data representing a plaintext form of nonconfidential second information, and where each of said files is identifiable by a file name; (b) a decrypting mechanism for decrypting ciphertext data into plaintext data; (c) recryption control means for selecting one of the files stored in said memory and for causing the decrypting mechanism to decrypt data contained in the selected file and for automatically later eliminating the decrypted data, (c.1) wherein said recryption control means is responsive to a supplied exclusion list, the exclusion list identifies one or more files in said memory as excluded files that are not to be selected by the recryption control means for decryption, and the recryption control means accordingly does not select the excluded files for decryption by the decrypting mechanism; (d) an interceptable access mechanism through which data of an identified file is accessed by identifiable, requesting programs; (e) bubble-control means coupled to intercept data access attempts made through said interceptable access mechanism by said identifiable, requesting programs, (e.1) wherein the bubble-control means includes deny/approve means for testing the intercepted data access attempts and responsively denying or approving data access to the data of an identified subset of said files based on the identity of one or more access-attempting programs, and (e.2) wherein a denial by the bubble-control means prevents the decrypting mechanism from decrypting data contained in the corresponding one or more files for which access was attempted.
29 . A machine system according to claim 28 further comprising:
(g) an encrypting mechanism for encrypting plaintext data into ciphertext data;
(c.2) wherein recryption control means eliminates the decrypted data at least by scorching the decrypted data or by causing the encrypting mechanism to encrypt data contained in the selected file.
30 . In an automated machine for executing one or more application programs, where the application programs access file data of a plurality of stored files by causing interceptable file-OPEN requests and file-CLOSE requests to be sent to an operating system of said machine, and where data within a subset of the plurality of stored files is encrypted; an automatic bubble-protecting and decryption control mechanism comprising:
(a) OPEN intercept means for intercepting said interceptable file-OPEN requests; (b) selective OPEN continuance means, responsive to the intercept means, for determining whether an intercepted file-OPEN request is requesting an open of a file for which the request is to be denied based on the identity of the requested file and the identity of a requesting program, (b.1) said selective OPEN continuance means being further for determining, if the access request is not denied on the basis of said identity of the requested file and said identity of a requesting program, whether the request-invoking application program expects to use a plaintext version of the requested file's data, and if not, for allowing the intercepted file-OPEN request to continue on its way to the operating system; (c) plaintext tracking means, responsive to the selective continuance means, for determining whether a plaintext version of the sometimes encrypted data of the requested file already exists, and if so, for allowing the intercepted file-OPEN request to continue on its way to the operating system such that the plaintext version will be accessed; and (d) a decrypting mechanism, responsive to the plaintext tracking means such that on a determination that a plaintext version of the sometimes encrypted data of the requested file does not already exist, the decrypting mechanism decrypts ciphertext data within the requested file into plaintext data.
31 . A machine-implemented method for carrying out in an automated machine that executes one or more application programs, where the application programs attempt to access file data of a plurality of stored files by causing interceptable file-OPEN requests to be sent to an operating system of said machine, and where data within a subset of the plurality of stored files is to be kept encrypted most of the time; said method comprising at least the step of:
(a) determining whether an intercepted file-OPEN request is requesting an open of a file for which the request is to be denied based on the identity of the requested file and the identity of a requesting program; said method further comprising one or more of the following steps if said determining step does not generate an access denial decision: (b) using file-exclusion lists to block on-the-fly recryption of identified files that do not need to be decrypted and thereafter optionally re-encrypted; (c) using application-program exclusion lists to block from on-the-fly recryption those files that are accessed by identified application programs that do not need use decrypted plaintext of such files; and (d) decrypting the ciphertext of unblocked files on an as needed basis in response to intercepted file-OPEN requests, said decrypting not being needed where a real or phantom plaintext version thereof is already available for use.
32 . A machine-implemented, program distribution method for use in a network composed of a plurality of automated machines that each executes one or more application programs, where the application programs attempt to access file data of targeted ones of a plurality of stored files by causing interceptable file-OPEN requests to be sent to an operating system of a corresponding one of said machines, and where data of at least a subset of the plurality of stored files is protected by a bubble protection mechanism that includes a temporal-causation restricting mechanism for restricting access to the bubble-protected files based on time of attempted access via said interceptable file-OPEN requests, said program distribution method comprising the steps of:
(a) for a given program that is to be distributively installed across at least a susbset of said machines of the network, defining a class of bubble-protected files which the given program may attempt to access; (b) for each bubble-protected file in said defined class, restricting access to the respective file to a temporal period that starts at a predefined distribution completion date; and (c) trickle distributing the given program over time via the network for installation in each of said at least susbset of machines such that distribution and installation completes by said predefined distribution completion date.
33 . An instruction conveying apparatus for operatively instructing a predefined, instructable machine to carry out bubble protection actions, said bubble protection actions comprising:
(a) intercepting a file access request caused by one or more causation-events for access to targeted data having a unique identity; (b) first testing the identity of the targeted data for satisfaction of a predefined target-query condition; (c) second testing the identity of the one or more causation-events or the timing of the corresponding file access request for satisfaction of a predefined causation-query condition; and (d) in response to said first and second testings, approving or denying the intercepted file access request.
34 . The instruction conveying apparatus of claim 33 wherein said bubble protection actions further comprise:
(e) in response to a denial based on said first and second testings, posting an alert message.
35 . The instruction conveying apparatus of claim 33 wherein
(b.1) said predefined target-query condition includes wild card designations for specifying the identity of a satisfying target.
36 . The instruction conveying apparatus of claim 33 wherein
(c.1) said predefined causation-query condition includes wild card designations for specifying the identity of a satisfying causation event.
37 . The instruction conveying apparatus of claim 33 wherein
(c.1) said predefined causation-query condition includes one or more timing queries selected from the group consisting of: day of a week, time of day, day of a month, month of a year, and year.
38 . The instruction conveying apparatus of claim 33 wherein
(c.1) said predefined causation-query condition includes combinatorial logic operators at least for defining AND and OR combinations of conditions to be satisfied.Join the waitlist — get patent alerts
Track US2001044901A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.