US2007033407A1PendingUtilityA1
Systems and methods for governing content rendering, protection, and management applications
Est. expiryJun 4, 2020(expired)· nominal 20-yr term from priority
H04L 9/0891G06F 21/60H04L 9/0822H04L 2463/101H04L 9/0877H04L 2209/603H04L 63/062
51
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
System and methods are disclosed for governing digital rights management systems and other applications through the use of supervisory governance applications and keying mechanisms. Governance is provided by enabling the supervisory applications to revoke access keys and/or to block certain file system calls, thus preventing governed applications from accessing protected electronic content.
Claims
exact text as granted — not AI-modified1 - 18 . (canceled)
19 . A method of controlling access to electronic content by an application program running on a host computer system, the method including:
generating a request to access a piece of electronic content, the request being generated by the application program and comprising, at least in part, a call to a conformance library running on the host computer system; and in response to the call to the conformance library, connecting the conformance library to a governance engine on the host computer system, the governance engine being operable to govern, at least in part, the operation of the application program, the governance engine performing the following steps:
(i) performing an integrity check on the application program, the integrity check being operable to (a) detect improper modifications to at least part of the application program and (b) deny access to the piece of electronic content if an improper modification is detected; and
(ii) performing an authorization check, the authorization check being operable to (a) determine if the application program is authorized to access electronic content and (b) deny access to the piece of electronic content if authorization is not detected; and
retrieving the piece of electronic content from a file system of the host computer system if permitted by the governance engine.
20 . A method as in claim 19 , wherein the application program comprises a content rendering application.
21 . A method as in claim 19 , wherein the application program comprises a digital rights management program, the digital rights management program being operable to manage the use of the piece of electronic content in accordance with one or more rules with which the piece of electronic content is associated.
22 . A method as in claim 19 , wherein performing the authorization check includes examining one or more digital certificates associated with the application program, the one or more digital certificates specifying, at least in part, the nature of the application program's authorization to access electronic content.
23 . A method as in claim 22 , wherein one or more of the digital certificates is operable to expire at a predefined time, and wherein the application program's authorization to access electronic content expires when said one or more digital certificates expire.
24 . A method as in claim 23 , wherein the governance engine is operable to receive one or more new digital certificates to replace one or more expired digital certificates, and wherein the application program's authorization to access electronic content is renewed when said one or more new digital certificates are received by the governance engine.
25 . A method as in claim 19 , wherein performing the integrity check includes generating a cryptographic hash of at least part of the application program, and comparing the generated cryptographic hash to a previously generated cryptographic hash.
26 . A method of controlling access to electronic content, the method comprising:
receiving, at a conformance library running on a computer system, a request from a governed application running on the computer system to access a piece of electronic content, wherein the conformance library implements one or more interfaces that the governed application calls to access the electronic content, and wherein the request to access the piece of electronic content comprises at least a first call to at least a first interface of said one or more interfaces that the conformance library implements; connecting to a supervisory application, the supervisory application being operable to check a credential associated with the governed application, the supervisory application being further operable to disable access to the piece of electronic content by the governed application if the credential check fails; and enabling access to the piece of electronic content by the governed application after completion of a successful credential check, wherein said enabling step includes making at least a second call to at least a second interface, and wherein the second interface comprises a file input/output interface of the computer system that corresponds to said first interface implemented by the conformance library.
27 . The method of claim 26 , further comprising invoking the supervisory application prior to the step of connecting to the supervisory application.
28 . The method of claim 26 , wherein the credential check comprises an integrity check on the governed application, the integrity check being operable to (a) detect improper modifications to at least part of the governed application and (b) deny access to the piece of electronic content if an improper modification is detected.
29 . The method of claim 26 , wherein the supervisory application is further operable to perform an authorization check, the authorization check being operable to (a) determine if the governed application is authorized to access the piece of electronic content and (b) deny access to the piece of electronic content if authorization is not detected.
30 . A computer-readable storage medium storing instructions that, when executed by a computer, cause the computer to perform steps comprising:
receiving a request from a governed application running on the computer to access a piece of electronic content, wherein the request to access the piece of electronic content comprises at least a first call to at least a first interface; connecting to a supervisory application running on the computer, the supervisory application being operable to check a credential associated with the governed application, the supervisory application being further operable to disable access to the piece of electronic content by the governed application if the credential check fails; and enabling access to the piece of electronic content by the governed application upon completion of a successful credential check, wherein said enabling includes making at least a second call to at least a second interface, and wherein the second interface comprises a file input/output interface of the computer that corresponds to said first interface.
31 . The medium of claim 30 , further comprising instructions that, when executed by the computer, cause the computer to invoke the supervisory application prior to connecting to the supervisory application.
32 . The medium of claim 30 , wherein the credential check comprises an integrity check, the integrity check being operable to (a) detect improper modifications to at least part of the governed application and (b) deny access to the piece of electronic content if an improper modification is detected.
33 . The medium of claim 30 , further comprising instructions that, when executed by the computer, cause the computer to perform an authorization check, the authorization check being operable to (a) determine if the governed application is authorized to access the piece of electronic content, and (b) deny access to the piece of electronic content if authorization is not detected.Join the waitlist — get patent alerts
Track US2007033407A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.