US2009222673A1PendingUtilityA1

System for controlling access and distribution of digital property

Assignee: VERIFIDES TECHNOLOGY CORPPriority: Jan 11, 1996Filed: May 15, 2009Published: Sep 3, 2009
Est. expiryJan 11, 2016(expired)· nominal 20-yr term from priority
G06F 2221/2143H04L 9/0822G06F 21/34G06Q 30/018G06F 21/577G06F 21/86H04L 9/08G06F 21/72G06F 2211/007G06F 21/71G06F 2221/2149G06F 2221/2145G06F 21/6209G06F 21/6245H04L 2463/101H04L 2209/56G11B 20/00673G06F 21/62H04L 63/0428G06F 21/32G06F 2221/2141G06F 2221/2137G06F 21/1062G06F 21/1063G06F 21/16G06F 21/109G06F 21/1011
52
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Digital data protection is provided by a processor running an operating system programmed to generate one or more interrupts; an access mechanism detects one or more interrupts at or below a BIOS level, a given detected interrupt being associated with an operating system request to access protected portions of the data, and restricts access to the protected portions of the data by the operating system in accordance with at least one rule; a tamper detecting mechanism prevents access to the data in an unprotected form has means for destroying data stored in the access mechanism when tampering is detected.

Claims

exact text as granted — not AI-modified
1 . An apparatus for the protection of digital data comprising:
 a first processor programmed to run an operating system, the operating system programmed to generate one or more interrupts;   an access mechanism including access control software run on a second processor and a memory, the access mechanism operative to:   detect one or more interrupts at or below a BIOS level, a given detected interrupt being associated with an operating system request to access protected portions of the data;   restrict access to the protected portions of the data by the operating system in accordance with at least one rule; and   a tamper detecting mechanism operative to prevent access to the data in an unprotected form comprising means for destroying data stored in the access mechanism when tampering is detected.   
     
     
         2 . The apparatus of  claim 1 , wherein the first processor interfaces with output peripheral devices to send packaged data only through the access mechanism. 
     
     
         3 . The apparatus of  claim 2 , wherein the output peripheral devices include at least one of a display, a printer a disk drive and a network interface. 
     
     
         4 . The apparatus of  claim 1 , wherein the memory is configured to store the at least one rule and the protected portions of the data. 
     
     
         5 . The apparatus of  claim 1 , wherein the rules and the protected portions of the data are received separately. 
     
     
         6 . The apparatus of  claim 1 , wherein the rules and the protected portions of the date are received as a package. 
     
     
         7 . The apparatus of  claim 1 , wherein both the rules and the protected portions of the data are encrypted. 
     
     
         8 . The apparatus of  claim 1 , wherein the rules indicate at least one of
 (a) which users are allowed to access the protected data,   (b) distribution rights of the data,   (c) access control rights of the user,   (d) access control quantities, and   (e) payment requirements, and   when the rules indicate which users are allowed to access the protected portions of the data, the device further comprises:
 means for allowing the user access to a protected portion of the data only if the rules indicate that the user is allowed to access that portion of the data; 
   when the rules indicate distribution rights of the data, the device further comprises:
 means for allowing distribution of the data only in accordance with the distribution rights indicated in the rules; 
   when the rules indicate access control rights of the user, the device further comprises:
 means for allowing the user to access the data only in accordance with the access control rights indicated in the rules; 
   when the rules indicate access control quantities, the device further comprises:
 means for allowing access to the data only in accordance with the access control quantities indicated in the rules; 
   when the rules indicate payment requirements, the device further comprising:
 means for allowing access to the data only if the payment requirements indicated in the rules are satisfied. 
   
     
     
         9 . The apparatus of  claim 1 , wherein the access mechanism only permits output of the protected portions of the data to output peripheral devices in accordance with the rules. 
     
     
         10 . A method comprising:
 receiving protected data at an access mechanism, the access mechanism including access control software, a first processor and a memory device;   transmitting an unprotected form of the protected data to a second processor in accordance with at least one rule;   detecting, through the use of the access mechanism, an interrupt at or below a BIOS level, the detected interrupt comprising a request to output the unprotected form of the protected data to an output peripheral device;   outputting the unprotected form of the protected data to the output peripheral device through the access mechanism in accordance with the at least one rule.   
     
     
         11 . The method of  claim 10 , the method further comprising the step of destroying data when tampering is detected. 
     
     
         12 . The method of  claim 10 , wherein the rules and the data are received as a package. 
     
     
         13 . The method of  claim 10 , wherein the rules and the data are received separately. 
     
     
         14 . The method of  claim 10 , further comprising: outputting the unprotected form of the protected data to the access mechanism;
 encrypting the unprotected form of the protected data to protect the data and outputting the protected data to a memory device in accordance with the at least one rule.   
     
     
         15 . The method of  claim 10 , further comprising: outputting the unprotected form of the protected data to the access mechanism;
 encrypting the unprotected form of the protected data to protect the data and outputting the protected data to a memory device in accordance with the at least one rule.   
     
     
         16 . The method of  claim 10 , wherein the rules indicate at least one of
 (a) which users are allowed to access the protected portions of the data,   (b) distribution rights of the data,   (c) access control rights of the user,   (d) access control quantities, and   (e) payment requirements, and   when the rules indicate which users are allowed to access the protected portions of the data, the method further comprises the step of:
 allowing the user access to a protected portion of the data only if the rules indicate that the user is allowed to access that portion of the data; 
   when the rules indicate distribution rights of the data, the method further comprises the step of:
 allowing distribution of the data only in accordance with the distribution rights indicated in the rules; 
   when the rules indicate access control rights of the user, the method further comprises the step of:
 allowing the user to access the data only in accordance with the access control rights indicated in the rules; 
   when the rules indicate access control quantities, the method further comprises the step of:
 allowing access to the data only in accordance with the access control quantities indicated in the rules; 
   when the rules indicate payment requirements, the method further comprises the step of:
 allowing access to the data only if the payment requirements indicated in the rules are satisfied. 
   
     
     
         17 . The method as in  claim 16 , wherein access control rights include at least one of:
 (a) local display rights,   (b) printing rights,   (c) copying rights,   (d) execution rights,   (e) transmission rights, and   (f) modification rights,   and wherein the access control quantities include at least one of:   (g) a number of allowed read-accesses to the data;   (h) an allowable size of a read-access to the data;   (i) an expiration date of the data;   (j) an intensity of access to the data;   (k) an allowed level of accuracy and fidelity;   (l) an allowed resolution of access to the data; and   (m) a valid start date of the data.   
     
     
         18 . The method of  claim 10  further comprising:
 the access mechanism is further operative to at least one of: alter and revoke the rules.   
     
     
         19 . The method of  claim 10 , wherein the rules are validated at a predetermined time interval. 
     
     
         20 . The method of  claim 10 , wherein the rules indicate distribution rights of the data such that a receiver of the data may request transfer of a protected file to a list of new persons and grant them at least one of: same or modified access rules. 
     
     
         21 . The method of  claim 10 , wherein the rules indicate access control rights given a user the ability to grant another user control of access rules to protect content. 
     
     
         22 . The method of  claim 10  further comprising:
 at least one of: altering and revoking the rules using the access mechanism.   
     
     
         23 . The method of  claim 10 , wherein the rules are validated at a predetermined time interval. 
     
     
         24 . The method of  claim 10 , wherein the rules indicate distribution rights of the data such that a receiver of the data may request transfer of a protected file to a list of new persons and grant them at least one of: same or modified access rules. 
     
     
         25 . The method of  claim 10 , wherein the rules indicate access control rights given a user the ability to grant another user control of access rules to protect content.

Join the waitlist — get patent alerts

Track US2009222673A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.