System for controlling access and distribution of digital property
Abstract
Digital data protection is provided by a processor running an operating system programmed to generate one or more interrupts; an access mechanism detects one or more interrupts at or below a BIOS level, a given detected interrupt being associated with an operating system request to access protected portions of the data, and restricts access to the protected portions of the data by the operating system in accordance with at least one rule; a tamper detecting mechanism prevents access to the data in an unprotected form has means for destroying data stored in the access mechanism when tampering is detected.
Claims
exact text as granted — not AI-modified1 . An apparatus for the protection of digital data comprising:
a first processor programmed to run an operating system, the operating system programmed to generate one or more interrupts; an access mechanism including access control software run on a second processor and a memory, the access mechanism operative to: detect one or more interrupts at or below a BIOS level, a given detected interrupt being associated with an operating system request to access protected portions of the data; restrict access to the protected portions of the data by the operating system in accordance with at least one rule; and a tamper detecting mechanism operative to prevent access to the data in an unprotected form comprising means for destroying data stored in the access mechanism when tampering is detected.
2 . The apparatus of claim 1 , wherein the first processor interfaces with output peripheral devices to send packaged data only through the access mechanism.
3 . The apparatus of claim 2 , wherein the output peripheral devices include at least one of a display, a printer a disk drive and a network interface.
4 . The apparatus of claim 1 , wherein the memory is configured to store the at least one rule and the protected portions of the data.
5 . The apparatus of claim 1 , wherein the rules and the protected portions of the data are received separately.
6 . The apparatus of claim 1 , wherein the rules and the protected portions of the date are received as a package.
7 . The apparatus of claim 1 , wherein both the rules and the protected portions of the data are encrypted.
8 . The apparatus of claim 1 , wherein the rules indicate at least one of
(a) which users are allowed to access the protected data, (b) distribution rights of the data, (c) access control rights of the user, (d) access control quantities, and (e) payment requirements, and when the rules indicate which users are allowed to access the protected portions of the data, the device further comprises:
means for allowing the user access to a protected portion of the data only if the rules indicate that the user is allowed to access that portion of the data;
when the rules indicate distribution rights of the data, the device further comprises:
means for allowing distribution of the data only in accordance with the distribution rights indicated in the rules;
when the rules indicate access control rights of the user, the device further comprises:
means for allowing the user to access the data only in accordance with the access control rights indicated in the rules;
when the rules indicate access control quantities, the device further comprises:
means for allowing access to the data only in accordance with the access control quantities indicated in the rules;
when the rules indicate payment requirements, the device further comprising:
means for allowing access to the data only if the payment requirements indicated in the rules are satisfied.
9 . The apparatus of claim 1 , wherein the access mechanism only permits output of the protected portions of the data to output peripheral devices in accordance with the rules.
10 . A method comprising:
receiving protected data at an access mechanism, the access mechanism including access control software, a first processor and a memory device; transmitting an unprotected form of the protected data to a second processor in accordance with at least one rule; detecting, through the use of the access mechanism, an interrupt at or below a BIOS level, the detected interrupt comprising a request to output the unprotected form of the protected data to an output peripheral device; outputting the unprotected form of the protected data to the output peripheral device through the access mechanism in accordance with the at least one rule.
11 . The method of claim 10 , the method further comprising the step of destroying data when tampering is detected.
12 . The method of claim 10 , wherein the rules and the data are received as a package.
13 . The method of claim 10 , wherein the rules and the data are received separately.
14 . The method of claim 10 , further comprising: outputting the unprotected form of the protected data to the access mechanism;
encrypting the unprotected form of the protected data to protect the data and outputting the protected data to a memory device in accordance with the at least one rule.
15 . The method of claim 10 , further comprising: outputting the unprotected form of the protected data to the access mechanism;
encrypting the unprotected form of the protected data to protect the data and outputting the protected data to a memory device in accordance with the at least one rule.
16 . The method of claim 10 , wherein the rules indicate at least one of
(a) which users are allowed to access the protected portions of the data, (b) distribution rights of the data, (c) access control rights of the user, (d) access control quantities, and (e) payment requirements, and when the rules indicate which users are allowed to access the protected portions of the data, the method further comprises the step of:
allowing the user access to a protected portion of the data only if the rules indicate that the user is allowed to access that portion of the data;
when the rules indicate distribution rights of the data, the method further comprises the step of:
allowing distribution of the data only in accordance with the distribution rights indicated in the rules;
when the rules indicate access control rights of the user, the method further comprises the step of:
allowing the user to access the data only in accordance with the access control rights indicated in the rules;
when the rules indicate access control quantities, the method further comprises the step of:
allowing access to the data only in accordance with the access control quantities indicated in the rules;
when the rules indicate payment requirements, the method further comprises the step of:
allowing access to the data only if the payment requirements indicated in the rules are satisfied.
17 . The method as in claim 16 , wherein access control rights include at least one of:
(a) local display rights, (b) printing rights, (c) copying rights, (d) execution rights, (e) transmission rights, and (f) modification rights, and wherein the access control quantities include at least one of: (g) a number of allowed read-accesses to the data; (h) an allowable size of a read-access to the data; (i) an expiration date of the data; (j) an intensity of access to the data; (k) an allowed level of accuracy and fidelity; (l) an allowed resolution of access to the data; and (m) a valid start date of the data.
18 . The method of claim 10 further comprising:
the access mechanism is further operative to at least one of: alter and revoke the rules.
19 . The method of claim 10 , wherein the rules are validated at a predetermined time interval.
20 . The method of claim 10 , wherein the rules indicate distribution rights of the data such that a receiver of the data may request transfer of a protected file to a list of new persons and grant them at least one of: same or modified access rules.
21 . The method of claim 10 , wherein the rules indicate access control rights given a user the ability to grant another user control of access rules to protect content.
22 . The method of claim 10 further comprising:
at least one of: altering and revoking the rules using the access mechanism.
23 . The method of claim 10 , wherein the rules are validated at a predetermined time interval.
24 . The method of claim 10 , wherein the rules indicate distribution rights of the data such that a receiver of the data may request transfer of a protected file to a list of new persons and grant them at least one of: same or modified access rules.
25 . The method of claim 10 , wherein the rules indicate access control rights given a user the ability to grant another user control of access rules to protect content.Join the waitlist — get patent alerts
Track US2009222673A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.