The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Jul. 18, 2017

Filed:

Aug. 25, 2015
Applicant:

Virtru Corporation, Washington, DC (US);

Inventor:

William R. Ackerly, Washington, DC (US);

Assignee:

Virtru Corporation, Washington, DC (US);

Attorneys:
Primary Examiner:
Int. Cl.
CPC ...
G06F 21/00 (2013.01); G06F 21/60 (2013.01); G06F 21/62 (2013.01); H04L 29/06 (2006.01); G06F 9/46 (2006.01); G06F 11/30 (2006.01); G06F 12/14 (2006.01); G06F 7/04 (2006.01); G06F 17/30 (2006.01);
U.S. Cl.
CPC ...
G06F 21/602 (2013.01); G06F 9/468 (2013.01); G06F 21/6281 (2013.01); H04L 63/0428 (2013.01); G06F 2221/2107 (2013.01); G06F 2221/2141 (2013.01); H04L 63/0892 (2013.01); H04L 2463/101 (2013.01);
Abstract

A method of providing a restricted set of application programming interfaces includes decrypting, by a secure object information reader executing on a computing device, an encrypted data object using information associated with the encrypted data object to generate a decrypted data object, the information received from an access control management system. The method includes intercepting, by a kernel driver executing on the computing device, from a process executing on the computing device, a request to access the decrypted data object. The method includes identifying, by the kernel driver, using the information associated with the encrypted data object, a usage requirement restricting a set of operations available to the process in accessing the decrypted data object. The method includes providing, by the kernel driver, to the process, a restricted set of application programming interfaces with which to interact with the decrypted data object, as permitted by the restricted set of operations.


Find Patent Forward Citations

Loading…