Nova Patents
EP3192002A2

Preserving data protection with policy

Abstract

This record has no abstract on file.

Term

9 yearsto projected expiry

Projected expiry 7 September 2035, counted from filing; an application has no term until it is granted.

  1. Priority
  2. Filed
  3. Published
  4. Today
  5. Projected expiry

15 claims: 10 independent, 5 dependent

  1. 1
    Claims of equivalent WO 2016040204 A2 CLAIMS 1. A method implemented in a computing device, the method comprising:identifying an entity-trusted application on the computing device, the entity-trusted application configured to access data;associating a first process that is a running instance of the entity-trusted application with an identifier of an entity that sets a data protection policy controlling access to the data;and enforcing, by an operating system of the computing device, the data protection policy of the entity to enhance data security provided by the computing device due to the operating system enforcing the data protection policy on behalf of the entity-trusted application, the enforcing including: automatically encrypting, by the operating system in accordance with the data protection policy, data saved by the first process;and preventing, by the operating system in accordance with the data protection policy, a second process that is a running instance of an entity-untrusted application from accessing the encrypted data.
  2. 4
    The method as recited in claims 1 to 3, the first process including multiple threads, and the enforcing the data protection policy includes enforcing the data protection policy for a first set of one or more of the multiple threads but not for a second set of one or more of the multiple threads.
  3. 5
    The method as recited in claims 1 to 4, further comprising treating the entity- trusted application as being an untrusted application for at least part of the data protection policy in response to a request from the first process for the operating system to treat the entity-trusted application as an entity-untrusted application.
  4. 6
    The method as recited in claims 1 to 5, the first process having multiple threads, and the first process requesting that the operating system treat a first set of one or more of the multiple threads, but not a second set of one or more of the multiple threads, as untrusted to obtain different policy enforcement behavior for the first set of one or more threads than for the second set of one or more threads.
  5. 7
    The method as recited in claims 1 to 6, the enforcing further including protecting the data when communicating the data to another device via a network, during buffer read operations and buffer write operations, and during clipboard read operations and clipboard write operations.
  6. 8
    The method as recited in claims 1 to 7, the enforcing further including saving the encrypted data in a container file that includes both metadata and the encrypted data, the metadata including the identifier of the entity.
  7. 10
    The method as recited in claims 1 to 9, further comprising performing the enforcing in the absence of logical or visual isolation of:the entity-trusted application and the entity-untrusted application in separate application containers;and a user of the computing device logging into different user accounts.
  8. 11
    A computing device comprising:a processing system comprising one or more processors;and one or more computer-readable storage media having stored thereon multiple instructions that, when executed by the processing system, cause the processing system to perform acts comprising: identifying a first application on the computing device, the first application configured to access data that is encrypted;associating a data file that includes the data with an identifier of an owner of the data, the owner of the data setting data protection policy controlling access to the data, the identifier of the owner of the data being separate from an identifier of a user that is logged into the computing device;associating a first process that is a running instance of the first application with the identifier of the owner of the data;and enforcing, by an operating system of the computing device, the data protection policy of the owner to enhance data security provided by the computing device due to the operating system enforcing the data protection policy on behalf of the first application, the enforcing including: allowing the data to be decrypted into plaintext data that is provided to the first process;and preventing the data from being decrypted into plaintext data and provided to a second process that is a running instance of a second application, the second process not being associated with the identifier of the owner of the data.
  9. 14
    The computing device as recited in claims 11 to 13, the enforcing further including allowing additional data stored in a data buffer of the computing device to be decrypted into plaintext data that is provided to the first process, but preventing the additional data from being decrypted into plaintext data and provided to the second process.
  10. 15
    The computing device as recited in claims 11 to 14, the enforcing further including protecting, by the operating system and based on a key of the owner, data copied to a clipboard of the computing device by the first process, but preventing data copied to the clipboard by the second process from being associated with the owner.