Device and method for determining content of access control of data

US10747893B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10747893-B2
Application numberUS-201313961222-A
CountryUS
Kind codeB2
Filing dateAug 7, 2013
Priority dateAug 22, 2012
Publication dateAug 18, 2020
Grant dateAug 18, 2020

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Determining the content of access control to data based on classification results obtained by classifying data includes recording setting information that sets a plurality of classification engines for predetermined conditions related to either data or to the access to the data and acquiring data subject to access when access to the data subject to access is requested. Responsive to satisfaction of predetermined conditions related to either the data subject to the access or access to the data subject to access, classification of data subject to access by the plurality of classification engines set for predetermined conditions in the setting information is indicated using a processor. Further, using the processor, the content of access control to the data subject to access based on classification results obtained by the plurality of classification engines classifying data subject to access is determined based on the indicating classification of data.

First claim

Opening claim text (preview).

What is claimed is: 1. A computer-implemented method for controlling access to data subject to access control, comprising: determining that the data subject to access control is subject to an access request by a user; acquiring access information including the data subject to access control and the access request; selecting, using the access information and a classification engine reference setting file, a plurality of classification engines including a general use classification engine and a specific application classification engine; receiving, from each of the plurality of classification engines each using the same access information, a classification result thereby resulting in a plurality of classification results received from the plurality of classification engines; and denying the access request based upon the plurality of classification results, wherein each of the received classifications results are independently generated, respectively, by the plurality of classifications engines, the classification engine reference setting file defines the specific application classification engine based upon at least one condition during the access request, and each of the plurality of classification engines include: a knowledge base, a data extracting part configured to extract structured data from the data subject to access control, and a data analyzing part configured to analyze the structured data using the knowledge base. 2. The method of claim 1 , wherein the access request by a user is based upon the using intending to email the data subject to access control to an intended recipient. 3. The method of claim 1 , wherein the at least one condition includes at least one of: the data subject to access being an encrypted file, the data subject to access being located into a specific folder, and the data subject to access being a compressed file. 4. The method of claim 1 , wherein the specific application classification engine is specific to the user. 5. The method of claim 1 , wherein the access request being denied is based upon user settings upon the plurality of classification engines providing different classification results. 6. The method of claim 1 , wherein the classification engine reference setting file is specific to the user. 7. The method of claim 1 , wherein the classification engine reference setting file is specific to an intended recipient of the data subject to access control. 8. A computer hardware system configured to control access to data subject to access control, comprising: a hardware processor configured to initiate the following executable operations: determining that the data subject to access control is subject to an access request by a user; acquiring access information including the data subject to access control and the access request; selecting, using the access information and a classification engine reference setting file, a plurality of classification engines including a general use classification engine and a specific application classification engine; receiving, from each of the plurality of classification engines each using the same access information, a classification result thereby resulting in a plurality of classification results received from the plurality of classification engines; and denying the access request based upon the plurality of classification results, wherein each of the received classifications results are independently generated, respectively, by the plurality of classifications engines, the classification engine reference setting file defines the specific application classification engine based upon at least one condition during the access request, and each of the plurality of classification engines include: a knowledge base, a data extracting part configured to extract structured data from the data subject to access control, and a data analyzing part configured to analyze the structured data using the knowledge base. 9. The system of claim 8 , wherein the access request by a user is based upon the using intending to email the data subject to access control to an intended recipient. 10. The system of claim 8 , wherein the at least one condition includes at least one of: the data subject to access being an encrypted file, the data subject to access being located into a specific folder, and the data subject to access being a compressed file. 11. The system of claim 8 , wherein the specific application classification engine is specific to the user. 12. The system of claim 8 , wherein the access request being denied is based upon user settings upon the plurality of classification engines providing different classification results. 13. The system of claim 8 , wherein the classification engine reference setting file is specific to the user. 14. The system of claim 8 , wherein the classification engine reference setting file is specific to an intended recipient of the data subject to access control. 15. A computer program product, comprising: a hardware storage device having stored thereon program code for controlling access to data subject to access control, the program code, which when executed by a computer hardware system, causes the computer hardware system to perform: determining that the data subject to access control is subject to an access request by a user; acquiring access information including the data subject to access control and the access request; selecting, using the access information and a classification engine reference setting file, a plurality of classification engines including a general use classification engine and a specific application classification engine; receiving, from each of the plurality of classification engines each using the same access information, a classification result thereby resulting in a plurality of classification results received from the plurality of classification engines; and denying the access request based upon the plurality of classification results, wherein each of the received classifications results are independently generated, respectively, by the plurality of classifications engines, the classification engine reference setting file defines the specific application classification engine based upon at least one condition during the access request, and each of the plurality of classification engines include: a knowledge base, a data extracting part configured to extract structured data from the data subject to access control, and a data analyzing part configured to analyze the structured data using the knowledge base. 16. The computer program product of claim 15 , wherein the access request by a user is based upon the using intending to email the data subject to access control to an intended recipient. 17. The computer program product of claim 15 , wherein the at least one condition includes at least one of: the data subject to access being an encrypted file, the data subject to access being located into a specific folder, and the data subject to access being a compressed file. 18. The computer program product of claim 15 , wherein the specific application classification engine is specific to the user. 19. The computer program product of claim 15 , wherein the access request being denied is based upon user settings upon the plurality of classification engines providing different classification results. 20. The computer program product of claim 15 , wherein the classification engine reference

Assignees

Inventors

Classifications

  • G06F21/606Primary

    by securing the transmission between two devices or processes · CPC title

  • G06F21/62Primary

    Protecting access to data via a platform, e.g. using keys or access control rules · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10747893B2 cover?
Determining the content of access control to data based on classification results obtained by classifying data includes recording setting information that sets a plurality of classification engines for predetermined conditions related to either data or to the access to the data and acquiring data subject to access when access to the data subject to access is requested. Responsive to satisfactio…
Who is the assignee on this patent?
IBM
What technology area does this patent fall under?
Primary CPC classification G06F21/606. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Aug 18 2020 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).