Secure data container for web applications

US9245144B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9245144-B2
Application numberUS-201213628502-A
CountryUS
Kind codeB2
Filing dateSep 27, 2012
Priority dateSep 27, 2012
Publication dateJan 26, 2016
Grant dateJan 26, 2016

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Systems and methods may provide for identifying web content and detecting an attempt by the web content to access a local data store. Additionally, a determination may be made as to whether to permit the attempt based on a context-based security policy. In one example, the context-based security policy is obtained from one or more of a user profile, a multi-user data source and a cloud service.

First claim

Opening claim text (preview).

We claim: 1. An apparatus comprising: an operating system-independent and browser-independent data container including a web application interface that obtains web content and detects an attempt by the web content to access a local data store due to at least a portion of the web content being written in one or more of a runtime or a just in time (JIT) environment language; an enforcement module in the data container to determine whether to permit the attempt based on a context-based security policy for the identified web content wherein the enforcement module is to obtain the context-based security policy from one or more of a user profile, a multi-user data source and a cloud service and wherein the context-based security policy is to identify one or more of a type of content, a content source and a browsing sequence; and a user interface in the data container to generate a first user prompt for authorization to implement an action associated with the context-based security policy, wherein the first user prompt is to include one or more multi-user statistics. 2. The apparatus of claim 1 , wherein the user interface is to receive a first user response to the first user prompt and generate a second user prompt for a reason associated with the first user prompt. 3. The apparatus of claim 2 , wherein the user interface is to receive a second user response to the second user prompt and transmit the first user response and the second user response to a multi-user data source. 4. The apparatus of claim 1 , further including the local data store positioned outside the data container. 5. At least one non-transitory computer readable storage medium comprising a set of instructions which, if executed by a processor, cause a computing device to: use an operating system-independent and browser-independent data container including a web application interface to identify web content; detect an attempt by the web content to access a local data store positioned outside the data container; determine whether to permit the attempt by the web content based on a context-based security policy in an enforcement module in the data container, the context-based security policy being obtainable from one or more of a user profile, a multi-user data source and a cloud service and wherein the context-based security policy is to identify one or more of a type of content, a content source and a browsing sequence; and generate a first user prompt for authorization to implement an action associated with the context-based security policy, wherein the first user prompt is to include one or more multi-user statistics. 6. The at least one medium of claim 5 , wherein the instructions, if executed, cause a computing device to: receive a first user response to the first user prompt; and generate a second user prompt for a reason associated with the first user response. 7. The at least one medium of claim 6 , wherein the instructions, if executed, cause a computing device to: receive a second user response to the second user prompt; and transmit the first user response and the second user response to a multi-user data source. 8. A method comprising: using an operating system-independent and browser-independent data container including a web application interface to identify web content; detecting an attempt by the web content to access a local data store positioned outside the data container; and determining whether to permit the attempt by the web content based on a context-based security policy in an enforcement module in the data container; and generating a first user prompt for authorization to implement an action associated with the context-based security policy, wherein the first user prompt includes one or more multi-user statistics. 9. The method of claim 8 , further including obtaining the context-based security policy from one or more of a user profile, a multi-user data source and a cloud service. 10. The method of claim 9 , wherein the context-based security policy identifies one or more of a type of content, a content source and a browsing sequence. 11. The method of claim 8 , further including: receiving a first user response to the first user prompt; and generating a second user prompt for a reason associated with the first user response. 12. The method of claim 11 , further including: receiving a second user response to the second user prompt; and transmitting the first user response and the second user response to a multi-user data source.

Assignees

Inventors

Classifications

  • to a system of files or objects, e.g. local or distributed file system or database · CPC title

  • Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems · CPC title

  • Protecting access to data via a platform, e.g. using keys or access control rules · CPC title

  • Entity profiles · CPC title

  • by executing in a restricted environment, e.g. sandbox or secure virtual machine · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9245144B2 cover?
Systems and methods may provide for identifying web content and detecting an attempt by the web content to access a local data store. Additionally, a determination may be made as to whether to permit the attempt based on a context-based security policy. In one example, the context-based security policy is obtained from one or more of a user profile, a multi-user data source and a cloud service.
Who is the assignee on this patent?
Intel Corp
What technology area does this patent fall under?
Primary CPC classification G06F21/6218. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Jan 26 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).