Detecting, enforcing and controlling access privileges based on sandbox usage

US9836614B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9836614-B2
Application numberUS-201414508519-A
CountryUS
Kind codeB2
Filing dateOct 7, 2014
Priority dateSep 27, 2012
Publication dateDec 5, 2017
Grant dateDec 5, 2017

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Systems and methods may provide for receiving web content and detecting an access control attribute associated with the web content. Additionally, the access control attribute may be monitored for a disablement condition. In one example, the disablement condition may be detected, an access policy may be determined in response to the disablement condition, and the access policy may be implemented. Other embodiments are described and claimed.

First claim

Opening claim text (preview).

We claim: 1. A method comprising: receiving web content locally at a device relative to a remote web content source device; detecting an enablement of an access control attribute associated with the web content that is to indicate the access control attribute is to operate, wherein the enablement prevents local operability at the device of at least one function of the web content, and wherein the access control attribute includes a Hypertext Markup Language 5 (HTML5) sandbox attribute; detecting a disablement of the access control attribute that is to indicate the access control attribute is not to operate, wherein the disablement permits local operability at the device of the at least one function of the web content; and determining an access policy in response to the disablement including one or more of: identifying one or more functions of the web content in response to the disablement and using the one or more functions to determine the access policy; and identifying a requestor application identity associated with the disablement and using the requestor application identity to determine the access policy. 2. The method of claim 1 , further including implementing the access policy. 3. The method of claim 2 , wherein implementing the access policy includes enabling the access control attribute from the disablement. 4. The method of claim 2 , wherein implementing the access policy includes generating a user notification, wherein the user notification includes an identification of the disablement and a recommended action. 5. The method of claim 4 , wherein implementing the access policy includes: receiving a response to the user notification; and determining whether to modify the access control attribute based on the response. 6. The method of claim 2 , further including: determining that the access control attribute cannot be enabled without impacting the web content; and disallowing the web content. 7. The method of claim 1 , further including using the one or more functions to retrieve at least a portion of the access policy from a policy repository. 8. The method of claim 1 , further including using the requestor application identity to retrieve at least a portion of the access policy from a profile repository. 9. At least one non-transitory computer readable storage medium comprising a set of instructions which, if executed by a processor, cause a computing device to: receive web content locally at a device relative to a remote web content source device; detect an enablement of an access control attribute associated with the web content that is to indicate the access control attribute is to operate, wherein the enablement is to prevent local operability at the device of at least one function of the web content, and wherein the access control attribute is to include a Hypertext Markup Language 5 (HTML5) sandbox attribute; detect a disablement of the access control attribute that is to indicate the access control attribute is not to operate, wherein the disablement is to permit local operability at the device of the at least one function of the web content; and determine an access policy in response to the disablement including one or more of: identification of one or more functions of the web content in response to the disablement and use of the one or more functions to determine the access policy; and identification of a requestor application identity associated with the disablement and use of the requestor application identity to determine the access policy. 10. The at least one non-transitory computer readable storage medium of claim 9 , wherein the instructions, if executed, cause a computing device to implement the access policy. 11. The at least one non-transitory computer readable storage medium of claim 10 , wherein the instructions, if executed, cause a computing device to enable the access control attribute from the disablement to implement the access policy. 12. The at least one non-transitory computer readable storage medium of claim 10 , wherein the instructions, if executed, cause a computing device to generate a user notification, wherein the user notification is to include an identification of the disablement and a recommended action to implement the access policy. 13. The at least one non-transitory computer readable storage medium of claim 12 , wherein the instructions, if executed, cause a computing device to: receive a response to the user notification; and determine whether to modify the access control attribute based on the response to implement the access policy. 14. The at least one non-transitory computer readable storage medium of claim 10 , wherein the instructions, if executed, cause a computing device to: determine that the access control attribute cannot be enabled without impacting the web content; and disallow the web content. 15. The at least one non-transitory computer readable storage medium of claim 9 , wherein the instructions, if executed, cause a computing device to use the one or more functions to retrieve at least a portion of the access policy from a policy repository. 16. The at least one non-transitory computer readable storage medium of claim 9 , wherein the instructions, if executed, cause a computing device to use the requestor application identity to retrieve at least a portion of the access policy from a profile repository. 17. An apparatus comprising: one or more of configurable logic hardware and fixed functionality logic hardware; logic, implemented at least partly in the one or more of configurable logic hardware and fixed functionality logic hardware; a browser module, implemented using the logic hardware, to receive web content locally at a device relative to a remote web content source device; and a security manager, implemented using the logic hardware, to: detect an enablement of an access control attribute of the web content that is to indicate the access control attribute is to operate, wherein the enablement is to prevent local operability at the device of at least one function of the web content, and wherein the access control attribute is to include a Hypertext Markup Language 5 (HTML5) sandbox attribute; detect a disablement of the access control attribute that is to indicate the access control attribute is not to operate, wherein the disablement is to permit local operability at the device of the at least one function of the web content; and determine an access policy in response to the disablement including one or more of: identification of one or more functions of the web content in response to the disablement and use of the one or more functions to determine the access policy; and identification of a requestor application identity associated with the disablement and use of the requestor application identity to determine the access policy. 18. The apparatus of claim 17 , wherein the security manager is further to: implement the access policy; use the one or more functions to retrieve at least a portion of the access policy from the policy repository; and use the requestor application identity to retrieve at least a portion of the access policy from the profile repository.

Assignees

Inventors

Classifications

  • during internet communication, e.g. revealing personal data from cookies · CPC title

  • G06F21/62Primary

    Protecting access to data via a platform, e.g. using keys or access control rules · CPC title

  • by executing in a restricted environment, e.g. sandbox or secure virtual machine · CPC title

  • involving web programs, i.e. using technology especially used in internet, generally interacting with a web browser, e.g. hypertext markup language [HTML], applets, java · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9836614B2 cover?
Systems and methods may provide for receiving web content and detecting an access control attribute associated with the web content. Additionally, the access control attribute may be monitored for a disablement condition. In one example, the disablement condition may be detected, an access policy may be determined in response to the disablement condition, and the access policy may be implemente…
Who is the assignee on this patent?
Intel Corp
What technology area does this patent fall under?
Primary CPC classification G06F21/6263. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Dec 05 2017 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).