Manage application-specific feature permissions

By managing application-specific feature permissions (ASFR) in the file system, the problem of feature permission management for different users in the collaborative working environment is solved, and flexible permission control and feature management in the subscription mode is realized, which improves the management efficiency and consistency of application functions.

CN113761484BActive Publication Date: 2025-07-11MICROSOFT TECHNOLOGY LICENSING LLC
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111095090.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2015-10-19
Filing Date
2016-10-05
Publication Date
2025-07-11
Estimated Expiration
2036-10-05

AI Technical Summary

Technical Problem

In a collaborative working environment, the flexibility and consistency of managing feature permissions is difficult to achieve when users use different versions of application software, especially after the transition from the traditional boxed software model to the freemium model, users may have different application versions and feature permissions.

Method used

By storing and managing application-specific feature permissions (ASFRs) in the file system, which are associated with a file or file location, allow or limit the activation of features, support a file-based feature permission model, including detecting, modifying, and sending files for dynamic management of permissions.

Benefits of technology

It realizes flexible feature permission management for different users and devices, supports feature management of third-party plug-ins, ensures feature permissions are transmitted together with files, supports permission control and renewal mechanisms in subscription mode, and improves the management efficiency and consistency of application functions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113761484B_ABST
    Figure CN113761484B_ABST
Patent Text Reader

Abstract

The present disclosure relates to various systems and methods for modifying application-specific feature permissions. In an example, a system for modifying application-specific feature permissions (ASFRs) is disclosed. An exemplary system may include a file system for storing files, where the file system includes a plurality of ASFRs corresponding to the files, and the plurality of ASFRs specify client types for triggering activation of features indicated by the plurality of ASFRs. The system may include a processor and a memory storage device storing executable instructions to be executed by the processor to cause a modification service implemented on a computing device to perform actions. The system also modifies the file to indicate the plurality of ASFRs associated with the file. The system is also capable of sending the modified file to a first user device.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application is a divisional application of the patent application "Managing Application-Specific Feature Permissions" with an application date of October 5, 2016 and an application number of 201680061171.2. Background Art

[0002] The software industry is moving from a model of simple perpetual licenses for selling application software to a new "freemium" model, in which users can utilize some functions of an application for free, but users may be required to pay for premium features, functions, or unlimited use. Thus, different application versions can provide different features or different editing functions and tools for the application depending on whether it is a paid or unpaid version of the application. The available features can also work on a tiered system, where certain payments only enable certain features rather than all features. Summary of the Invention

[0003] A simplified summary is presented below to provide a basic understanding of some aspects described herein. This summary of the invention is not an extensive overview of the claimed subject matter. This summary of the invention is also not intended to identify key or essential elements of the claimed subject matter, nor to delineate the scope of the claimed subject matter. The sole purpose of this summary of the invention is to present some concepts of the claimed subject matter in a simplified form as a prelude to the more detailed description that is presented later.

[0004] An embodiment provides a system for modifying application-specific feature permissions, including a processor and a file system for storing files, where the file system includes a plurality of application-specific feature rights (ASFRs) corresponding to the files. The system may also include a plurality of ASFRs that specify the client types that can trigger the activation of the features indicated by the ASFRs. The system may include a processor and a computer-readable memory storage device that stores executable instructions that are to be executed by the processor to cause a modification service implemented on a computing device to perform actions. The system can also detect the selection of a file stored in the file system. In an example, the system can modify the file to indicate the plurality of ASFRs associated with the file. The system can also send the modified file to a first user device.

[0005] One embodiment provides a method for modifying ASFRs. The method may include detecting the selection of a file stored in a file system, the file system including a plurality of ASFRs corresponding to the file. The method may include using a processor to modify the file to indicate the plurality of ASFRs associated with the file. The method may also include sending the modified file to a first user device.

[0006] One embodiment provides a system for modifying application-specific feature rights (ASFR), the system including a processor for identifying an application on a user device to execute a file received from a file system. The example system can be executed by the processor to cause a modification service implemented on a computing device to identify an application on the user device to execute a file received from the file system. In an example, the instructions are further for interpreting the received file, the file including content and an ASFR, the ASFR for specifying a feature of the application to be presented in the application. In an example, the instructions are further for causing the feature of the application to be executed on the file in response to the feature being identified in the ASFR. BRIEF DESCRIPTION OF THE DRAWINGS

[0007] The following detailed description can be better understood by reference to the accompanying drawings, which include specific examples of various features of the disclosed subject matter.

[0008] Figure 1 is a block diagram of an example of a computing system for modifying application-specific feature rights (ASFR);

[0009] Figure 2 is a flowchart of an example process for modifying ASFR;

[0010] Figure 3 is a block diagram of an example computer-readable storage medium for modifying ASFR;

[0011] Figure 4 is a block diagram of an example networked system for modifying ASFR having a file system and a user device;

[0012] Figure 5 is a block diagram of an example file having an ASFR;

[0013] Figure 6A and 6B shows a block diagram of an example file and application system for implementing an ASFR and modifications to the ASFR; and

[0014] Figure 7 is a block diagram of an example of a system for interpreting and executing application-specific feature rights (ASFR) on a file. DETAILED DESCRIPTION

[0015] As the retail space for software shifts from the traditional boxed software model to a "freemium" or subscription model, file manipulation or feature permissions can vary between software versions. The newer subscription models of software deployment provide a free version of the software with fewer or limited features for entry-level users, where the user can pay for the option to enable more advanced features. However, the management of this model can be a challenge in a collaborative work environment, where users may want to collaborate on the same work product, but different users may access the file using different application versions - some users with value-added features and others with restricted features. To enable a more flexible subscription model, the present disclosure generally relates to techniques for managing feature permissions or features based on files and file system locations. In some embodiments, feature permissions associated with users, applications, and other software products can be based on the file being edited or even on the storage or logical location of the specific file to be edited. Each file or file location can be associated with different application-specific licenses for enabling various advanced or additional features of the application. Additional features can include a full version of the application that provides a complete offering of the features available in the application. In an example, the type of features enabled can vary from file to file rather than being limited to the specific version of the software purchased or installed.

[0016] Systems implementing the techniques of the present disclosure are utilized, for example, to specify multiple files or storage locations of files that, when opened by their respective applications, unlock additional or value-added capabilities of the application. Similarly, systems implementing the techniques of the present disclosure can also restrict or reduce the functionality of the application when opened on the same application.

[0017] Multiple methods can be employed to determine which files unlock additional functionality of the software. For example, when application-specific feature permissions are granted to a file, the file can, in some examples, include the ability to grant the same license as the original file to multiple other files to access software features. In this way, value-added or enhanced ability features can be associated with multiple files (e.g., a set of files associated with a project) rather than a single file. In another example, a file with application-specific feature permissions (ASFR) can be associated with a specific one or more users or can associate certain features with a specific one or more users. In another example, the ASFR can be stored or associated in the file system, and more specifically, the permissions and features enabled by the ASRF can be applied to files within the associated location.

[0018] Additionally, the disclosed technology can enable file-based features for third-party plug-in extensions for software. For example, developers of plug-in applications for software can choose to restrict the feature permissions authorized or enabled by their plug-ins in cases where the plug-ins can be embedded in a specific document or the software itself. Such restrictions can follow a file-based feature permission model; the free use of third-party plug-ins can be restricted to a limited number of documents per user; or the feature permissions for unrestricted use of these plug-ins can be enabled based on a specific document, document location, or user identity of the user showing the use of the application.

[0019] As a citation, some of the figures describe concepts referred to as functions, modules, features, elements, etc. in the context of one or more structural components. The various components shown in the figures can be implemented in any way, such as by software, hardware (e.g., discrete logic components, etc.), firmware, etc., or in any combination of these implementations. In one embodiment, the various components can reflect the use of the corresponding components in an actual implementation. In other embodiments, any single component shown in the figures can be implemented by multiple actual components. The depiction of any two or more separate components in the figures can reflect different functions performed by a single actual component. The following discussion Figure 1 provides details related to a system that can be used to implement the functions shown in the figures.

[0020] Other figures describe concepts in flowchart form. In this form, certain operations are described as distinct boxes that are executed in a certain order. Such implementations are exemplary and non-limiting. Certain boxes described herein can be grouped together and executed in a single operation, certain boxes can be split into multiple sub-boxes, and certain boxes can be executed in an order different from that shown herein, including in a parallel manner of executing the boxes. The boxes shown in the flowcharts can be implemented by software, hardware, firmware, manual processing, etc., or in any combination of these implementations. As used herein, hardware can include computer systems, discrete logic components such as application-specific integrated circuits (ASICs), etc., and any combination thereof.

[0021] The term "logic" encompasses any functionality for performing a task. For example, each operation shown in the flowchart corresponds to the logic for performing that operation. The operations can be performed using software, hardware, firmware, physical electronic circuits, etc., or any combination thereof.

[0022] As used herein, terms such as "component", "system", "client", etc. are intended to refer to computer-related entities, which are hardware, software (e.g., in execution), and / or firmware, or a combination thereof. For example, a component can be a process running on a processor, an object, an executable, a program, a function, a library, a subroutine, and / or a combination of a computer or software and hardware. By way of illustration, both an application running on a server and the server can be components. One or more components can reside within a process and a component can be localized on one computer and / or distributed between two or more computers.

[0023] Furthermore, the claimed subject matter can be implemented as a method, apparatus, or article of manufacture using standard programming and / or engineering techniques to produce software, firmware, hardware, or any combination thereof to control a computer to implement the disclosed subject matter.

[0024] Computer-readable storage media can include, but are not limited to, magnetic storage devices (e.g., hard disks, floppy disks, and magnetic strips, etc.), optical disks (e.g., compact disks (CDs) and digital versatile disks (DVDs)), smart cards, and flash memory devices (e.g., cards, sticks, and key drives). Computer-readable storage media generally do not include all implementations of computer-readable media, such as signals themselves. Thus, by contrast, computer-readable media generally (i.e., not computer-readable storage media) can additionally include communication media, such as transmission media for wireless signals, etc.

[0025] Figure 1 is a block diagram of an example of a computing system for modifying application-specific feature permissions (ASFR). The computing system 100 can be, for example, a mobile phone, a laptop computer, a desktop computer, or a tablet computer, etc. The computing system 100 can include a processor 102 suitable for executing stored instructions, and a memory device 104 storing instructions executable by the processor 102. The processor 102 can be a single-core processor, a multi-core processor, a computing cluster, or any number of other configurations. The memory device 104 can include random access memory (e.g., SRAM, DRAM, zero-capacitor RAM, SONOS, eDRAM, EDO RAM, DDR RAM, RRAM, PRAM, etc.), read-only memory (e.g., Mask ROM, PROM, EPROM, EEPROM, etc.), flash memory, or any other suitable memory system. The instructions executed by the processor 102 can be used to modify application-specific feature permissions.

[0026] The processor 102 may be connected to an input / output (I / O) device interface 108 via a system bus 106 (e.g., PCI, ISA, PCI-Express, NuBus, etc.), and the I / O device interface is adapted to connect the computing system 100 to one or more I / O devices 110. The I / O devices 110 may include, for example, a keyboard, a gesture recognition input device, a voice recognition device, and an indicating device, where the indicating device may include a touchpad or a touch screen, etc. The I / O devices 110 may be built-in components of the computing system 100, or may be devices externally connected to the computing system 100.

[0027] The processor 102 may also be linked to a display device interface 112 via the system bus 106, and the display device interface 112 is adapted to connect the computing system 100 to a display device 114. The display device 114 may include a display screen as a built-in component of the computing system 100. The display device 114 may also include a computer monitor, a television, a projector, etc. externally connected to the computing system 100. A network interface card (NIC) 116 may also be adapted to connect the computing system 100 to a network (not shown) via the system bus 106.

[0028] The storage 118 may include a hard disk drive, an optical disk drive, a USB flash drive, a drive array, or any combination thereof. The storage 118 may include a file 120, a detector 122, and a transmitter 126. In some embodiments, the file 120 may include application-specific feature rights (ASFRs) for specifying which feature rights can be used for the file, used within a specific period of time, or used at a specific file location for the computer 100 or an application running on the computer 100. For example, the file 120 may include ASFRs that indicate to an application running on the computer 100 that additional features of the application can be used for the file 120. In another example, the ASFRs are not located on the file, but may alternatively correspond to or be associated with the file and be located elsewhere in the file system on the storage 118, the memory device 104, or any other suitable device for tracking ASFRs and the files they affect.

[0029] The detector 122 may detect a selection of the file 120 stored in a file system such as the storage 118. The detected file selection may be the result of user input, an automatic selection based on files that meet selection criteria, or any other suitable reason for selection. The detector 122 may also identify multiple ASFRs that may exist in the file system on the storage 118 or the memory device 104. When the detector detects a selection of the file 120, the detector is also able to detect multiple ASFRs corresponding to the file 120.

[0030] Modifier 124 can modify a file to indicate multiple ASFRs associated with the file. In an example, the modification can include inserting information from the ASFRs into the metadata of the file. In this example, the metadata can include data stored within the file that generally shows information related to the file, the information including file type, global permissions, creation time, author, or other similar information. In an example, modifier 124 can modify the file to indicate multiple ASFRs by changing existing permissions in the file to include application and feature specific permissions and then adjusting those permissions to match the ASFR information. In an example, modifier 124 can modify the file by removing data portions of functional components that are features of the application, such data portions as the index of the file, reference information in a video file, saved data, undo data, file history, or other similar data portions. In this example, the modifier can remove data portions of functional components that are features of the application to limit or enable those features to be available on the application.

[0031] Transmitter 126 can send file 120 and an indication of the corresponding multiple ASFRs to a first user device. The indication sent by transmitter 126 can alert any suitable device, application, machine, or plug-in software about the ASFRs corresponding to file 120 sent by transmitter 126. If file 120 corresponding to transmitter 126 is sent to another device, machine, application, or plug-in, the indication sent by transmitter 126 can also follow file 120.

[0032] It is to be understood that Figure 1 the block diagram is not intended to indicate that computing system 100 is to include all of the components shown in Figure 1 Instead, computing system 100 can include fewer components or additional components (e.g., additional applications, additional modules, additional memory devices, additional network interfaces, etc.) not shown in Figure 1 It.

[0033] Figure 2 is a flowchart of an example method 200 for modifying ASFRs. Method 200 can be implemented using any suitable computing device, such as Figure 1 computing system 100 of Figure 1 as described therein.

[0034] At block 202, detector 122 detects the selection of file 120 stored in the file system. For example, the corresponding ASFR stored in the file system can also be detected, where the ASFR corresponds to file 120 detected by detector 122. In an example, the ASFR is based on and stored within the file itself, but in another example, the ASFR is stored within a file system in a cloud storage format or stored within a shared network. In an example, the ASFR can include multiple permissions, rights, keys, function enabling codes, or certificates that summarize which feature permissions and capabilities are enabled, allowed, or granted to an application that can open and edit file 120. In an example, the ASFR corresponding to file 120 can be managed or changed when file 120 is opened or otherwise used. In another example, the ASFR can correspond to a location within the file system, where the file system can include file 120, and where the ASFR can be detected as corresponding to each file located within the location in the file system corresponding to the ASFR. In an example, the detected ASFR can also include an association with one or more user identity values. In this example, although also corresponding to file 120, the association of the ASFR with user identity values can also allow full ASFR-based functionality for the identified user while restricting the functionality of users without the ASFR identity with respect to the file. In an example, the detection of the ASFR corresponding to file 120 can enable a user with an associated user identity value to add other user identity values to the ASFR to be stored in the file or associated with the file in the file system storage, a cloud structure within the file system storage, or any other suitable value storage system.

[0035] At block 204, a modifier can modify a file to indicate multiple ASFRs associated with the file. In an example, this can include modifying the file or any data associated with the file, the data including content data, metadata, or data that is not located within a folder but is directly referenced or linked to a file that includes information stored on a server that references the file. As discussed above, the modifier can modify the file in a variety of ways such that the modification is coupled to the file during subsequent file transfers. By directly modifying the file, the permissions and features granted to the file can be sent along with the file such that additional devices and users can access the file. In an example, a user can request a service to associate additional feature permissions to one or more files (e.g., by paying a third-party service). These modified files can then continue to enable the additional features added when the file is accessed on an additional device or by an additional user. In an example, a file can have ASFRs that indicate additional features of multiple applications that can access the file. In some examples, ASFRs that indicate additional features that multiple applications can use to edit the file can be included in the file or data associated with the file.

[0036] At block 206, the transmitter 126 can send the modified file to the first user device. In an example, the modified file is accompanied by an indication that it has been modified and that additional application features can be accessed based on the data changed in the file. In an example, the modified file can also be sent with an indication of the modification that is not included in the file but is still associated with the file. In an example, the indication can be separate data sent to a file server that can confirm the status of the file and confirm what application feature permissions the file can have in the case where an application requests the confirmation from the file server. In some examples, the indication is not sent and the ASFR permissions are instead stored separately for subsequent reference. In an example, both the file and the indication can be sent to the first user device, where the first user device can run an application to also read or execute the file 120 based on the ASFRs transmitted in the indication. The modified file or the indication can represent the ASFR to the receiving device or machine. The modified file or the indication can include the functions enabled by the ASFR for the file 120 detected by the detector. In an example, the modified file can be associated with the indication such that if the first device sends the file to a second user device, the indication can travel with the second user device or at least be accessible by the second user device. In an example, the association of the ASFR indication with the file can enhance the file because the permissions and functions supported by the ASFR can be sent with the file rather than being exclusively associated with a particular program or machine.

[0037] Figure 3 is a block diagram of an example computer-readable storage medium 300 for modifying ASFRs. Items with the same number are as Figure 1 described. The tangible computer-readable storage medium 300 can be accessed by a processor 302 via a computer bus 304. Additionally, the tangible computer-readable storage medium 300 can include code for guiding the processor 302 to perform the steps of the current method.

[0038] The various software components discussed herein can be stored on the tangible computer-readable storage medium 300 as indicated in Figure 3 For example, the tangible computer-readable storage medium 300 can include a detector module 306 for detecting a file 120 stored in a file system that includes a plurality of ASFRs corresponding to the file 120. For example, the detector module 306 can detect the file stored in the file system locally within the computer-readable storage medium 300 or in another device, machine, cloud storage, or appliance. In an example, the detector module 306 detects the number of ASFRs of the file 120 based on the location of the file 120 in the file system. In an example, the location-based detection of the file and the corresponding number of ASFRs can allow the computer-readable storage medium 300 to associate the ASFRs with any file within the location in the file system.

[0039] In an example, the tangible computer-readable storage medium 300 can include a modifier module 308 for modifying the file 120 to indicate the plurality of ASFRs associated with the file. In an example, the modifier module can modify the file 120 by changing the file content or metadata, or otherwise modifying the file to indicate the characteristics and permissions corresponding to the file 120.

[0040] In an example, the tangible computer-readable storage medium 300 can include a transmitter module 310 that is operative to transmit a file 120 and an indication from the computer-readable storage medium. For example, the transmitter module 310 can transmit both the file and the indication to a first user device. In an example, the indication identifies an ASFR corresponding to the transmitted file 120. In an example, the transmitter module 310 transmits the file 120 and the indication to a first user device, where the indication is transmitted with the file 120 in the event the file 120 is transmitted to a second user device. This can allow the ASFR to be subsequently transmitted with the file rather than with a user, device, or specific program; however, each of these data or category fields (e.g., user, device, and program) can be included in the indication to be transmitted by the transmitter module 310. In an example, the indication includes a user identity value to be transmitted by the transmitter module 310 with the file 120, regardless of whether the file is transmitted to the first user device or subsequently a second time to the second user device. The second transmission can be accomplished by the transmitter module 310 or by the first user device that has received the file 120. In an example, the transmitter module can also transmit notification data to be displayed, regardless of where the file 120 is transmitted, including to the first user device, the second user device, or used locally by the computer-readable storage medium. In an example, the displayable data can be transmitted prior to a disassociation event to alert of the disassociation of the ASFR from the file 120. The disassociation event can be the sending of data or a notification to a client or receiver indicating the disassociation of the ASFR from the file 120. After receiving or detecting the disassociation event, the client or receiver can take action based on the specific disassociation indicated by the disassociation event. In an example, the displayable data to be transmitted by the transmitter module 310 can be prior to a disassociation event including the disassociation of a user identity value from the file or from the ASFR. The management of the association and disassociation of identity values such as, for example, a user identity value can allow for greater security of a system that implements an ASFR corresponding to a file. In an example, the notification transmitted by the transmitter module 310 can also include displayable techniques to follow and implement to avoid a disassociation event. In an example, techniques to avoid a disassociation event can include renewing (e.g., by paying) a subscription to a set of specific features enabled by the ASRF for a particular file or file location. In an example, other methods of delaying ASFR disassociation include viewing an advertisement, performing an action such as a purchase action, or by detection of active or recent use of application capabilities enabled by the corresponding ASFR. In another example, a notification can be transmitted regardless of whether the ASFR has expired, where the notification can display potential features that can be enabled by the ASFR in the event a user or device receives access to additional application functionality.In another example, if a user device has a specific ASFR for a file and shares the file and an indication of the ASFR with a second user device, subsequent calls to the ASFR from the first user device can also remove the ASFR from the second user device. In this example, the second user device can receive a notification regarding the termination of certain application features and a potential reason is the lack of the ASFR provided to the file by the first user device.

[0041] It is to be understood that any number of additional software components not shown in Figure 3 may be included within the tangible computer-readable storage medium 300 depending on the specific application. Although the subject matter has been described in language specific to structural features and / or methods, it is to be understood that the subject matter defined in the appended claims is not necessarily limited to the specific structural features or methods described above. Rather, the specific structural features or methods described above are disclosed as example forms of implementing the claims.

[0042] Figure 4 is a block diagram showing an example networking system 400 for modifying ASFRs having a file system and user devices. Like-numbered items are as Figure 1 described in

[0043] The networking system 400 can include a computer system 100 connected to a network 402 through its network interface card (NIC) 166. The network can also be connected to a file system storage 404. The file system storage 404 can be separate from the computer system 100 and connected through the network 402. In some examples, the file system storage 404 is stored within the computer system 100, or it can also be part of the storage of the computer system 100, or distributed in a cloud storage system.

[0044] In an example, a file 120 can be stored in the file system storage 404 of the networking system 400. In an example, the file system storage 404 can also include application-specific feature rights (ASFR) 406. The ASFR can be stored in the file 120 as a separate certificate in the form of data or any other suitable means for storing information regarding application feature rights associated with a certain file or location. The file system storage 404 can be a single physical storage device and can also be a cloud storage solution. In an example, the ASFR 406 corresponds to the file 120 stored in the file system storage 404. In an example, the ASFR 406 is stored as part of the file 120 or as data in the network 402, or stored in the file system storage 404 stored in the cloud of the computer system.

[0045] As discussed above, detector 122 can detect files in file system storage 404, where file system storage 404 includes ASFR 406. Detection of file 120 in file system storage 404 having an ASFR 406 corresponding to file 120 can be performed via network 402. As discussed above, transmitter 126 can direct the transmission of file 120 and an indication of the ASFR via network 402 to first user device 408. The transmission of file 120 and the indication of the ASFR can provide the application on first user device 408 with the ability to use the functionality of additional application 410 based on the ASFR 406 identified by the indication. For example, if the file is transmitted to first user device 408 without an indication of the corresponding ASFR 406, the application may not have the feature permissions identified by ASFR 406 for file 120. In an example, application 410 can be a third-party plug-in for a larger application. The plug-in version of application 410 managed by ASFR 406 associated with the file can enable per-file management of the features of the plug-in. For example, third-party providers can choose to allow their plug-ins or templates for a specific application 410 to be accessed on a per-file basis. In some examples, this allowance can enable full feature access to application 410 with no restrictions on the user device in terms of the number of files using the plug-in. In some embodiments, access to application features associated with subsequent file 120 can be restricted by a more restrictive ASFR 406, or a notification can be triggered to prompt the user to perform an action to re-enable the user's access to additional features of the plug-in for application 406.

[0046] In an example, file 120 can be transmitted from first user device 408 to second user device 412 a second time. This transmission of the file can be done by transmitter 126 or can be initiated from first user device 408. In an example, ASFR 406 can be transmitted to second user device 412 along with file 120. The transmission of file 120 and the indication of ASFR 406 can provide the application 410 on second user device 412 with the ability to use the functionality of additional application 410 based on the ASFR 406 identified by the indication. For example, if file 120 is transmitted to second user device 412 without an indication of the corresponding ASFR 406, the application may not have the feature permissions or functionality identified by ASFR 406 for file 120.

[0047] In an example, a service provider can provide an application for use by computer system 100 to store and access files in the service provider's system storage 404. In an example, computer system 100, the first user device 408, or the second user device 412 can access applications and files stored in the service provider's file system storage based on an ASFR associated with each accessed file or the location of the file. In an example, the ASFR associated with each file for a specific user device can be based on a subscription paid to gain access to certain features of an application hosted or provided by the service provider.

[0048] In an example, a service provider can provide a location in file system storage 404 for storing files, where the files stored in that designated location have an ASFR 406 associated with them to support additional features or enhanced functionality of the applications that run those files. In this example, a user device that opens or edits file 120 can check with the service provider to determine that a location on file system storage 404 is associated with a specific ASFR.

[0049] In an example, the first user device 408 and the second user device 412 can receive files that do not contain an ASFR 406. In this example, the first user device 408 and the second user device 412 can check file system storage 404 to confirm whether there is an ASFR 406 corresponding to a specific file 120. In this example, file system storage 404 can act as a service that records feature permissions associated with each user device for files and certain file locations managed by file system storage 404.

[0050] In an example, a user device can exercise some control over those files in file system storage 404 that have additional or enhanced ASFRs. Specifically, the first user device 408 can be given permission by the service provider's file system storage 404 to select the power to enable certain or additional application features for an application to run and edit file 120 for a specific file. In an example, the ability of the user device to have the additional application features it has selected persists only if file system storage 404 authorizes the user device to make those types of designations.

[0051] In an example where a user device attempts to edit a file 120 locally instead of on a file system storage 404, the user device can download the specified file for local editing based on an ASFR 406. In the example, the ASFR 406 can be transmitted to the user device by arranging a certificate indicating the permissions conveyed by the ASFR 406 within the file. In the example, the file 120 can be cryptographically signed by a service provider such that when an application 410 opens the file, the application can verify that the signature belongs to the service provider and that the signature matches the file. In the example, this verification can prevent tampering by a user who might seek to add markings to any file without going through the service provider. If the file 120 passes the signature verification, the user device having the file 120 can utilize additional application functionality to edit the file 120. In the example, if the file fails the signature verification, the user device is restricted to reduced application functionality when accessing the file.

[0052] In the example, a network connection to the service provider can verify appropriate certificates such that the user device can re-certify and re-sign the file 120. If the characteristic permissions of the file, as stored in the ASFR section of the file, are attached to a subscription period of the service, the certificate within the file or ASFR can store the expiration date of the subscription and also store a unique identifier for the subscription.

[0053] In the example, when the file 120 is saved in the file system storage 404, the expiration date of the ASFR 406 can be updated in the case where the specified subscription has been renewed. In an example where the current date is after the specified expiration date of the ASFR 406 for the file, the application 410 that opens the file 120 can synchronize with the service provider operating in the file system storage 404 to determine whether the subscription for the ASFR 406 of the file has been renewed. If not, the file 120 may not be able to be used with additional application functionality.

[0054] In the example, users implementing the ASFR 406 and the currently disclosed system can grant their ASFR 406 the ability to specify and save data to a privileged location such as the file system storage 404. In this example and based on the ASFR 406 that the user is licensed to use or has purchased, the user can specify a second user who can also access the file 120 saved in the privileged location. The second user provided with the ASFR 406, the file location, or access to the unlocked file can receive as many or as few permissions as those managed by the original user.

[0055] In an example, ASFRs 406 can be automatically managed or authorized based on their storage in a particular location, such as a designated file system storage 404. The file system storage 404 can also determine which ASFR 406 to provide for a file, user, or device based on the user, device, or network that placed the file in the file system storage 404. For example, if the file system storage 404 is owned by a single user who has been granted a certain set of ASFRs 406, any file stored in the file system storage 404 cannot reference the location where it is stored, but instead, the user identification number of the user who is operating, owning, managing, etc. is assigned or associated with the file system storage 404.

[0056] Even for the same file in the same location, the granted application feature permissions can depend on the device being used. Thus, for example, a tablet / mobile device can have fewer permissions than a desktop PC.

[0057] Some permissions can be granted to files on a public sharing system where the files can be viewed without restriction. In other words, a user can access additional application features without the permission to have privacy or move the files.

[0058] Figure 5 is a block diagram 500 of an example file with ASFRs. Items with the same number are as Figure 4 described in

[0059] File 120 can be a collection of data sent, received, and stored by a computer system 100. File 120 can be stored in a single physical location or in several physical locations, but is logically considered a single collection of information. The file can include content 502, which can include text data, video data, static image data, sound information, or any other suitable collection of information that the computer system 100 can process. In some examples, file 120 can include metadata, which, although not always part of the content 502 of the file, can include information about the file 120 itself, such as the type of the file, the size of the file, the origin of the file, author identity, and many other similar points about the information in file 120. In an example, a flag designated for file 120 for an ASFR can be stored with file 120. When file 120 is designated, the "flag" can be added to the metadata of the file, which marks the file as eligible for full or additional functionality based on the ASFR associated with the file. In an example, the file and its metadata can be stored in cloud storage, and a user device may not be able to freely manipulate the flag locally to grant itself the ability to edit the file.

[0060] In an example, if a user device requests access to a file and the additional feature capabilities of a specific program for a specific file, the application can check the file system storage or the cloud storage server to determine whether the file has a suitable ASFR. This check can be done through a secure connection to verify that the communication is with a genuine server and has not been tampered with. In an example, if the server indicates that the file is designated with an appropriate ASFR, the user device can access and utilize the additional functions of the application to edit the file; if not, the user device may only be granted access to application-restricted or reduced functions for the file.

[0061] In an example, application feature permissions can be de-associated if a file exceeds file parameters, where the parameters can be the size of the file, the age of the file, the total or the time spent by the user editing the file, the number of editing sessions conducted, how frequently a certain application feature has been used within a single file, and other similar parameters. In such an example, content 502 may be restricted or have restricted application feature permissions in a specific session of a specific file 120. By restricting the amount of content 502 on file 120 to have a suitable size limit, or by de-associating application feature permissions in certain segments or above a certain size, the opportunity for abuse of additional application feature permissions in a file-based system can be reduced. For example, instead of the ability to obtain certain application feature permissions for ten different files, the content from those ten files can be manually added by a user who wants to avoid paying to a single file with an ASFR 406 that supports additional application feature permissions. In this example, a limit on the size of content 502 in file 120 can eliminate the worst abuses of this problem. As mentioned above, many different user-influenced parameters of a file can be used to trigger various restrictions on application functionality. For example, if the file includes text content, content 502 can be restricted to 50 pages in content 502 having application features supported by ASFR 406. In an example, the ability to restrict application functionality based on file parameters and the use of ASFRs can also involve Information Rights Management (IRM) techniques and similar Digital Rights Management (DRM) features. In an example, the inclusion of these features can be used to limit which parts of a file can be edited, or to limit what a user with an ASFR license can do with a file. In an example, a user can create a document containing a form that uses IRM to allow specified fields to be edited. In this example and due to the pairing of IRM with ASFR, another user who receives the document can be adequately licensed to edit the document while being restricted in terms of which parts the user can edit.

[0062] Here, file 120 includes an Application Specific Feature Right (ASFR) 406 within the file, but other files may not include the ASFR 406. Including the ASFR within the file allows both the file and the ASFR 406 to be easily transferred from one machine to the next. As discussed above, the specific ASFR 406 associated with each file allows the application feature rights to vary from file to file. In other examples, file 120 does not include the ASFR 406, but instead, the ASFR 406 may be located in a different storage and simply associated with file 120 to allow information about the application feature rights for that specific file to be provided. In an example, file 120 may be accessed and edited at a location specified by the service provider or in a cloud storage system operated by the service provider.

[0063] Figure 6A and 6B FIG. shows a block diagram of an example file and application system 600 for implementing ASFRs and modifications to ASFRs. Like-numbered items are as Figure 4 and 5 described therein.

[0064] In Figure 6A , file 120 includes content 502 and ASFR-1 602. File 120 may be run, executed, viewed, edited, or perform similar functions on application 410. ASFR-1 indicates what (if any) feature rights or additional feature rights application 410 may have when processing file 120 and file content 502. In an example, application 510 includes several functions that may be applied to or performed on file 120. When working on file 120, functions 1 604, function 2 606, and function 3 608 are possible for application 410. In an example, the feature rights supported by the file with the associated ASFR-1 only allow application 410 to use functions 1 604 and function 2 606. In an example, a user who may use file 120 has only downloaded and is using the "free version" of application 410, which allows access to the more basic functions 1 604 and function 2 606. In an example, since ASFR-1 602 is associated with file 120, application 410 may change the functions it can use, at least in part, based on the file on which application 410 is working.

[0065] In Figure 6BIn it, file 120 includes content 502 and ASFR-2 610. The feature permissions of ASFR-2 610 can be read by application 410 and allow file 120 to access functions 1 604, function 2 606, and function 3 608. In the example, ASFR-2 510 can be included within the logical boundaries of file 120, but can also simply be associated with file 120 and stored in a separate physical or logical space. Although support for ASFR-2 functionality is shown in the Figure 6B example shown, it may not always increase the number of functions, and instead can specify which functions an application can use when working with a specific file. In the example, if a file does not have a corresponding ASFR, application 410 can fall back to a state where functions may be inactive or very few functions can be used for file 120. When application 410 is reduced in functionality, the functions can simply not be presented for a specific file, user, or file location, while still being available for other files that have appropriate feature permissions for that specific application. Similarly, in the example, application 410 with restricted functionality can allow the user device or computer system 100 to only read the file and not edit it.

[0066] In addition, although the term "function" is used for functions 1 604, function 2 606, and function 3 608, the term "function" can also include any type of action or interaction that an application has with a file having a specific ASFR.

[0067] In the example, application 410 can gain or lose functionality for either ASFR-1 602 or ASFR-2 610 based on an update to the application functionality itself. In this example, a new version can be provided to users of the service, where the functionality of the application is upgraded, reconfigured, or otherwise changed. In this example, the provider of the application can push these updates in application 410 and the ASFR 406 of each file 120 to the users of application 410. In the example, users who store, access, or receive file 120 can be notified of changes to the available features of a specific application 410. In the example, if it is not the provider of the application but the users who change their own ASFR 406 by upgrading or downgrading the service at the user device or storage location, the ASFR 406 can also change without any action being taken on the previously shared files by the users, user devices, or providers.

[0068] Figure 7 is a block diagram of an example of system 400 for interpreting and executing application-specific feature rights (ASFR) on files. Items with the same number are as Figure 1 and 4 described in.

[0069] System 700 can be a computing system that a user uses to access and manipulate files stored on storage 118. The files can be received by the system from a file system and identified, interpreted, and executed according to their content and the permissions they include.

[0070] System 700 can include a storage 118 with an identification module 702. The identification module 702 can identify applications that can operate on the system. In an example, the identification module 702 can identify applications that can execute, read, write, or otherwise modify files received from a file system.

[0071] System 700 can include an interpretation module 704 for interpreting the received files. In an example, the interpretation module 704 can interpret the content and ASFR included in the files. In an example, the interpretation module 704 can not only identify the ASFR, but also identify the specific features of the applications that the ASFR allows the applications to run.

[0072] System 700 can include an execution module 706 for enabling the features of an application to be executed on a file in response to the feature being specified by the interpretation module 704. In an example, if system 700 receives a file (e.g., a video file) to be opened by an application (e.g., a video editing program) identified by the identification module 702 as corresponding to the file type, the interpretation module 704 can interpret the file to identify which features of the video editing program can be used by the execution module 706 that runs the video editing program. In this example, if the ASFR indicates the permission to use specific features in the application, the execution module 706 can enable the feature in the application. In this example, if the video file does not have an ASFR for a feature (e.g., a tool for adding lens flare effects) of the video editing software, the feature will not be enabled for that specific file. However, in this example, if system 700 receives a second file with an ASFR indicating that the lens flare tool feature should be enabled for that file, the execution module 706 can enable the feature of the application executed on the file.

[0073] In an example, the interpretation module 704 detects an ASFR corresponding to a file and stored in the file system. In an example, system 700 includes an association module for associating the module with a user identity value, where the ASFR and the file can be modified to indicate a second user identity value to be associated with the ASFR. In an example, system 700 includes a notification module for generating notification data to be displayed by a first user device prior to an ASFR disassociation event. The notification can be sent to a display device, or can be sent over a network to a user or other device that can view, read, or act on the notification. In an example, the notification can indicate steps for avoiding an ASFR disassociation event.

[0074] Example 1

[0075] A system for modifying application-specific feature rights (ASFR) includes: a file system for storing files, where the file system includes a plurality of ASFRs corresponding to the files, and the plurality of ASFRs specify client types for triggering activation of features indicated by the plurality of ASFRs. The system can include a processor and a memory storage device storing executable instructions to be executed by the processor to cause a modification service implemented on a computing device to perform the following operations: detect a selection of the file stored in the file system; modify the file on the file system to indicate the plurality of ASFRs associated with the file; and send the modified file to a first user device.

[0076] Example 2

[0077] A system where the file system corresponds the plurality of ASFRs to the file based on the location of the file in the file system.

[0078] Example 3

[0079] A system where the plurality of ASFRs corresponding to the file are associated with a user identity value, and the plurality of ASFRs store a designation by the first user device of a second user identity value to be included in the ASFR.

[0080] Example 4

[0081] A system where the processor is used to disassociate the ASFR from the file at the end of a subscription period; and where the subscription period is for an application running the file.

[0082] Example 5

[0083] A system, wherein the plurality of ASFRs include multiple subsets that apply the complete functions for the file; and the plurality of ASFRs corresponding to the file include associating different subsets of ASFRs with each of the first user device and the second user device.

[0084] Example 6

[0085] A system, wherein the processor that executes the instructions stored in the file system storage is used to send notification data to be displayed on the first user device before an ASFR disassociation event; and the notification data is used to indicate steps to avoid the ASFR disassociation event and provide an interface for implementing the steps to avoid the ASFR disassociation event.

[0086] Example 7

[0087] A system, wherein the processor that executes the instructions stored in the file system storage is used to disassociate the ASFR from the file when the file exceeds the file parameters.

[0088] Example 8

[0089] A method for modifying application-specific feature permissions (ASFR), including detecting a selection of a file in a file system via a processor, the file system including multiple ASFRs corresponding to the file. In Example 1, the method may include modifying the file via the processor to indicate the multiple ASFRs associated with the file. In Example 1, the method may include sending the modified file to a first user device via the processor.

[0090] Example 9

[0091] A method, including detecting multiple ASFRs of the file based on the location of the file in the file system.

[0092] Example 10

[0093] A method, including associating the multiple ASFRs with a user identity value, wherein the multiple ASFRs store a second user identity value based on a specification received from a first user device.

[0094] Example 11

[0095] A method, wherein the ASFR is indicated by ASFR data that may be stored in cloud storage.

[0096] Example 12

[0097] A method, wherein the ASFR data can be stored in the file, and wherein the association of the ASFR with the file is modified at the first user to allow a second user device to access the file with the associated ASFR.

[0098] Example 13

[0099] A method includes disassociating the ASFR from the file at the end of a subscription period, wherein the subscription period is for an application that runs the file.

[0100] Example 14

[0101] A method, wherein the plurality of ASFRs include multiple subsets of the complete functionality that the application has for the file, and different subsets of the ASFR are associated with each of the first user device and the second user device.

[0102] Example 15

[0103] A method includes sending notification data to be displayed on the first user device before an ASFR disassociation event, wherein the notification indicates how to avoid the ASFR disassociation event.

[0104] Example 16

[0105] A method includes disassociating the ASFR from the file if the file exceeds file parameters.

[0106] Example 17

[0107] A system for modifying application-specific feature rights (ASFR) includes a processor; and a computer-readable memory storage device storing executable instructions. In an example, the instructions are to be executed by the processor to cause a modification service implemented on a computing device to identify an application on the user device for executing a file received from a file system. In an example, the instructions are for interpreting the received file, the file including content and an ASFR that is used to specify a feature of the application to be presented in the application. In an example, the instructions are further for causing the feature of the application to be executable on the file in response to identifying the feature in the ASFR.

[0108] Example 18

[0109] A system, wherein the processor is for detecting an ASFR corresponding to the file and stored in a file system.

[0110] Example 19

[0111] A system, wherein the processor is configured to associate an ASFR corresponding to the file with a user identity value, wherein the ASFR and the file are modified to indicate that a second user identity value is to be associated with the ASFR.

[0112] Example 20

[0113] A system, wherein the processor is configured to generate notification data to be displayed by the first user device prior to an ASFR disassociation event, wherein the notification indicates steps for avoiding the ASFR disassociation event.

Claims

1. An application system for implementing Application-Specific Feature Rights (ASFR), comprising: a processor; and a computer-readable memory storage device storing executable instructions that, in response to execution by the processor, cause the processor to: execute a file comprising content and ASFR; run an application comprising a plurality of functions that interact with the content of the file; and enable a subset of the plurality of functions in the application, the subset being selected based on the ASFR of the file, wherein an expiration date in the ASFR of the file is updated in response to a renewed subscription, and updating the ASFR comprises modifying a plurality of ASFRs associated with the file such that the subset of the plurality of functions enabled is updated based on the updated plurality of ASFRs, wherein the updated plurality of ASFRs associated with the file are updated in terms of content data, metadata, and data referencing the file from a server.

2. The application system according to claim 1, wherein Download the application to the computer-readable memory storage device and run it on the computer-readable memory storage device without detecting a financial transaction indicator associated with the application.

3. The application system according to claim 2, wherein A free version of the application includes initially enabled functions that are not included in the subset of the plurality of functions.

4. The application system according to claim 1, wherein In response to detecting that a second file comprising a second ASFR is processed by the application, the application modifies the functions enabled.

5. The application system according to claim 1, wherein, The ASFR is arranged within a logical collection of data called the file.

6. The application system according to claim 1, wherein The ASFR is associated with the file but stored in a collection of data that is logically separate from the file.

7. The application system according to claim 1, wherein, The ASFR is associated with the file and stored in a separate physical memory area in the computer-readable memory storage device.

8. The application system according to claim 1, wherein, The plurality of functions of the application are initially disabled and, in response to the processor detecting the plurality of functions in the ASFR of the file, the plurality of functions are enabled.

9. The application system according to claim 1, wherein, In response to the application addressing a second file that does not have the ASFR, the subset of the plurality of functions in the application is disabled.

10. The application system according to claim 1, wherein, In response to the ASFR of the file not including an editing function associated with the file, the processor disables the editing function.

11. A method for implementing Application-Specific Feature Rights (ASFR) on an application, comprising: executing a file comprising content and ASFR; running an application comprising a plurality of functions that interact with the content of the file; and enabling a subset of the plurality of functions in the application, the subset being selected based on the ASFR of the file, wherein an expiration date in the ASFR of the file is updated in response to a renewed subscription, and updating the ASFR comprises modifying a plurality of ASFRs associated with the file such that the subset of the plurality of functions enabled is updated based on the updated plurality of ASFRs, wherein the updated plurality of ASFRs associated with the file are updated in terms of content data, metadata, and data referencing the file from a server.

12. The method according to claim 11, wherein, Download the application to a computer-readable memory storage device and run it on the computer-readable memory storage device without detecting a financial transaction indicator associated with the application.

13. The method according to claim 12, wherein, The free version of the application includes initially enabled features that are not included in the subset of the plurality of features.

14. The method according to claim 11, wherein, In response to detecting that a second file including a second ASFR is processed by the application, the application modifies the enabled features.

15. The method according to claim 11, wherein, The plurality of features of the application are initially disabled, and in response to the processor detecting permissions for the plurality of features in the ASFR of the file, the plurality of features are enabled.

16. The method according to claim 11, wherein, In response to the application addressing a second file without the ASFR, the subset of the plurality of features in the application is disabled.

17. The method according to claim 11, wherein, In response to the ASFR of the file not including an edit feature associated with the file, the processor disables the edit feature.

18. A computer-readable storage medium for storing executable instructions to be executed by a processor, the instructions, in response to execution by the processor: Execute a file including content and an Application-Specific Feature Right (ASFR); Run an application including a plurality of features that interact with the content of the file; and Enable a subset of the multiple functions in the application, the subset being selected based on the ASFR of the file, where, The expiration date in the ASFR of the file is updated in response to a renewed subscription, and updating the ASFR includes modifying a plurality of ASFRs associated with the file such that a subset of the plurality of enabled features is updated based on the updated plurality of ASFRs, wherein the updated plurality of ASFRs associated with the file is updated in terms of content data, metadata, and data referencing the file from a server.

19. The computer-readable storage medium according to claim 18, wherein, Download the application to the computer-readable storage medium and run it on the computer-readable storage medium without detecting a financial transaction indicator associated with the application.

20. The computer-readable storage medium according to claim 19, wherein, The free version of the application includes initially enabled features that are not included in the subset of the plurality of features.

21. The computer-readable storage medium according to claim 19, wherein, The updated data referencing the file from the server is not located in the folder of the file.

Citation Information

Patent Citations

  • Application rights enabling

    US20030159035A1

  • Availability of permission models in roaming environments

    US20100293622A1