Plug-in Module Intercepts Function Calls for DRM Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems face challenges in controlling and managing the functions that can be performed on security-protected documents after they are disseminated, as policies and digital rights management settings are difficult to enforce, particularly in ensuring that certain actions like printing or saving are restricted.

Innovation Solution

A plug-in software module intercepts function calls made by applications to enforce security and DRM policies by redirecting operations to memory instead of disk storage, using a code disassembler to modify and control functions within the application's library, ensuring that sensitive actions are restricted or redirected according to set policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security settings and DRM controls are applied to documents, then document security and policy enforcement are improved, but control over document functions becomes difficult to maintain after dissemination

Engineering Contradiction:
Improvesecurity enforcementVSAvoiddocument function control
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

A plug-in module acts as an intermediary between the application and the document, intercepting function calls and enforcing security policies. The plug-in monitors and controls document operations by capturing function calls, determining whether they are controlled functions, and either allowing or blocking them based on security settings and DRM policies, thereby maintaining control over disseminated documents

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Security controls and DRM policies are applied in advance to the document before dissemination. The system pre-configures security settings, identifies controlled functions, and establishes enforcement rules beforehand, enabling automatic control over document operations after the document is distributed to users

Inventive Principle:
Principle #10Preliminary action

2Reliability

If a plug-in module intercepts function calls to enforce security policies, then security control over document operations is improved, but system complexity increases

Engineering Contradiction:
Improvepolicy enforcementVSAvoidsystem architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The plug-in module serves multiple functions within a single component: it intercepts function calls, determines whether they are controlled functions, enforces security policies, and manages DRM controls. This multi-functional approach consolidates security enforcement capabilities into one universal module, reducing overall system complexity while maintaining comprehensive policy enforcement

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If controlled functions are intercepted and redirected, then unauthorized actions are prevented, but ease of operation for legitimate functions is reduced

Engineering Contradiction:
Improvesecurity protectionVSAvoiddocument operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The plug-in module continuously monitors function calls and provides real-time feedback by determining whether each call represents a controlled function. Based on this determination and the associated security policies, the plug-in dynamically allows or blocks the function, providing adaptive control that protects security while facilitating legitimate operations without manual intervention

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9218464B2Interception of controlled functions
Publication Date: 2015.12.22 ADOBE INC
  • US9218464B2 patent drawing
  • US9218464B2 patent drawing
  • US9218464B2 patent drawing

AI summary

Briefly, in accordance with one embodiment of the invention, a plug-in type application may intercept called functions in order to implement one or more security or digital rights management type settings, and/or one or more policies for a given document where such functions may be restricted, prohibited, and/or otherwise controlled. Patch code may be integrated with such controlled functions to modify the behavior of the function when executed in order to comply with the security or digital rights management setting, and/or one or more policies.