Virtualization Module for Application-Agnostic Information Rights Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional information-rights-management systems face challenges due to the lack of support for rich plug-in architectures in common applications, leading to increased costs and complexity in administration, as well as exposure to attacks and inconsistent user interfaces across different applications.

Innovation Solution

Implementing virtualization to intercept application requests, query information-rights-management policies, and control data access transparently, allowing for operating-system-level virtualization and secure data handling without the need for application-specific plug-ins.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional information-rights-management systems use application-specific plug-ins to enforce policies, then information security is improved, but device complexity and administrative burden increase significantly

Engineering Contradiction:
Improveinformation securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a virtualization layer as an intermediary between applications and the information-rights-management system. This virtualization module intercepts data access requests at the operating system level, acting as a mediator that enforces security policies without requiring application-specific plug-ins. The virtualization layer translates application requests into controlled access operations, thereby maintaining security while reducing system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent shifts the enforcement point from the application dimension to the operating system dimension. By implementing information-rights-management at the virtualization layer of the operating system, the solution moves security enforcement to a different architectural dimension where it can apply universally across all applications without requiring application-specific modifications.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If application-specific plug-ins are deployed for information rights management, then data access control is improved, but ease of operation deteriorates due to the need to acquire, install, and maintain plug-ins for each application

Engineering Contradiction:
Improvedata access controlVSAvoidadministrative ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The virtualization module serves as a universal enforcement mechanism that handles data access control for all applications through a single implementation. Instead of requiring separate plug-ins for each application, the virtualization layer provides multi-functional policy enforcement that works across the entire application base, dramatically simplifying administrative operations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If plug-ins are used to enforce information-rights-management policies within applications, then security control is improved, but adaptability worsens due to inconsistent user interfaces and altered application behavior across different applications

Engineering Contradiction:
Improvesecurity controlVSAvoidapplication compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The virtualization layer acts as an intermediary that standardizes security control enforcement across all applications. By intercepting and managing data access requests at the virtualization level, it provides a consistent user interface and behavior regardless of the underlying application, thereby improving adaptability while maintaining security control.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8938808B1Systems and methods for using virtualization to implement information rights management
Publication Date: 2015.01.20 GEN DIGITAL INC
  • US8938808B1 patent drawing
  • US8938808B1 patent drawing
  • US8938808B1 patent drawing

AI summary

A method for using virtualization to implement information rights management. The method may include: 1) intercepting, at a virtualization module, a request from an application to access data; 2) querying an information-rights-management database for a virtualization policy associated with the access request; 3) receiving, at the virtualization module, the virtualization policy from the information-rights-management database; and 4) controlling access to the data by applying the virtualization policy to the access request in a manner that is transparent to the application. Various other methods, systems, and computer-readable media are also disclosed.