发明名称 Systems and methods for creating a rights management system (RMS) with superior layers and subordinate layers
摘要 A computer-implemented method for creating a rights management system (RMS) with superior layers and subordinate layers is described. A separate trust network for one or more layers of the RMS is established. The trust network includes one or more computing nodes within the one or more layers. A data object is created on a computing node that is a member of trust network in a superior layer. The data object is encrypted to a ciphertext data object. A publishing license is created for each of the one or more layers of the RMS. Access rights and attributes associated with the ciphertext data object are controlled within each layer based on the publishing license of each of the one or more layers of the RMS.
申请公布号 US8977849(B1) 申请公布日期 2015.03.10
申请号 US200912552404 申请日期 2009.09.02
申请人 Symantec Corporation 发明人 Clifford Thomas
分类号 G06F21/62 主分类号 G06F21/62
代理机构 Holland & Hart, LLP 代理人 Holland & Hart, LLP
主权项 1. A computer-implemented method for creating a rights management system (RMS) with superior layers and subordinate layers, comprising: establishing a separate trust network for each of a plurality of layers of the RMS, wherein each trust network comprises one or more computing nodes within each of the plurality of layers, wherein a first layer comprises an enterprise rights management (ERM) layer to manage access rights associated with a ciphertext data object, and wherein a second layer comprises an object storage rights management (OSRM) layer to manage storage attributes of the ciphertext data object; obtaining a document on a computing node that is a member of a first trust network in the first layer of the plurality of layers; encrypting the document to the ciphertext data object; creating a publishing license for each of the plurality of layers of the RMS, wherein each publishing license lists rights and attributes associated with the ciphertext data object for a respective layer, each layer including an authentication mechanism to validate users of a respective layer and to manage the data access rights for each user; encrypting each publishing license according to an encryption scheme, the encryption scheme based at least in part on the respective layer; sending, from the first trust network in the first layer, the ciphertext data object to a second trust network in the second layer, wherein the second layer is subordinate to the first layer; and decrypting the publishing license for the second layer to access the rights and attributes assigned to the second layer, wherein the publishing license for the OSRM layer specifies at least one of a minimum number of separate storage sites where the ciphertext data object is stored within the OSRM layer, a maximum number of copies of the ciphertext data object allowed in the OSRM layer, and a duration of time after which the ciphertext data object may be deleted.
地址 Mountain View CA US