Apparatus and method for managing security content using virtual folder
First Claim
1. An apparatus for managing security contents comprising:
- a data control unit configured to receive an authority policy on contents from a security content server, and store the received authority policy in a storage means, the data control unit including a central processing unit, and the central processing unit maintaining a session so that the function of each execution file is performed, transmitting and receiving data to and from the security content server by supporting data transmission and reception protocols, and processing communication and authority information between execution processes in which a process having a user interface for authority control, a system tray process and an integrated viewer process are included,wherein user information is stored in the storage means based on login information received through a user authentication screen before the data control unit receives the authority policy;
a security processing unit configured to encode contents created on a first computing environment based on the authority policy provided from the data control unit, or decode contents that is required to be read, wrote, moved, copied or corrected on a second computing environment different from the first computing environment and stored in a virtual folder,wherein a file included in the contents to be encoded or decoded is confirmed for determining whether information stored in the file is the same as information stored in the storage means; and
a security filesystem interface unit configured to create the virtual folder based on position information of a folder to be virtualized and path information of the virtual folder by driving a virtual folder creation module that is operated in a kernel mode and register the created virtual folder in a filesystem, and provide, to the security processing unit, contents corresponding to an input and output event hooked from the kernel mode for contents which have been recorded or are to be recorded in the virtual folder,wherein the virtual folder is controlled according to authority set in the contents or the process having a user interface for authority control, andwherein the file to be created in the virtual folder is encoded or decoded into a format of a new security file before the security processing unit encodes and decodes.
3 Assignments
0 Petitions
Accused Products
Abstract
Provided are an apparatus and method for managing security contents using a virtual folder. The apparatus for managing security contents includes a data control unit that receives an authority policy on contents from a security content server, and stores the received authority policy in a storage means, a security processing unit that encodes or decodes the contents based on the authority policy provided from the data control unit, and a security filesystem interface unit that creates a virtual folder based on position information of a folder to be virtualized and path information of the virtual folder by driving a virtual folder creation module that is operated in a kernel mode and registers the created virtual folder in a filesystem, and provides, to the security processing unit, contents corresponding to an input and output event for contents which have been recorded or are to be recorded in the virtual folder hooked from the kernel mode and instructs the security processing unit to encode or decode the provided contents. According to the present invention, it is possible to provide contents created in different environments to a user based on authority information without any separate content conversion operation.
-
Citations
20 Claims
-
1. An apparatus for managing security contents comprising:
-
a data control unit configured to receive an authority policy on contents from a security content server, and store the received authority policy in a storage means, the data control unit including a central processing unit, and the central processing unit maintaining a session so that the function of each execution file is performed, transmitting and receiving data to and from the security content server by supporting data transmission and reception protocols, and processing communication and authority information between execution processes in which a process having a user interface for authority control, a system tray process and an integrated viewer process are included, wherein user information is stored in the storage means based on login information received through a user authentication screen before the data control unit receives the authority policy; a security processing unit configured to encode contents created on a first computing environment based on the authority policy provided from the data control unit, or decode contents that is required to be read, wrote, moved, copied or corrected on a second computing environment different from the first computing environment and stored in a virtual folder, wherein a file included in the contents to be encoded or decoded is confirmed for determining whether information stored in the file is the same as information stored in the storage means; and a security filesystem interface unit configured to create the virtual folder based on position information of a folder to be virtualized and path information of the virtual folder by driving a virtual folder creation module that is operated in a kernel mode and register the created virtual folder in a filesystem, and provide, to the security processing unit, contents corresponding to an input and output event hooked from the kernel mode for contents which have been recorded or are to be recorded in the virtual folder, wherein the virtual folder is controlled according to authority set in the contents or the process having a user interface for authority control, and wherein the file to be created in the virtual folder is encoded or decoded into a format of a new security file before the security processing unit encodes and decodes. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8)
-
-
9. An apparatus for managing security contents comprising:
-
a storage means that stores an authority policy on contents received from a security content server and a security content management program for managing security contents; and a processor that performs security management on the contents by executing the security content management program, wherein the security content management program includes a data control module that stores the authority policy received from the security content server in the storage means, and wherein user information is stored in the storage means before the receiving the authority policy based on login information received through a user authentication screen; a security processing module that encodes contents created on a first computing environment based on the authority policy provided from the data control module or decode contents that is required to be read, wrote, moved, copied or corrected on a second computing environment different from the first computing environment and stored in a virtual folder, wherein a file included in the contents is confirmed for determining whether information stored in the file is the same as information stored in the storage means after the providing contents; and a security filesystem interface module that creates the virtual folder based on position information of a folder to be virtualized and path information of the virtual folder by driving a virtual folder creation module that is operated in a kernel mode, registers the created virtual folder in a filesystem, and provides, to the security processing module, contents corresponding to an input and output event hooked from the kernel mode for contents which have been recorded or are to be recorded in the virtual folder, wherein the virtual folder is controlled according to authority set in the contents or the process having a user interface for authority control, and wherein the file to be created in the virtual folder is encoded or decoded into a format of a new security file. - View Dependent Claims (10, 11, 12, 13, 14)
-
-
15. A method for managing security contents comprising:
-
(a) receiving an authority policy on contents from a security content server, and storing the received authority policy in a storage means, wherein user information is stored in the storage means before the receiving the authority policy based on login information received through a user authentication screen; (b) creating a virtual folder based on position information of a folder to be virtualized and path information of the virtual folder by driving a virtual folder creation module that is operated in a kernel mode, and registering the created virtual folder in a filesystem, wherein a file to be created in the virtual folder is encoded or decoded into a format of a new security file; and (c) hooking an input and output event for contents which have been recorded or are to be recorded in the virtual folder from the kernel mode on a first computing environment, providing contents corresponding to the hooked input and output event to a security processing unit, and instructing the security processing unit to encode the provided contents on a first computing environment or decode the provided contents on a second computing environment different from the first computing environment, wherein the file included in the contents is confirmed for determining whether information stored in the file is the same as information stored in the storage means after the providing contents. - View Dependent Claims (16, 17, 18, 19, 20)
-
Specification