IP Library Granted Patent US 7,904,720
Granted Patent B2
US 7,904,720 · App. 10/289,528 · Granted Mar 8, 2011

System and method for providing secure resource management

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,904,720
App. No.
10/289,528
Granted
Mar 8, 2011
Kind
B2
Abstract

System and method for providing secure resource management. The system includes a first device that creates a secure, shared resource space and a corresponding root certificate for the shared space. The first device associates one or more resources that it can access with the shared space. The first device invites one or more other devices to join as members of the space, and establishes secure communication channels with the devices that accept this invitation. The first device generates a member certificate for each accepting device, and sends the root certificate and the generated member certificate to the device through the secure channel. These devices may then access resources associated with the shared space by presenting their member certificates. Further, members of the shared space may invite other device to join the space, and may create member certificates in the same manner as the first device.

Claims (53)

1. A method for managing a secure shared resource between a plurality of computing devices in an ad-hoc network, comprising:

creating at a first member computing device a first representation of a shared space defined by a first set of one or more data structures for storing information describing one or more shared resources included in the shared space, the first representation being unique to the first member computing device;

providing access to a first set of at least one shared resource included in the shared space and accessible to the first member computing device through the first representation to a second member computing device to form a second representation of the shared space unique to the second member computing device, wherein the second member computing device further provides a copy of the second representation to a plurality of member computing devices to form respectively unique representations of the shared space based upon the second representation;

hosting at the first member computing device the first set of shared resources associated with the shared space, the first member computing device being trusted by at least one of the second member computing device and the plurality of other member computing devices, the first member computing device providing at least one of the second member computing device and the plurality of other members with the copy of the first representation; and

accessing at least one of the second member computing device and the plurality of other member computing devices the first set of the at least one shared resource associated with the shared space and accessible to the second member computing device and the plurality of other member computing devices through their respective copy of the first representation, the at least one shared resource provided to the first representation copies by at least one of the first member computing device, the second member computing device, and a plurality of other member computing devices.

2. The method as set forth in claim 1 wherein the creating is carried out by at least one of the first member computing device, the second member computing device, and the plurality of other member computing devices.

3. The method as set forth in claim 1 further comprising establishing a secure communication channel between the first member computing device and at least one of the second member computing device and the plurality of other member computing devices.

4. The method as set forth in claim 3 wherein the establishing the secure communication channel further comprises using range-limited signals to transfer a commitment to a public key between the first member computing device and at least one of the second member computing device and the plurality of other member computing devices.

5. The method as set forth in claim 3 further comprising creating a set of credentials at the first member computing device for authorizing at least one of the first member computing device, the second member computing device and the plurality of other member computing devices to access the first representation of the shared space, and providing the set of credentials to at least one of the second member computing device and the plurality of other member computing devices through the secure communication channel.

6. The method as set forth in claim 1 further comprising:

accessing at the second member computing device a second set of at least one shared resource associated with the shared space and accessible to the second member computing device through the second representation, the second set of at least one shared resource provided to the second representation by at least one of the first member computing device, the second member computing device, and the plurality of other member computing devices.

7. The method as set forth in claim 6 wherein at least one of the first member computing device, the second member computing device and the plurality of other member computing devices associates a third set of at least one shared resource with the shared space.

8. The method as set forth in claim 1 wherein the first member computing device provides a first current state information of the shared space to the second member computing device.

9. The method as set forth in claim 8 wherein at least one of the plurality of other member computing devices provides a second current state information to at least one of the first member computing device and the second member computing device.

10. The method as set forth in claim 1 wherein the first member computing device is configured to dissociate at least one of the second member computing device and the plurality of other member computing devices from the shared space.

11. The method as set forth in claim 1 wherein at least one of the first member computing device, the second member computing device, and the plurality of other member computing devices store a copy of the first set of the at least one shared resource of the shared space.

12. The method as set forth in claim 1 wherein at least one of the first member computing device, the second member computing device, and the plurality of other member computing devices maintain a record log of operations involving the shared space.

13. The method as set forth in claim 1 wherein the first member computing device obtains a representation of at least one other shared space.

14. A non-transitory computer-readable medium having stored thereon instructions, which when executed by at least one processor, causes the processor to perform:

creating at a first member computing device a first representation of a shared space defined by a first set of one or more data structures for storing information describing one or more resources included in the shared space, the first representation being unique to the first member computing device;

providing access to a first set of at least one shared resource included in the shared space and accessible to the first member computing device through the first representation to a second member computing device to form a second representation of the shared space unique to the second member computing device, wherein the second member computing device further provides a copy of the second representation to a plurality of member computing devices to form respectively unique representations of the shared space based upon the second representation;

hosting at the first member computing device the first set of shared resources associated with the shared space, the first member computing device being trusted by at least one of the second member computing device and the plurality of other member computing devices, the first member computing device providing at least one of the second member computing device and the plurality of other member computing devices—with the copy of the first representation; and

accessing at least one of the second member computing device and the plurality of other member computing devices the first set of the at least one shared resource associated with the shared space and accessible to the second member computing device and the plurality of other member computing devices through their respective copy of the first representation, the at least one shared resource provided to the first representation copies by at least one of the first member computing device, the second member computing device, and a plurality of other member computing devices.

15. The medium as set forth in claim 14 wherein the creating is carried out by at least one of the first member computing device, the second member computing device, and the plurality of other member computing devices.

16. The medium as set forth in claim 14 further comprising establishing a secure communication channel between the first member computing device and at least one of the second member computing device and the plurality of other member computing devices.

17. The medium as set forth in claim 16 wherein the establishing the secure communication channel further comprises using range-limited signals to transfer a commitment to a public key between the first member computing device and at least one of the second member computing device and the plurality of other member computing devices.

18. The medium as set forth in claim 16 further comprising creating a set of credentials at the first member computing device for authorizing at least one of the first member computing device, the second member computing device and the plurality of other member computing devices to access the first representation of the shared space, and providing the set of credentials to at least one of the second member computing device and the plurality of other member computing devices through the secure communication channel.

19. The medium as set forth in claim 14 further comprising:

accessing at the second member computing device a second set of at least one shared resource associated with the shared space and accessible to the second member computing device through the second representation, the second set of at least one shared resource provided to the second representation by at least one of the first member computing device, the second member computing device and the plurality of other member computing devices.

20. The medium as set forth in claim 19 wherein at least one of the first member computing device, the second member computing device and the plurality of other member computing devices associates a third set of at least one shared resource with the shared space.

21. The medium as set forth in claim 14 wherein the first member computing device provides a first current state information of the shared space to the second member computing device.

22. The medium as set forth in claim 21 wherein at least one of the plurality of other member computing devices provides second current state information to at least one of the first member computing device and the second member computing device.

23. The medium as set forth in claim 14 wherein the first member computing device is configured to dissociate at least one of the second member computing device and the plurality of other member computing devices from the shared space.

24. The medium as set forth in claim 14 wherein at least one of the first member computing device, the second member computing device, and the plurality of other member computing devices store a copy of the first set of the at least one shared resource of the shared space.

25. The medium as set forth in claim 14 wherein at least one of the first member computing device, the second member computing device and the plurality of other member computing devices maintain a record log of operations involving the shared space.

26. The medium as set forth in claim 14 wherein the first member computing device obtains a representation of at least one other shared space.

27. A system configured to manage a secure shared resource between a plurality of computing devices in an ad-hoc network comprising:

a first representation of a shared space located at a first member computing device defined by a first set of one or more data structures that store information describing one or more resources included in the shared space, the first representation being unique to the first member computing device, the first representation being accessible to a second member computing device to form a second representation of the shared space unique to the second member computing device, wherein the second member computing device further provides a copy of the second representation to a plurality of member computing devices to form respectively unique representations of the shared space based upon the second representation, the shared space has a first set of at least one shared resource included in the shared space,

wherein the first set of shared resources associated with the shared space is hosted at the first member computing device, the first member computing device being trusted by at least one of the second member computing device and the plurality of other member computing devices the first set of the at least one shared resource associated with the shared space being accessible to at least one of the second member computing device and the plurality of other member computing devices through their respective copy of the first representation, the at least one shared resource being provided to the first representation copies by at least one of the first member computing device, the second member computing device, and a plurality of other member computing devices.

28. The system as set forth in claim 27 wherein, the shared space has a second set of at least one shared resource, the second set of at least one shared resource is accessible to the second member computing device through the second representation.

29. The system as set forth in claim 27 further comprising a secure communication channel over which a commitment to a public key is encoded into range-limited signals and transferred between the first member computing device and at least one of the second member computing device and the plurality of other member computing devices.

30. The system as set forth in claim 27 wherein the first member computing device has authorization information that describes at least one of the second member computing device and the plurality of other member computing devices as being valid members of the shared space.

31. The system as set forth in claim 27 wherein at least one of the first member computing device, the second member computing device, and the plurality of other member computing devices has current state information of the shared space.

32. The system as set forth in claim 27 wherein at least one of the first member computing device, the second member computing device and the plurality of other member computing device has a stored copy of the first set of the at least one shared resource of the shared space.

33. The system as set forth in claim 27 wherein at least one of the first member computing device, the second member computing device, and the plurality of other member computing devices has a record log of operations involving the shared space.

34. The system as set forth in claim 27 wherein the first member computing device has a representation of at least one other shared space.

35. The system as set forth in claim 27 wherein the first set of the at least one shared resource is associated with at least one of the first member computing device, the second member computing device and the plurality of other member computing devices.

36. The method as set forth in claim 1 , wherein at least one member computing device coupled to the second member computing device is not directly connected to the ad-hoc network.

37. The medium as se forth in claim 14 , wherein at least one member computing device coupled to the second member computing device is not directly connected to the ad-hoc network.

38. The system as set forth in claim 27 , wherein at least one member computing device coupled to the second member computing device is not directly connected to the ad-hoc network.

39. The method as set forth in claim 1 , wherein the shared space is separate from a root certificate stored in the first member computing device.

40. The medium as se forth in claim 14 , wherein the shared space is separate from a root certificate stored in the first member computing device.

41. The system as set forth in claim 27 , wherein the shared space is separate from a root certificate stored in the first member computing device.

Assignments (8)
SECOND LIEN NOTES PATENT SECURITY AGREEMENT Recorded Jul 2, 2025
From: XEROX CORPORATION
To: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 071785/0550 →
FIRST LIEN NOTES PATENT SECURITY AGREEMENT Recorded Apr 11, 2025
From: XEROX CORPORATION
To: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 070824/0001 →
SECURITY INTEREST Recorded Feb 13, 2024
From: XEROX CORPORATION
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 066741/0001 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS RECORDED AT RF 064760/0389 Recorded Feb 13, 2024
From: CITIBANK, N.A., AS COLLATERAL AGENT
To: XEROX CORPORATION
Reel/Frame 068261/0001 →
SECURITY INTEREST Recorded Nov 20, 2023
From: XEROX CORPORATION
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 065628/0019 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVAL OF US PATENTS 9356603, 10026651, 10626048 AND INCLUSION OF US PATENT 7167871 PREVIOUSLY RECORDED ON REEL 064038 FRAME 0001. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 28, 2023
From: PALO ALTO RESEARCH CENTER INCORPORATED
To: XEROX CORPORATION
Reel/Frame 064161/0001 →
SECURITY INTEREST Recorded Jun 22, 2023
From: XEROX CORPORATION
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 064760/0389 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 20, 2023
From: PALO ALTO RESEARCH CENTER INCORPORATED
To: XEROX CORPORATION
Reel/Frame 064038/0001 →