IP Library Granted Patent US 7,472,272
Granted Patent B2
US 7,472,272 · App. 10/716,336 · Granted Dec 30, 2008

Digital asset usage accountability via event journaling

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,472,272
App. No.
10/716,336
Granted
Dec 30, 2008
Kind
B2
Abstract

A technique for establishing a perimeter of accountability for usage of digital assets such as data files. The accountability model not only tracks authorized users' access to files, but monitors passage of such files to uncontrollable removable storage media or through network connections and the like which may indicate possible abuse of access. In accordance with a preferred embodiment, an autonomous independent agent process running at a point of use, such as in the background of a client operating system kernel, interrupts requests for access to resources. The agent process senses low level system events, filters, aggregates them, and makes reports to a journaling server. The journaling server analyzes sequences of low level events to detect when aggregate events of interest occur, such as “FileEdit”, network file transfers and the like. Reports can be generated to provide an understanding of how digital assets have been accessed, used or communicated by individuals in an enterprise.

Claims (29)

1. A system for providing a usage accountability model for data security in a data processing system, comprising:

a user client device having (i) a sensor to sense atomic level events at a point of authorized access to at least one digital asset by an end user of the user client device, the sensor located within an operating system kernel within the user client device, (ii) a filter to filter the atomic level events with an approved event list, the filter filtering out atomic level events not corresponding to approved events, and (iii) a coalescing aggregator to aggregate sets of atomic level events relating to respective single end user actions into single atomic level events, resulting in coalesced atomic level events, and to bundle and encrypt the coalesced atomic level events, resulting in bundles of coalesced atomic level events; and

a journaling server having a high-level aggregator (i) to accept the bundles of coalesced atomic level events from the user client device, (ii) to decrypt the bundles of coalesced atomic level events, (iii) to store the coalesced atomic level events in a table having fields relating to the coalesced atomic level events including event type, event category, event name, event detail, and event discriminant, and (iv) to aggregate at least some of the coalesced atomic level events to generate at least one aggregate event based on at least one predetermined sequence of atomic level events, and having a reporter to generate an audit trail from the at least one aggregate event, the audit trail representing usage of the at least one digital asset by the end user.

2. A system as in claim 1 wherein the aggregate events are associated with a particular executing process.

3. A system as in claim 2 wherein the executing process is associated with the end user.

4. A system as in claim 1 wherein the high-level aggregator only accepts atomic level events not filtered out by the filter.

5. A system as in claim 1 wherein the approved event list includes a list of approved file identifiers.

6. A system as in claim 5 wherein the file identifiers are a hash code.

7. A system as in claim 1 wherein sequence numbers are added to the bundles.

8. A system as in claim 1 wherein the at least one aggregate event is detected as a suspect action with a data file.

9. A system as in claim 1 wherein the at least one aggregate event is attributable to the end user, a thread and/or an application as identified at a known time.

10. A system as in claim 1 wherein the coalescing aggregator reports a single coalesced event after a time out period with no activity.

11. A system as in claim 1 wherein the at least one aggregate event and the audit trail are used to control security of the data processing system by determining patterns of unexpected behavior based on the at least one aggregate event and the audit trail.

12. A system as in claim 1 wherein the aggregate events and the audit trail provide a perimeter of accountability for usage of the at least one digital asset at a point of use of the at least one digital asset.

13. A system as in claim 12 wherein the point of use is the user client device and the accountability is of access, modification, and distribution of the at least one digital asset.

14. A method for providing a usage accountability model for data security in a data processing system, the method comprising:

sensing atomic level events at a point of authorized access to at least one digital asset by an end user of a user client device of the data processing system, the sensing taking place in an operating system kernel within the user client device;

filtering out atomic level events not corresponding to approved events using an approved event list;

aggregating sets of atomic level events relating to respective single end user actions into single atomic level events, resulting in coalesced atomic level events;

bundling and encrypting the coalesced atomic level events, resulting in bundles of coalesced atomic level events;

forwarding the bundles of coalesced atomic level events to a journaling server of the data processing system;

decrypting the bundles of coalesced atomic level events;

storing the coalesced atomic level events in a table having fields relating to the coalesced atomic level events including event type, event category, event name, event detail, and event discriminant;

aggregating at least some of the coalesced atomic level events at the journaling server to generate at least one aggregate event based on at least one predetermined sequence of atomic level events; and

generating an audit trail from the at least one aggregate event, the audit trail representing usage of the at least one digital asset by the end user.

15. A method as in claim 14 wherein forwarding the bundles of coalesced atomic level events to the journaling server includes forwarding only atomic level events not filtered out by the approved event list.

16. A method as in claim 15 where the approved event list includes a list of approved file identifiers.

17. A system as in claim 1 wherein the usage of the at least one digital asset includes access and dissemination of the at least one digital asset.

18. A method as in claim 14 wherein the usage of the at least one digital asset includes access and dissemination of the at least one digital asset.

Assignments (16)
TERMINATION AND RELEASE OF FIRST LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 58892/0766 Recorded Nov 24, 2025
From: JEFFERIES FINANCE LLC
To: DIGITAL GUARDIAN LLC
Reel/Frame 073783/0619 →
TERMINATION AND RELEASE OF SECOND LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 58892/0945 Recorded Nov 21, 2025
From: ACQUIOM AGENCY SERVICES LLC
To: DIGITAL GUARDIAN LLC
Reel/Frame 073663/0411 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 14, 2025
From: GOLUB CAPITAL MARKETS LLC (AS EXISTING AGENT)
To: ACQUIOM AGENCY SERVICES LLC (AS SUCCESSOR COLLATERAL AGENT)
Reel/Frame 072471/0665 →
RELEASE OF SECURITY INTEREST Recorded May 3, 2022
From: GOLUB CAPITAL LLC
To: DIGITAL GUARDIAN LLC
Reel/Frame 059802/0303 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 28, 2022
From: DIGITAL GUARDIAN, LLC
To: GOLUB CAPITAL MARKETS LLC, AS COLLATERAL AGENT
Reel/Frame 058892/0945 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 28, 2022
From: DIGITAL GUARDIAN, LLC
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 058892/0766 →
SECOND AMENDED AND RESTATED INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 2, 2021
From: DIGITAL GUARDIAN LLC
To: GOLUB CAPITAL LLC, AS ADMINISTRATIVE AGENT
Reel/Frame 055207/0012 →
AMENDED AND RESTATED INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 29, 2019
From: DIGITAL GUARDIAN LLC
To: GOLUB CAPITAL LLC, AS ADMINISTRATIVE AGENT
Reel/Frame 050305/0418 →
CHANGE OF NAME Recorded May 21, 2019
From: DIGITAL GUARDIAN, INC.
To: DIGITAL GUARDIAN LLC
Reel/Frame 049240/0514 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jun 23, 2018
From: DIGITAL GUARDIAN, INC.
To: GOLUB CAPITAL LLC, AS ADMINISTRATIVE AGENT
Reel/Frame 046419/0207 →
RELEASE OF SECURITY INTEREST Recorded Dec 19, 2016
From: BRIDGE BANK, NATIONAL ASSOCIATION
To: DIGITAL GUARDIAN, INC. (FORMERLY VERDASYS INC.)
Reel/Frame 040672/0221 →
CHANGE OF NAME Recorded Apr 22, 2015
From: VERDASYS INC.
To: DIGITAL GUARDIAN, INC.
Reel/Frame 035479/0083 →
SECURITY AGREEMENT Recorded Dec 28, 2012
From: VERDASYS INC.
To: BRIDGE BANK, NATIONAL ASSOCIATION
Reel/Frame 029549/0302 →
RELEASE OF SECURITY INTEREST Recorded Dec 7, 2012
From: ORIX VENTURES, LLC
To: VERDASYS INC.
Reel/Frame 029425/0592 →
SECURITY AGREEMENT Recorded Oct 17, 2008
From: VERDASYS INC.
To: ORIX VENTURE FINANCE LLC
Reel/Frame 021701/0187 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 18, 2003
From: STAMOS, NICHOLAS; BIRNBAUM, SETH N.; REVESZ, TOMAS JR.; BUCCELLA, DONATO; MACDONALD, KEITH A.; CARSON, DWAYNE A.; FLETCHER, WILLIAM E.
To: VERDASYS, INC.
Reel/Frame 014717/0435 →