IP Library Granted Patent US 7,100,047
Granted Patent B2
US 7,100,047 · App. 10/750,321 · Granted Aug 29, 2006

Adaptive transparent encryption

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,100,047
App. No.
10/750,321
Granted
Aug 29, 2006
Kind
B2
Abstract

A technique for adaptive encryption of digital assets such as computer files. The system model monitors passage of files to uncontrollable removable storage media or through network connections and the like which may indicate possible abuse of access rights. In accordance with a preferred embodiment, an autonomous independent agent process running at a point of use, such a background process in a client operating system kernel, interrupts requests for access to resources. The agent process senses low level system events, filters, and aggregates them. A policy engine analyzes sequences of aggregate events to determine when to apply encryption.

Claims (40)

1. A process for controlling access to digital assets in a network of data processing devices, the process comprising:

defining a security perimeter that includes two or more data processing devices;

defining one or more digital asset encryption policies, to be applied to digital assets when a possible risk in use of a digital asset by an end user occurs;

sensing atomic level digital asset access events, the sensing step located within an operating system kernel in an end user client device, at a point of authorized access to the digital asset by the end user;

aggregating multiple atomic level events to determine a sequence of digital asset access events;

if the sequence of digital asset access events matches a predefined digital asset usage policy that indicates a risk of use of the digital asset outside of the security perimeter;

asserting one of the digital asset encryption policies associated with the sequence of events, by encrypting the digital asset, prior to allowing access to the digital asset from outside the security perimeter.

2. A method as in claim 1 wherein the digital assets are application level data files to which the user has read and write access within the security perimeter.

3. A method as in claim 1 additionally comprising the steps of:

storing the digital asset encryption policies in a policy server device in the network; and

within the operating system kernel of the end user client device,

receiving the stored digital asset encryption policies from the policy server over a secure network connection.

4. A process as in claim 1 wherein the step of asserting the digital asset encryption policy, by encrypting the digital asset prior to providing access, is implemented in an operating system kernel of the client user device.

5. A method as in claim 1 wherein

the sequence of digital access events indicates that the end user is attempting to store a copy of the digital asset, and

the digital asset encryption policy specifies whether the digital asset is to be encrypted or not, depending upon a type of storage device on which the end user is attempting to store a copy.

6. A method as in claim 5 wherein the encryption policy specifies that the digital asset is not to be encrypted when the type of storage device is a local file server.

7. A method as in claim 5 wherein the encryption policy specifies that the digital asset is to be encrypted when the type of storage device is a removable media storage device.

8. A method as in claim 1 wherein

the sequence of access events indicates that the end user is sending the digital asset through a network communication port; and

the encryption policy further specifies that the digital asset is to be encrypted, prior to sending the digital asset through the network communication point.

9. A method as in claim 8 wherein

the sequence of access events indicates that the end user is attaching the digital asset to one of an electronic mail message or instant messaging service.

10. A method as in claim 1 wherein

the sequence of access events includes a first file open event, followed by a clipboard copy operation, a second file open event, and a file transmit through network communication event.

11. A method as in claim 1 wherein

one of the encryption policies specifies that encryption is to be applied to an asset when a particular sequence of access events is sensed; and

another of the encryption policies specifies that encryption is not to be applied to an asset when another particular sequence of access events is sensed.

12. A process as in claim 1 that operates independently of application software.

13. A process as in claim 1 additionally comprising:

determining a sensitivity level of a particular digital asset in the step of sensing atomic level digital asset access events; and

asserting one of the digital asset encryption policies by either encrypting the digital asset or not, depending upon the sensitivity of the particular digital asset.

14. A process as in claim 1 additionally comprising:

forwarding the digital asset to a second client end user device; and

asserting an encryption policy at the second client end user device.

15. A process as in claim 14 additionally comprising:

applying decryption at the second client user device.

16. A process as in claim 1 additionally comprising:

forwarding the digital asset to a second client user device; and

not asserting an encryption policy at the second client user device, so that if the encryption policy specifies encryption, the digital asset cannot be read at the second client user device.

Assignments (16)
TERMINATION AND RELEASE OF FIRST LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 58892/0766 Recorded Nov 24, 2025
From: JEFFERIES FINANCE LLC
To: DIGITAL GUARDIAN LLC
Reel/Frame 073783/0619 →
TERMINATION AND RELEASE OF SECOND LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 58892/0945 Recorded Nov 21, 2025
From: ACQUIOM AGENCY SERVICES LLC
To: DIGITAL GUARDIAN LLC
Reel/Frame 073663/0411 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 14, 2025
From: GOLUB CAPITAL MARKETS LLC (AS EXISTING AGENT)
To: ACQUIOM AGENCY SERVICES LLC (AS SUCCESSOR COLLATERAL AGENT)
Reel/Frame 072471/0665 →
RELEASE OF SECURITY INTEREST Recorded May 3, 2022
From: GOLUB CAPITAL LLC
To: DIGITAL GUARDIAN LLC
Reel/Frame 059802/0303 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 28, 2022
From: DIGITAL GUARDIAN, LLC
To: GOLUB CAPITAL MARKETS LLC, AS COLLATERAL AGENT
Reel/Frame 058892/0945 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 28, 2022
From: DIGITAL GUARDIAN, LLC
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 058892/0766 →
SECOND AMENDED AND RESTATED INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 2, 2021
From: DIGITAL GUARDIAN LLC
To: GOLUB CAPITAL LLC, AS ADMINISTRATIVE AGENT
Reel/Frame 055207/0012 →
AMENDED AND RESTATED INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 29, 2019
From: DIGITAL GUARDIAN LLC
To: GOLUB CAPITAL LLC, AS ADMINISTRATIVE AGENT
Reel/Frame 050305/0418 →
CHANGE OF NAME Recorded May 21, 2019
From: DIGITAL GUARDIAN, INC.
To: DIGITAL GUARDIAN LLC
Reel/Frame 049240/0514 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jun 23, 2018
From: DIGITAL GUARDIAN, INC.
To: GOLUB CAPITAL LLC, AS ADMINISTRATIVE AGENT
Reel/Frame 046419/0207 →
RELEASE OF SECURITY INTEREST Recorded Dec 19, 2016
From: BRIDGE BANK, NATIONAL ASSOCIATION
To: DIGITAL GUARDIAN, INC. (FORMERLY VERDASYS INC.)
Reel/Frame 040672/0221 →
CHANGE OF NAME Recorded Apr 22, 2015
From: VERDASYS INC.
To: DIGITAL GUARDIAN, INC.
Reel/Frame 035479/0083 →
SECURITY AGREEMENT Recorded Dec 28, 2012
From: VERDASYS INC.
To: BRIDGE BANK, NATIONAL ASSOCIATION
Reel/Frame 029549/0302 →
RELEASE OF SECURITY INTEREST Recorded Dec 7, 2012
From: ORIX VENTURES, LLC
To: VERDASYS INC.
Reel/Frame 029425/0592 →
SECURITY AGREEMENT Recorded Oct 17, 2008
From: VERDASYS INC.
To: ORIX VENTURE FINANCE LLC
Reel/Frame 021701/0187 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 1, 2004
From: STAMOS, NICHOLAS; BUCCELLA, DONATO; CARSON, DWAYNE A.
To: VERDASYS INC.
Reel/Frame 015535/0559 →