IP Library Granted Patent US 44,364
Granted Patent E1
US 44,364 · App. 11/129,746 · Granted Jul 9, 2013

Method of encrypting information for remote access while maintaining access control

Inventors: John J. Cristy (Landenberg, PA); David A. Pensak (Wilmington, DE); Steven J. Singles (Newark, DE)
Assignee: EMC Corporation
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 44,364
App. No.
11/129,746
Filed
May 16, 2005
Granted
Jul 9, 2013
Kind
E1
Art Unit
2434
USPC
713/171
Abstract

The invention provides for encrypting electronic information such as a document so that only users with permission may access the document in decrypted form. The process of encrypting the information includes selecting a set of policies as to who may access the information and under what conditions. A remote server stores a unique identifier for the information and associates an encryption/decryption key pair and access policies with the information. Software components residing on the author's computer retrieve the encryption key from the remote server, encrypt the information, and store the encrypted information at a location chosen by the author. A user wishing to access the information acquires the encrypted information electronically. Software components residing on the viewing user's computer retrieve the associated decryption key and policies, decrypt the information to the extent authorized by the policies, and immediately delete the decryption key from the viewing user's computer upon decrypting the information and rendering the clear text to the viewing user's computer screen. The software components are also capable of prohibiting functional operations by the viewing user's computer while the clear text is being viewed.

Claims (120)

1. A method of controlling distribution of a segment of encrypted electronic information, comprising:

receiving, at a user location, a user code and an identification of the segment;

transmitting the user code and the identification from the user location to a key server;

receiving, at a user location from a key server in response to the user code representing a user authorized to view the segment, a decryption key for the segment and at least one access policy associated with the segment;

decrypting the segment with the decryption key into clear text in response to said receiving;

destroying the decryption key in response to said decrypting;

rendering the clear text;

limiting access to the clear text consistent with the at least one access policy; and

defending the decryption key at the user location when the decryption key is resident at the user location;

wherein a processing between and including said receiving the decryption key and said destroying the decryption key occurs with sufficient speed such that the decryption key is only resident at the user location for a moment, and said defending resists capturing of the decryption key during the moment.

2. A method of controlling distribution of a segment of encrypted electronic information, comprising:

receiving, at a user location from a key server, a decryption key for the segment;

immediately decrypting the segment with the decryption key after said receiving;

immediately destroying the decryption key after to said decrypting; and

defending the decryption key at the user location when the decryption key is resident at the user location;

wherein said receiving, said immediately decrypting and said immediately destroying only permit the decryption key to be resident at the user location for a brief moment in time, and said defending resists capture of the decryption key during the brief moment in time, such that it is difficult to improperly capture the decryption key at the user location.

3. A method of controlling distribution of a segment of encrypted electronic information, comprising:

receiving, at a user location from a key server, a decryption key for the segment;

decrypting the segment with the decryption key in response to said receiving;

destroying the decryption key in response to said decrypting; and

defending the decryption key at the user location when the decryption key is resident at the user location;

wherein processing between and including said receiving and said destroying occurs with sufficient speed such that the decryption key is only resident at the user location for a moment, and said defending resists capture of the decryption key during the moment.

4. A method of controlling distribution of a segment of encrypted electronic information, comprising:

receiving, at a user location from a key server, a decryption key for the segment;

immediately decrypting the segment into clear text with the decryption key after said receiving;

immediately rendering said clear text on a display;

immediately destroying the decryption key after one of said decrypting and said rendering; and

defending the decryption key at the user location when the decryption key is resident at the user location;

wherein said receiving, said immediately decrypting and said immediately destroying only permit the decryption key to be resident at the user location for a brief moment in time, and said defending resists capture of the decryption key during the brief moment in time, such that it is difficult to improperly capture the decryption key at the user location.

5. A method of controlling distribution of a segment of encrypted electronic information, comprising:

receiving, at a user location, a user code and an identification of the segment;

transmitting the user code and the identification to a server;

receiving, at a user location from a key server, a decryption key for the segment in response to the user code representing a user authorized to view the segment;

decrypting the segment with the decryption key in response to said receiving;

destroying the decryption key in response to said decrypting; and

defending the decryption key at the user location when the decryption key is resident at the user location;

wherein a processing between and including said receiving the decryption key and said destroying the decryption key occurs with sufficient speed such that the decryption key is only resident at the user location for a moment, and said defending resists capturing of the decryption key during the moment.

6. A system for controlling access to a segment of encrypted electronic content, comprising:

a computer readable medium containing instructions designed to operate in conjunction with computer hardware and other computer software to:

receive, at a user location, a user code and an identification of the segment;

transmit the user code and the identification from the user location to a key server;

receive, at a user location from a key server in response to the user code representing a user authorized to view the segment, a decryption key for the segment and at least one access policy associated with the segment;

decrypt the segment with the decryption key into clear text in response to said receiving;

destroy the decryption key in response to said decrypting;

render the clear text;

limit access to the clear text consistent with the at least one access policy; and

defend the decryption key at the user location when the decryption key is resident at the user location;

wherein said instructions require that computer processing between and including said receive the decryption key and said destroy the decryption key occurs with sufficient speed such that the decryption key is only resident at the user location for a moment, and said defend the decryption key resists capture of the decryption key during the moment.

7. A system for controlling access to a segment of encrypted electronic content, comprising:

a computer readable medium containing instructions designed to operate in conjunction with computer hardware and other computer software to:

receive, at a user location from a key server, a decryption key for the segment;

immediately decrypt the segment with the decryption key after said receiving;

immediately destroy the decryption key after said decrypting; and

defend the decryption key at the user location when the decryption key is resident at the user location;

wherein the decryption key will only be resident at the user location for a brief moment in time, and said defend the key resists capture of the decryption key during the brief moment in time, such that it is difficult to improperly capture the decryption key at the user location.

8. A system for controlling access to a segment of encrypted electronic content, comprising:

a computer readable medium containing instructions designed to operate in conjunction with computer hardware and other computer software to:

receive, at a user location from a key server, a decryption key for the segment;

decrypt the segment with the decryption key in response to said receiving;

destroy the decryption key in response to said decrypting; and

defend the decryption key at the user location when the decryption key is resident at the user location;

wherein said instructions require computer processing between and including said receive and said destroy to occur with sufficient speed such that the decryption key is only resident at the user location for a moment, and said defend resists capture of the decryption key during the moment.

9. A system for controlling access to a segment of encrypted electronic content, comprising:

a computer readable medium containing instructions designed to operate in conjunction with computer hardware and other computer software to:

receive, at a user location from a key server, a decryption key for the segment;

immediately decrypt the segment into clear text with the decryption key after said receiving;

immediately render said clear text on a display;

immediately destroy the decryption key in response to one of said decrypting and said rendering; and

defend the decryption key at the user location when the decryption key is resident at the user location;

wherein the decryption key will only be resident at the user location for a brief moment in time, and said defend resists capture of the decryption key during the brief moment in time, such that it is difficult to improperly capture the decryption key at the user location.

10. A system for controlling access to a segment of encrypted electronic content, comprising:

a computer readable medium containing instructions designed to operate in conjunction with computer hardware and other computer software to:

receive, at a user location, a user code and an identification of the segment;

transmit the user code and the identification to a server;

receive, at a user location from a key server, a decryption key for the segment in response to the user code representing a user authorized to view the segment;

decrypt the segment with the decryption key in response to said receiving;

destroy the decryption key in response to said decrypting; and

defend the decryption key at the user location when the decryption key is resident at the user location;

wherein said instructions require that computer processing between and including said receiving the decryption key and said destroying the decryption key occurs with sufficient speed such that the decryption key is only resident at the user location for a moment, and said defend resists capturing of the decryption key during the moment.

11. A method of controlling distribution of an encrypted segment of electronic information, comprising:

receiving, at a user location from a remote server, a key capable of decrypting the encrypted segment, and at least one policy limitation associated with the segment;

generating, at the user location, a decrypted version of the encrypted segment using at least a single-use copy;

limiting use of the decrypted version of the encrypted segment at the user location consistent with the at least one policy limitation; and

preventing the single-use copy of a key from being used more than once to decrypt the encrypted segment, such that attempting to re-access the encrypted segment requires obtaining a new copy of the key.

12. The method of claim 11 further comprising making the key unusable at the remote server, such that the encrypted segment becomes inaccessible absent breaking the underlying encryption methodology.

13. The method of claim 12, wherein said making the key unusable comprises destroying the key or disassociating the key from the encrypted segment.

14. The method of claim 11, further comprising:

sending, from the user location to a remote server and before said receiving, a request to access the encrypted segment; and

logging the request to thereby create a record of attempts to access the encrypted segment;

wherein as a result of said logging a record is created of activity relating to the encrypted segment.

15. A method of controlling distribution of electronic information, comprising:

receiving, from a remote location, a single-use copy of a key capable of decrypting a segment of encrypted electronic information, and at least one policy limitation assigned to the segment;

accessing, at the user location, the segment using the single-use copy of a key, said accessing being consistent with the at least one policy limitation; and

rendering the decrypted segment;

wherein the single-use copy of a key cannot be used more than once to access the encrypted segment.

16. A method of controlling distribution of electronic information, comprising:

attempting to access, at a user location, an encrypted segment of encrypted electronic information;

sending, from the user location to a remote location, a request to access the encrypted segment of electronic information;

receiving, from a remote location, a single-use copy of a decryption key for the segment;

accessing, at the user location, the encrypted segment using single-use copy of the decryption key;

displaying a displayable portion of the encrypted segment as accessed; and

destroying the single use copy of the decryption key;

wherein the single use copy of the decryption key can only be used once, and a user who wishes to re-access the segment of encrypted electronic information at the user location must obtain a new copy of the decryption key.

17. A method of controlling distribution of electronic information, comprising:

first receiving, at a user location from a remote location, a first single-use authorization to access an encrypted segment of electronic information;

first accessing, at the user location, the encrypted segment using the first single-use authorization;

attempting at the user location to re-access the encrypted segment;

second receiving at the said user location in response to said attempting at a user location, a second single-use authorization to access the encrypted segment of electronic information;

second accessing, at the user location, the encrypted segment using the second single-use authorization;

wherein the first single-use authorization can only be used once, such that the encrypted segment cannot be re-accessed using the first single-use authorization.

18. A method of controlling distribution of an encrypted segment of electronic information, the encrypted segment having a plurality of sets of access policies associated therewith, each set including at least one access policy, the method comprising:

sending, from the user location to a remote location, a request to access the encrypted segment of electronic information, the request being associated with a specific requestor;

receiving, at a user location from the remote location, a single-use copy of a decryption key for the encrypted segment, and a set of access policies from the plurality of sets of access policies, the set being associated with the specific requester;

decrypting, at the user location, the encrypted segment using the single-use copy of the decryption key;

using the decrypted version of the encrypted segment at the user location consistent with the set of access policies; and

preventing the single-use copy of the decryption key from being used more than once to decrypt the encrypted segment.

19. The method of claim 11, wherein the segment is a text document.

20. The method of claim 19, wherein the at least one policy limitation comprises printing the text document.

21. The method of claim 19, wherein the at least one policy limitation comprises saving or copying the text document.

22. The method of claim 12, wherein once the key is rendered unusable, the user has no access to any electronic version of the decrypted content.

Assignments (12)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
CHANGE OF NAME Recorded Oct 13, 2016
From: AUTHENTICA SECURITY TECHNOLOGIES, INC.
To: AUTHENTICA, INC.
Reel/Frame 040337/0393 →
CHANGE OF NAME Recorded Sep 27, 2016
From: AUTHENTICA SECURITY TECHNOLOGIES, INC.
To: AUTHENTICA, INC.
Reel/Frame 040164/0911 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 27, 2016
From: PENSAK, DAVID A; CRISTY, JOHN J; SINGLES, STEVEN J
To: AUTHENTICA SECURITY TECHNOLOGIES, INC.
Reel/Frame 039863/0152 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 25, 2006
From: AUTHENTICA, INC.
To: EMC CORPORATION
Reel/Frame 017821/0737 →
Continuity (4)
Reissue 09985096 · Nov 1, 2001
Continuation 10936829 · Sep 9, 2004
Division 09906811 · Jul 18, 2001
Division 09321839 · May 28, 1999