IP Library Granted Patent US 7,409,547
Granted Patent B2
US 7,409,547 · App. 11/510,891 · Granted Aug 5, 2008

Adaptive transparent encryption

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,409,547
App. No.
11/510,891
Granted
Aug 5, 2008
Kind
B2
Abstract

A technique for adaptive encryption of digital assets such as computer files. The system model monitors passage of files to uncontrollable removable storage media or through network connections and the like which may indicate possible abuse of access rights. In accordance with a preferred embodiment, an autonomous independent agent process running at a point of use, such a background process in a client operating system kernel, interrupts requests for access to resources. The agent process senses low level system events, filters, and aggregates them. A policy engine analyzes sequences of aggregate events to determine when to apply encryption.

Claims (37)

1. An apparatus for controlling access to digital assets in a data processing environment comprising:

an encryption policy server, for storing one or more asset encryption policies to be applied to a security perimeter, the security perimeter comprising two or more data processing assets;

an atomic level data processing asset access event sensor, located within an operating system kernel within an end user device to sense atomic level events at a point of authorized access by the end user device to one or more digital assets;

an aggregator, to aggregate multiple atomic level events to determine if a group of two or more asset access events has occurred; and

an encryptor, to assert an asset encryption policy if a group of asset access events has occurred that indicates a risk of use of a digital asset outside the security perimeter.

2. An apparatus as in claim 1 wherein the encryptor additionally asserts at least one of the asset encryption policies by encrypting an associated digital asset.

3. An apparatus as in claim 1 wherein the group of asset access events is a time sequence of multiple atomic level events.

4. An apparatus as in claim 1 that operates independently of application software executing on the end user device.

5. An apparatus as in claim 1 wherein the sensor, aggregator, and encryptor operate in real time.

6. An apparatus as in claim 1 wherein a sensitivity of a particular digital asset is also sensed by the asset access event sensor, and the encryptor additionally comprises:

an adaptive encryptor, for adaptably encrypting the digital asset, optionally depending upon the sensitivity of the particular digital asset.

7. An apparatus as in claim 1 additionally wherein the encryptor is located:

at the end user device, to apply the encryption policy specified to the digital asset.

8. An apparatus as in claim 7 additionally comprising:

a transmitter, for sending the digital asset to a second end user device; and

an encryptor, to apply the encryption policy at the second end user device.

9. An apparatus as in claim 8 additionally comprising:

a decryptor, to decrypt the digital asset at the second end user device.

10. An apparatus as in claim 7 additionally comprising:

a transmitter, for forwarding the digital asset to a second end user device; and

an encryptor, which does not assert an encryption policy at the second end user device, so that if the encryption policy specifies encryption, the digital asset cannot be read at the second end user device.

11. An apparatus as in claim 1 wherein the digital assets are application level data files to which the end user device has read and write access within the security perimeter.

12. An apparatus as in claim 1 wherein the operating system kernel of the end user device receives the stored digital asset encryption policies from the policy server over a secure network connection.

13. An apparatus as in claim 1 wherein the encryptor is implemented in an operating system kernel of the end user device.

14. An apparatus as in claim 13 wherein the group of access events includes a first file open event, followed by a clipboard copy operation, a second file open event, and a file transmit through network communication point event.

15. An apparatus as in claim 1 wherein:

the sequence of digital access events indicates that the end user device is attempting to store a copy of the digital asset, and

at least one digital asset encryption policy specifies whether the digital asset is to be encrypted or not, depending upon a type of storage device on which the end user device is attempting to store a copy.

16. An apparatus as in claim 15 wherein the encryption policy specifies that the digital asset is not to be encrypted when the type of storage device is a local file server.

17. An apparatus as in claim 15 wherein the encryption policy specifies that the digital asset is to be encrypted when the type of storage device is a removable media storage device.

18. An apparatus as in claim 1 wherein:

the group of access events indicates that the end user device is sending the digital asset through a network communication port; and

the encryption policy further specifies that the digital asset is to be encrypted, prior to sending the digital asset through the network communication point.

19. An apparatus as in claim 18 wherein the group of access events indicates that the end user device is attaching the digital asset to one of an electronic mail message or instant messaging service.

20. An apparatus as in claim 1 wherein:

one of the encryption policies specifies that encryption is to be applied to an asset when a particular time sequence of access events is sensed; and

another of the encryption policies specifies that encryption is not to be applied to an asset when another particular time sequence of access events is sensed.

Assignments (16)
TERMINATION AND RELEASE OF FIRST LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 58892/0766 Recorded Nov 24, 2025
From: JEFFERIES FINANCE LLC
To: DIGITAL GUARDIAN LLC
Reel/Frame 073783/0619 →
TERMINATION AND RELEASE OF SECOND LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 58892/0945 Recorded Nov 21, 2025
From: ACQUIOM AGENCY SERVICES LLC
To: DIGITAL GUARDIAN LLC
Reel/Frame 073663/0411 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 14, 2025
From: GOLUB CAPITAL MARKETS LLC (AS EXISTING AGENT)
To: ACQUIOM AGENCY SERVICES LLC (AS SUCCESSOR COLLATERAL AGENT)
Reel/Frame 072471/0665 →
RELEASE OF SECURITY INTEREST Recorded May 3, 2022
From: GOLUB CAPITAL LLC
To: DIGITAL GUARDIAN LLC
Reel/Frame 059802/0303 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 28, 2022
From: DIGITAL GUARDIAN, LLC
To: GOLUB CAPITAL MARKETS LLC, AS COLLATERAL AGENT
Reel/Frame 058892/0945 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 28, 2022
From: DIGITAL GUARDIAN, LLC
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 058892/0766 →
SECOND AMENDED AND RESTATED INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 2, 2021
From: DIGITAL GUARDIAN LLC
To: GOLUB CAPITAL LLC, AS ADMINISTRATIVE AGENT
Reel/Frame 055207/0012 →
AMENDED AND RESTATED INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 29, 2019
From: DIGITAL GUARDIAN LLC
To: GOLUB CAPITAL LLC, AS ADMINISTRATIVE AGENT
Reel/Frame 050305/0418 →
CHANGE OF NAME Recorded May 21, 2019
From: DIGITAL GUARDIAN, INC.
To: DIGITAL GUARDIAN LLC
Reel/Frame 049240/0514 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jun 23, 2018
From: DIGITAL GUARDIAN, INC.
To: GOLUB CAPITAL LLC, AS ADMINISTRATIVE AGENT
Reel/Frame 046419/0207 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 9, 2018
From: STAMOS, NICHOLAS; BUCCELLA, DONATO; CARSON, DWAYNE A.
To: VERDASYS, INC.
Reel/Frame 044568/0077 →
RELEASE OF SECURITY INTEREST Recorded Dec 19, 2016
From: BRIDGE BANK, NATIONAL ASSOCIATION
To: DIGITAL GUARDIAN, INC. (FORMERLY VERDASYS INC.)
Reel/Frame 040672/0221 →
CHANGE OF NAME Recorded Apr 22, 2015
From: VERDASYS INC.
To: DIGITAL GUARDIAN, INC.
Reel/Frame 035479/0083 →
SECURITY AGREEMENT Recorded Dec 28, 2012
From: VERDASYS INC.
To: BRIDGE BANK, NATIONAL ASSOCIATION
Reel/Frame 029549/0302 →
RELEASE OF SECURITY INTEREST Recorded Dec 7, 2012
From: ORIX VENTURES, LLC
To: VERDASYS INC.
Reel/Frame 029425/0592 →
SECURITY AGREEMENT Recorded Oct 17, 2008
From: VERDASYS INC.
To: ORIX VENTURE FINANCE LLC
Reel/Frame 021701/0187 →