IP Library Granted Patent US 7,916,870
Granted Patent B2
US 7,916,870 · App. 11/556,372 · Granted Mar 29, 2011

Systems and methods for document control using public key encryption

Assignee: Verizon Patent and Licensing Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,916,870
App. No.
11/556,372
Granted
Mar 29, 2011
Kind
B2
Abstract

Systems and methods for document control using public key encryption are provided. An interface program serves as a software interface between user applications used to create and access documents and a data storage system that stores the documents in an encrypted form. When a document is saved for the first time, information corresponding to the destruction of that document is obtained either from a user or in accordance with predefined criteria. The document is encrypted and stored with a pointer to an encryption key on a token/key server. When the document is subsequently accessed, the interface program will read the pointer and attempt to retrieve the key. If the key has expired in accordance with the destruction policy, the document is inaccessible. Otherwise, the document is decrypted using the key. Multiple documents may be saved according to the same destruction policy and even the same key, thereby greatly enhancing the ability to “destroy” documents regardless of their location with minimal process.

Claims (31)

1. A system comprising:

an encryption key server that is configured to:

provide an encryption key for a requesting application when a document is initially saved by that application;

store a decryption key associated with the encryption key and destruction information associated with the document and a subsequent version of the document;

provide the decryption key to requesting application in response to at least one of the document and the subsequent version of the document being subsequently opened for as long as the key remains valid in accordance with the destruction information; and

destroy the decryption key in accordance with one or more key destruction rules indicated in the destruction information, wherein the one or more key destruction rules specify an expiration date of the decryption key for the document and the subsequent version of the document.

2. The system according to claim 1 , wherein the one or more rules are received from a user input.

3. The system according to claim 1 , wherein the one or more rules are default rules of the encryption key server.

4. The system according to claim 1 , wherein the encryption server comprises a software-based interface to a encryption requesting software application that encrypts and decrypts documents for one or more user applications running on a computing device.

5. The system according to claim 4 , wherein, upon a subsequent request to the encryption server for a particular key, the server is configured to provide the key if it is still valid, or otherwise provide an indication to the requesting software application that the key is unavailable.

6. A method comprising:

receiving a request to apply a document control policy to a document;

sending a request for an encryption key to a key server;

sending document control policy information associated with the document and a subsequent version of the document to the key server;

receiving the encryption key in response to the request for an encryption key and the document policy information;

encrypting the document and the subsequent version of the document with the encryption key in response to receiving the encryption key;

storing the document and the subsequent version of the document in an encrypted format with information for obtaining a decryption key; and

destroying the decryption key in accordance with one or more key destruction rules, wherein the one or more key destruction rules specify an expiration date of the decryption key for the document and the subsequent version of the document.

7. The method according to claim 6 , further comprising

receiving a request to access an encrypted document;

sending a request for the decryption key to the key server in response to the request; receiving the decryption key, if the key is still valid; and

decrypting the document with the key.

8. A method comprising:

receiving a request, from a client, for an encryption key to encrypt a document, the request including document policy information that is associated with the document and a subsequent version of the document;

providing an encryption key in response to the received request;

associating the document policy information with the encryption key;

sending the encryption key to the requesting client;

receiving a request for a decryption key from the client upon a subsequent attempt to open at least one of the document and the subsequent version of the document;

verifying that the document policy information indicates that at least one of the document and the subsequent version of the document are still available; and, if so,

sending the decryption key to the client; and

destroying the decryption key in accordance with one or more key destruction rules, wherein the one or more key destruction rules specify an expiration date of the decryption key for the document and the subsequent version of the document.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 2, 2009
From: FEDERAL NETWORK SYSTEMS LLC
To: VERIZON PATENT AND LICENSING INC.
Reel/Frame 023455/0249 →
CORRECTIVE ASSIGNMENT TO CORRECT THE NAME OF THE ASSIGNEE FROM "VERIZON DATA SERVICES INC." PREVIOUSLY RECORDED ON REEL 019253 FRAME 0821. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNEE NAME SHOULD BE "FEDERAL NETWORK SYSTEMS LLC". Recorded Nov 14, 2007
From: MERGEN, JOHN FRANCIS
To: FEDERAL NETWORK SYSTEMS LLC
Reel/Frame 020111/0230 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 1, 2007
From: MERGEN, JOHN FRANCIS
To: VERIZON DATA SERVICES INC.
Reel/Frame 019253/0821 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 3, 2006
From: MERGEN, JOHN-FRANCIS
To: VERIZON SERVICES ORGANIZATION INC.
Reel/Frame 018479/0181 →
Continuity (1)
Related Publication 20080107271A1 · May 8, 2008