IP Library Granted Patent US 7,950,065
Granted Patent B2
US 7,950,065 · App. 11/558,908 · Granted May 24, 2011

Method and system to control access to content stored on a web server

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,950,065
App. No.
11/558,908
Granted
May 24, 2011
Kind
B2
Abstract

Embodiments of the invention describe a technique to Content may be viewed or accessed with a link. The access or viewing of the content may be controlled by using an encrypted link that is generated and sent to an authorized user. When the authorized user uses a client system to access the content with the link, the client system is registered and the link is associated with the client system. When the link is forwarded to another computer system and the link is received from the other computer system in an attempt the access the content associated with the link, access to the content is at least initially, denied.

Claims (27)

1. A method for protecting stored content on a web server such that the stored content is available through a link but only to a first device accessing the link, and so as to prevent access to subsequent devices who receive the link, the method comprising:

generating an encrypted link to content, the encrypted link comprising authentication information for an authorized user, and the content being accessible through a plurality of different encrypted links, each different encrypted link being registered to and reusable by a particular computing device;

sending the encrypted link to the authorized user;

receiving a request for the content, the request being the result of receipt of the encrypted link from a computing device;

using registration information to determine whether access to the content through the encrypted link should be granted, wherein using the registration information determining whether the requesting computing device itself registered to access the content through the encrypted link, as well as determining whether the computing device was the first computing device to request access to the content through the encrypted link;

when the computing device is determined to be the first computing device to request access to the content through the encrypted link, providing the content to the computing device, such that the encrypted link is reusable by the computing device; and

when the computing device is determined not to be the first computing device to request access to the content through the encrypted link, denying access to the content.

2. The method of claim 1 , further comprising performing a primary registration operation to register a client system to use the encrypted link.

3. The method of claim 2 , wherein the primary registration operation comprises upon receiving the encrypted link from a client computing device, and if the encrypted link is received for the first time from any client computing device, then creating a registration record to indicate that the encrypted link is registered to the client computing device which then becomes the registered client computing device.

4. The method of claim 3 , further comprising sending identification data to be stored on the registered client computing device, the identification data to identify the registered client computing device.

5. The method of claim 4 , wherein controlling access to the content comprises allowing a client computing device access to the content if the identification data matches that stored in a registration record.

6. The method of claim 3 , further comprising in the case of the encrypted link being received from a client computing device other that the registered client system, then performing a modified registration operation to register the client computing device using another of the plurality of different encrypted links.

7. The method of claim 6 , wherein the modified registration operation comprises sending a notification to the client computing device to indicate that the encrypted link has already been registered against the registered client computing device.

8. The method of claim 7 , wherein the modified registration operation comprises prompting a user of the client computing device to indicate whether another of the plurality of different encrypted links to the content is required; and

receiving a response to the prompting.

9. The method of claim 8 , further comprising, if the response is affirmative, generating a new encrypted link to the content; and

sending the new encrypted link to the user.

10. The method of claim 8 , further comprising, receiving the new encrypted link from the client computing device and performing the primary registration operation.

11. The method of claim 6 , wherein the modified registration operation comprises confirming whether the user of the client computing device is the authorized user.

12. The method of claim 11 , further comprising, if the modified registration operation indicates that the user is not the authorized user, notifying an owner of the content that a new user wishes to view the content.

13. The method of claim 12 , further comprising sending information about the new user to the owner.

14. The method of claim 13 , further comprising generating and sending a new encrypted link to the content to an email address of the new user upon request of the owner.

15. A system, comprising:

a processor; and

a memory coupled to the processor, the memory storing instructions which when executed by the processor, cause the system to perform the method of claim 1 .

16. The system of claim 15 , wherein the memory further stores instructions which when executed by the processor, cause the system to perform a secondary registration operation to register the computing device when the computing device is determined not to be the first computing device to request access to the content through the encrypted link, the secondary registration operation comprising sending a fresh link to the unauthorized user who then becomes an authorized user, and performing a registration operation in respect of the fresh link when it is received from the authorized user the computing device is the first computing device to request access to the content through the fresh link.

17. A computer readable storage device, having stored thereon a sequence of instructions which when executed by a server system, cause the server system to perform the method of claim 1 .

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 9, 2014
From: MICROSOFT CORPORATION
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 034542/0001 →