Information Management System
An information management system is described comprising one or more workstations running applications to allow a user of the workstation to connect to a network, such as the Internet. Each application has an analyzer, which monitors transmission data that the application is about to transmit to the network or about to receive from the network and which determines an appropriate action to take regarding that transmission data. Such actions may be extracting data from the transmission data, such as passwords and usernames, digital certificates or eCommerce transaction details for storage in a database; ensuring that the transmission data is transmitted at an encryption strength appropriate to the contents of the transmission data; determining whether a check needs to be made as to whether a digital certificate received in transmission data is in force, and determining whether a transaction about to be made by a user of one of the workstations needs third party approval before it is made. The analyzer may consult a policy data containing a policy to govern the workstations in order to make its determination. The information management system provides many advantages in the eCommerce environment to on-line trading companies, who may benefit by being able to regulate the transactions made by their staff according to their instructions in a policy data, automatically maintain records of passwords and business conducted on-line, avoid paying for unnecessary checks on the validity of digital certificates and ensure that transmissions of data made by their staff are always protected at an agreed strength of encryption.
1 . An information management system comprising:
one or more workstations connected to a computer network, each workstation having a memory;
an application stored in said memory of each workstation for receiving at least inbound data from said computer network;
an analyzer, said analyzer monitoring, in conjunction with said application, said inbound data and to identify in at least said inbound data, signed data that has been digitally signed with a digital certificate, extracting one or more details of said signed data, and determining whether or not verification is required for said digital certificate;
policy data, accessible by said analyzer, containing rules which define whether or not verification is required for said digital certificate; and wherein said analyzer determines whether or not verification is required for said digital certificate in dependence on said rules of said policy data and in dependence on said one or more details of said signed data extracted by said analyzer.
2 . The system of claim 1 wherein said verification for said digital certificate includes determining whether said digital certificate has been revoked.
3 . The system of claim 2 wherein said analyzer further determines whether said signed data is part of an eCommerce transaction, and if it is, determines the amount of money that is promised in that eCommerce transaction, wherein said verification for the digital certificate also includes determining whether said digital certificate can be taken as a guarantee of receiving the amount of money promised in said eCommerce transaction.
4 . The system of claim 1 wherein said analyzer extracts as one or more details of said signed data, one or more of said digital certificate holder's identity, the expiry date of said digital certificate, the issue number of said digital certificate, and the domain name from which the signed data was received, and wherein said rules of said policy file define whether or not verification for said digital certificate is required in dependence on the one or more details extracted by said analyzer.
5 . The system of claim 1 wherein said analyzer determines whether or not an eCommerce transaction is occurring, and extracts, as one or more details of said signed data, the amount of any transaction being made with said digital certificate, the account code from which any payment is being made, a credit card number, one or more indicators of the nature of the transaction, and wherein said rules of said policy file define whether or not verification is required for a digital certificate in dependence on the one or more details extracted by said analyzer.
6 . The system of claim 5 further comprising a data repository in which, digital certificates used to digitally sign any previously received signed data or sufficient descriptive data to identify any such digital certificates, and transaction data describing any previous transactions made with those digital certificates are stored, said transaction data being at least one or more of the date of any previous transactions made with a digital certificate, and the amount of any previous transaction made with that digital certificate, and wherein said rules of said policy file define whether or not verification for said digital certificate is required in dependence on said transaction data.
7 . The system of claim 1 further comprising a data repository, accessible by said analyzer, wherein said analyzer identifies any digital certificates that are used to digitally sign signed data in at least said inbound data, and causes any such digital certificates, or sufficient descriptive data to identify such digital certificates to be stored in said data repository.
8 . The system of claim 7 wherein said analyzer records the results of any verification for a digital certificate in said data repository together with said digital certificate or together with said descriptive data.
9 . The system of claim 8 wherein said analyzer, if it identifies a digital certificate in said inbound data, determines whether said digital certificate has been previously stored in said data repository, or whether said descriptive information identifying said digital certificate has been stored in said data repository, and if said digital certificate has been previously stored, looks-up the results of any previous verification of whether said digital certificate has been revoked, wherein said analyzer determines whether or not to verify if said digital certificate has been revoked in dependence on said results of any previous verification of whether said identified digital certificate has been revoked.
10 . The system of claim 1 wherein said analyzer further verifies whether or not a digital certificate has been revoked, and wherein said application prevents said inbound data being viewed by a user of said application if said analyzer determines that said digital certificate has been revoked.
11 . The system of claim 1 wherein said analyzer further verifies whether or not a digital certificate has been revoked, and said application notifies a user of said application that said inbound data is not to be relied upon if said analyzer determines that said digital certificate has been revoked.
12 . The system of claim 1 wherein said analyzer is located on each of said one or more workstations.
13 . The system of claim 1 wherein said application is a web browser.
14 . The system of claim 13 wherein said analyzer is a plug-in module of said web browser.
15 . The system of claim 14 wherein said web browser is Microsoft's Internet Explorer and said analyzer is a Browser Helper Object.
16 . The system of claim 1 wherein said application is an e-mail client.
17 . The system of claim 16 wherein said analyzer is a plug-in module of said e-mail client.
18 . The system of claim 17 wherein said e-mail client is Microsoft's Outlook e-mail client and said analyzer is a Microsoft client extension.
19 . The system of claim 1 wherein said computer network comprises a server, and said analyzer is located at a point on said computer network intermediate to said one or more workstations and said server, or said analyzer is located at said server.
20 . The system of claim 1 wherein said computer network to which said one or more workstations are connected to is a public computer network, and wherein said one or more workstations together form a private computer network.
21 . The system of claim 1 further comprising a supervisor workstation, said policy data being accessible by said supervisor workstation, such that a user of said supervisor workstation can edit said policy data.
22 . A method of managing information comprising the steps of:
providing one or more workstations connected to a computer network, each workstation having a memory;
providing an application stored in said memory of each workstation for receiving at least inbound data from said computer network;
providing policy data, containing rules which define whether or not verification is required for a digital certificates used to digitally sign signed data received in said inbound data;
identifying in at least said inbound data, signed data that has been digitally signed with a digital certificate;
extracting one or more details of said signed data; and
determining whether or not verification is required for said digital certificate in dependence on said rules of said policy data and in dependence on said one or more details of said signed data extracted in said extracting step.
23 . The method of claim 22 wherein said verification for the digital certificate includes determining whether the digital certificate has been revoked.
24 . The method of claim 23 further comprising the step of determining whether said signed data is part of an eCommerce transaction, and if it is, determining the amount of money that is promised in that eCommerce transaction, wherein said verification for the digital certificate also includes determining whether said digital certificate can be taken as a guarantee of receiving the amount of money promised in said eCommerce transaction.
25 . The method of claim 22 wherein said one or more details of said signed data extracted in said extracting step, include one or more of said digital certificate holder's identity, the expiry date of said digital certificate, the issue number of said digital certificate, and the domain name from which the signed data was received, and wherein said rules of said policy file define whether or not verification for said digital certificate is required in dependence on the one or more details.
26 . The method of claim 22 further comprising the step of determining whether or not an eCommerce transaction is occurring, and if it is, extracting in said extracting step, as one or more details of said inbound data, the amount of any transaction being made with said digital certificate, the account code from which any payment is being made, a credit card number, one or more indicators of the nature of the transaction, and wherein said rules of said policy file define whether or not verification is required for a digital certificate in dependence on said one or more details.
27 . The method of claim 26 further comprising the step of providing a data repository in which digital certificates used to digitally sign any previously received signed data or sufficient descriptive data to identify any such digital certificates, and transaction data describing any previous transactions made with those digital certificates are stored; said transaction data being at least one or more of the date of any transactions made with a digital certificate, and the amount of any transaction made with that digital certificate, and wherein said rules of said policy file define whether or not verification for said digital certificate is required in dependence on said transaction data.
28 . The method of claim 22 further comprising the steps of identifying digital certificates used to sign signed data in said inbound data or digital certificates transmitted in said inbound data and storing said digital certificates or sufficient descriptive data to identify said digital certificates in said data repository.
29 . The method of claim 28 further comprising the steps of recording the results of any verification for an digital certificate in said data repository together with said digital certificate.
30 . The method of claim 29 further comprising the step of determining whether said digital certificate has been previously stored in said data repository, and if it has been previously stored, to look-up the results of any previous verification for said digital certificate, wherein said step of determining whether or not verification is required for said digital certificate is dependent on said results of any previous verification for said digital certificate.
31 . The method of claim 22 further comprising the steps of determining whether or not a digital certificate has been revoked, and preventing said inbound data being viewed by a user of said application if said identified digital certificate has been revoked.
32 . The method of claim 22 further comprising the steps of determining whether or not a digital certificate has been revoked, and notifying a user of said application that said inbound data is not to be relied upon if said digital certificate has been revoked.
33 . The method of claim 22 wherein said steps of identifying a digital certificate, extracting one or more details from said signed data and determining whether or not verification is required are performed at said one or more workstations.
34 . The method of claim 22 wherein said application is a web browser.
35 . The method of claim 34 wherein said steps of identifying a digital certificate, extracting one or more details from said signed data and determining whether or not verification is required are performed by a plug-in module of said web browser.
36 . The method of claim 35 wherein said web browser is Microsoft's Internet Explorer and said plug-in module is a Browser Helper Object.
37 . The method of claim 22 wherein said application is an e-mail client.
38 . The method of claim 37 wherein said steps of identifying a digital certificate, extracting one or more details from said signed data and determining whether or not verification is required are performed by a plug-in module of said e-mail client.
39 . The method of claim 38 wherein said e-mail client is Microsoft's Outlook e-mail client and said plug-in module is a Microsoft Exchange client extension.
40 . The method of claim 22 wherein said computer network comprises a server, and said steps of identifying a digital certificate, extracting one or more details from said signed data and determining whether or not verification is required are performed at a point on said computer network intermediate to said one or more workstations and said server, or said steps of identifying a digital certificate, extracting one or more details from said signed data and determining whether or not verification is required are performed at said server.
41 . The method of claim 22 wherein said computer network to which said one or more workstations are connected is a public computer network, and wherein said one or more workstations together form a private computer network.
42 . The method of claim 22 further comprising providing a supervisor workstation, said policy data being accessible by said supervisor workstation, such that a user of said supervisor workstation can edit said policy data.
43 . An information management system comprising:
one or more workstations connected to a computer network, each workstation having a memory;
application means, stored in said memory of each workstation, for receiving at least inbound data from said computer network;
analyzing means for monitoring, in conjunction with said application means, said inbound data to identify in at least said inbound data signed data that has been digitally signed with a digital certificate, for extracting one or more details of said signed data and for determining whether or not verification is required for said digital certificate;
policy storage means, accessible by said analyzing means, for storing policy data containing rules which define whether or not verification is required for said digital certificate; and
wherein said analyzing means determines whether or not verification is required for said digital certificate in dependence on said rules of said policy data and in dependence on said one or more details of said signed data extracted by said analyzing means.
44 . The system of claim 43 wherein said verification for said digital certificate includes determining whether said digital certificate has been revoked.
45 . The system of claim 44 wherein said analyzing means further determines whether said signed data is part of an eCommerce transaction, and if it is, determines the amount of money that is promised in that eCommerce transaction, wherein said verification for the digital certificate also includes determining whether said digital certificate can be taken as a guarantee of receiving the amount of money promised in said eCommerce transaction.
46 . The system of claim 43 wherein said analyzing means extracts as one or more details of said signed data, one or more of said digital certificate holder's identity, the expiry date of said digital certificate, the issue number of said digital certificate, and the domain name from which the signed data was received, and wherein said rules of said policy file define whether or not verification for said digital certificate is required in dependence on the one or more details extracted by said analyzing means.
47 . The system of claim 43 wherein said analyzing means determines whether or not an eCommerce transaction is occurring, and extracts, as one or more details of said signed data, the amount of any transaction being made with said digital certificate, the account code from which any payment is being made, a credit card number, one or more indicators of the nature of the transaction, and wherein said rules of said policy file define whether or not verification is required for a digital certificate in dependence on the one or more details extracted by said analyzing means.
48 . The system of claim 47 further comprising a data repository in which, digital certificates used to digitally sign any previously received signed data or sufficient descriptive data to identify any such digital certificates, and transaction data describing any previous transactions made with those digital certificates are stored, said transaction data being at least one or more of the date of any previous transactions made with a digital certificate, and the amount of any previous transaction made with that digital certificate, and wherein said rules of said policy file define whether or not verification for said digital certificate is required in dependence on said transaction data.
49 . The system of claim 43 further comprising a data repository, accessible by said analyzing means, wherein said analyzing means identifies any digital certificates that are used to digitally sign signed data in at least said inbound data, and causes any such digital certificates, or sufficient descriptive data to identify such digital certificates to be stored in said data repository.
50 . The system of claim 49 wherein said analyzing means records the results of any verification for an digital certificate in said data repository together with said digital certificate or together with said descriptive data.
51 . The system of claim 50 wherein said analyzing means, if it identifies a digital certificate in said inbound data, determines whether said digital certificate has been previously stored in said data repository, or whether said descriptive information identifying said digital certificate has been stored in said data repository, and if said digital certificate has been previously stored, look-ups the results of any previous verification of whether said digital certificate has been revoked, wherein said analyzing means determines whether or not to verify if said digital certificate has been revoked in dependence on said results of any previous verification of whether said identified digital certificate has been revoked.
52 . The system of claim 43 wherein said analyzing means further verifies whether or not a digital certificate has been revoked, and wherein said application means prevents said inbound data being viewed by a user of said application means if said analyzing means determines that said digital certificate has been revoked.
53 . The system of claim 43 wherein said analyzing means further verifies whether or not a digital certificate has been revoked, and said application means notifies a user of said application means that said inbound data is not to be relied upon if said analyzing means determines that said digital certificate has been revoked.
54 . The system of claim 43 wherein said analyzing means is located on each of said one or more workstations.
55 . The system of claim 43 wherein said application means is a web browser.
56 . The system of claim 55 wherein said analyzing means is a plug-in module of said web browser.
57 . The system of claim 56 wherein said web browser is Microsoft's Internet Explorer and said analyzing means is a Browser Helper Object.
58 . The system of claim 43 wherein said application means is an e-mail client.
59 . The system of claim 58 wherein said analyzing means is a plug-in module of said e-mail client.
60 . The system of claim 59 wherein said e-mail client is Microsoft's Outlook e-mail client and said analyzing means is a Microsoft client extension.
61 . The system of claim 43 wherein said computer network comprises a server, and said analyzing means is located at a point on said computer network intermediate to said one or more workstations and said server, or said analyzing means is located at said server.
62 . The system of claim 43 wherein said computer network to which said one or more workstations are connected is a public computer network, and wherein said one or more workstations together form a private computer network.
63 . The system of claim 43 further comprising a supervisor workstation, said policy data being accessible by said supervisor workstation, such that a user of said supervisor workstation can edit said policy data.