Information Management System
An information management system is described comprising one or more workstations running applications to allow a user of the workstation to connect to a network, such as the Internet. Each application has an analyzer, which monitors transmission data that the application is about to transmit to the network or about to receive from the network and which determines an appropriate action to take regarding that transmission data. Such actions may be extracting data from the transmission data, such as passwords and usernames, digital certificates or eCommerce transaction details for storage in a database; ensuring that the transmission data is transmitted at an encryption strength appropriate to the contents of the transmission data; determining whether a check needs to be made as to whether a digital certificate received in transmission data is in force, and determining whether a transaction about to be made by a user of one of the workstations needs third party approval before it is made. The analyzer may consult a policy data containing a policy to govern the workstations in order to make its determination. The information management system provides many advantages in the eCommerce environment to on-line trading companies, who may benefit by being able to regulate the transactions made by their staff according to their instructions in a policy data, automatically maintain records of passwords and business conducted on-line, avoid paying for unnecessary checks on the validity of digital certificates and ensure that transmissions of data made by their staff are always protected at an agreed strength of encryption.
1 . An information management system comprising:
a plurality of workstations connected to a computer network, each workstation having a memory;
a data repository arranged to receive data from each of said workstations;
an application stored in said memory of each workstation for transmitting outbound data to said computer network and receiving inbound data from said computer network;
policy data containing rules defining relevant commercial data which is to be stored in said data repository; and
an analyzer, said analyzer monitoring, in conjunction with said policy data, at least one of said outbound data and said inbound data, identifying in at least one of said outbound data and said inbound data, relevant commercial data that is to be stored in said data repository in accordance with said rules in said policy data, and causing said relevant commercial data to be stored in said data repository.
2 . The system of claim 1 wherein said relevant commercial data that is to be stored in said data repository is encrypted prior to it being transmitted to said data repository.
3 . The system of claim 1 wherein said relevant commercial data that is stored in said data repository is encrypted.
4 . The system of claim 1 wherein said computer network, to which said one or more workstations are connected, is the Internet.
5 . The system of claim 4 wherein said analyzer identifies, as relevant commercial data, at least one of usernames and passwords used to identify a user, and usernames and passwords used to access web pages on the Internet, and the URL address of the web page at which those usernames and passwords are used, said identified usernames, passwords and said identified URLs being stored in said data repository.
6 . The system of claim 5 wherein said analyzer identifies usernames and passwords from the field names of data contained in at least one of said outbound data and said inbound data.
7 . The system of claim 5 wherein a representation of the input fields of a web page is stored in said memory of said one or more workstations, and wherein said analyzer identifies usernames and passwords from said representation.
8 . The system of claim 5 wherein said analyzer identifies usernames or passwords from the field types of data contained in said outbound or said inbound data.
9 . The system of claim 4 wherein said analyzer identifies, as relevant commercial data, digital certificates contained in at least one of said outbound or said inbound data or used to digitally sign signed data in said inbound data or said outbound data, or sufficient descriptive data to identify such digital certificates, said digital certificates and/or said descriptive data being stored in said data repository.
10 . The system of claim 9 wherein said analyzer identifies one or more of the following data as relevant commercial data: whether or not said digital certificate has been revoked; the identity of the holder of said digital certificate; the amount of any eCommerce transaction being made that is related to said digital certificate; the goods or services being sold in any eCommerce transaction being made with said digital certificate; the date of receipt of said digital certificate; and wherein said identified data is stored with said digital certificate in said data repository.
11 . The system of claim 4 wherein the analyzer identifies when an eCommerce transaction is occurring and if an eCommerce transaction is identified as occurring, identifies in said outbound or said inbound data one or more of the following data as relevant commercial data: the URL address or e-mail address of the remote location to which outbound data is being transmitted or inbound data is being received; the web pages accessed by a user of said one or more workstations during the transaction; the amount of the transaction; the goods or services being traded in the transaction; the date of the transaction; and wherein said relevant commercial data is stored in said data repository.
12 . The system of claim 1 wherein said analyzer is located on each of said one or more workstations.
13 . The system of claim 1 wherein said application is a web browser.
14 . The system of claim 13 wherein said analyzer is a plug-in module of said web browser.
15 . The system of claim 14 wherein said web browser is Microsoft's Internet Explorer and said analyzer is a Browser Helper Object.
16 . The system of claim 1 wherein said application is an e-mail client.
17 . The system of claim 16 wherein said analyzer is a plug-in module of said e-mail client.
18 . The system of claim 17 wherein said e-mail client is Microsoft's Outlook e-mail client and said analyzer is a Microsoft Exchange client extension.
19 . The system of claim 1 wherein said computer network includes a server and said analyzer is located at a point on said computer network intermediate to said one or more workstations and said server, or said analyzer is located at said server.
20 . The system of claim 1 further comprising a supervisor workstation, said supervisor workstation having access to said data repository and viewing said relevant commercial data stored in said data repository.
21 . The system of claim 20 wherein said policy data is accessible by said supervisor workstation, such that a user of said supervisor workstation can edit said policy data.
22 . The system of claim 1 wherein a workstation of said plurality of workstations has access to said data repository and views said relevant commercial data stored in said data repository.
23 . The system of claim 1 wherein said computer network to which said one or more workstations are connected is a public computer network, and wherein said one or more workstations together form a private computer network.
24 . A method of managing information comprising the steps of:
providing a plurality of workstations connected to a computer network, each workstation having a memory;
providing a data repository arranged to receive data from each of said workstations;
providing an application stored in said memory of each workstation for transmitting outbound data to said computer network and receiving inbound data from said computer network;
providing policy data containing rules defining relevant commercial data which is to be stored in said data repository; and
analyzing at least one of said outbound data and said inbound data, with reference to said policy data, to identify in at least one of said outbound data and said inbound data, relevant commercial data that is to be stored in said data repository in accordance with said rules in said policy data; and
storing said relevant commercial data in said data repository.
25 . The method of claim 24 further comprising the step of encrypting said relevant commercial data that is to be stored in said data repository prior to it being stored in said data repository.
26 . The method of claim 24 further comprising the step of encrypting said relevant commercial data that is stored in said data repository after it has been stored in said data repository.
27 . The method of claim 24 wherein said computer network, to which said one or more workstations are connected, is the Internet.
28 . The method of claim 27 wherein in the analyzing step, at least one of usernames and passwords used to identify a user, and usernames and passwords used access web pages on the Internet, and the URL address of those web pages, are identified as relevant commercial data.
29 . The method of claim 28 wherein in said analyzing step, usernames and passwords are identified from the field names of data contained in at least one of said outbound data and said inbound data.
30 . The method of claim 28 wherein a representation of the input fields of a web page is stored in said memory of said one or more workstations, and wherein in said analyzing step usernames and passwords are identified from said representation.
31 . The method of claim 28 wherein in said analyzing step usernames or passwords are identified from the field types of data contained in said outbound or said inbound data.
32 . The method of claim 27 wherein in said analyzing step, digital certificates contained in at least one of said outbound or said inbound data or used to digitally sign signed data in said inbound or said outbound data, are identified as relevant commercial data, or sufficient descriptive data to identify such digital certificates, is identified as relevant commercial data.
33 . The method of claim 32 wherein said analyzing step includes identifying one or more of the following data as relevant commercial data: whether or not said digital certificate has been revoked; the identity of the holder of said digital certificate; the amount of any eCommerce transaction being made that is related to said digital certificate; the goods or services being sold in any eCommerce transaction being made with said digital certificate; and the date of receipt of said digital certificate.
34 . The method of claim 27 wherein said analyzing step includes identifying when an eCommerce transaction is occurring and if an on-line eCommerce transaction is identified as occurring, identifying in said outbound or said inbound data one or more of the following data as relevant commercial data: the URL address or e-mail address of the remote location to which outbound data is being transmitted or inbound data is being received; the web pages accessed by a user of said one or more workstations during the transaction; the amount of the transaction; the goods or services being traded in the transaction; the date of the transaction.
35 . The method of claim 24 wherein said analyzing step is carried out at said one or more workstations.
36 . The method of claim 24 wherein said application is a web browser.
37 . The method of claim 36 wherein said analyzing step is performed by a plug-in module of said web browser.
38 . The method of claim 37 wherein said web browser is Microsoft's Internet Explorer and said plug-in module is a Browser Helper Object.
39 . The method of claim 24 wherein said application is an e-mail client.
40 . The method of claim 39 wherein said analyzing step is performed by a plug-in module of said e-mail client.
41 . The method of claim 40 wherein said e-mail client is Microsoft's Outlook e-mail client and said plug-in module is a Microsoft Exchange client extension.
42 . The method of claim 24 wherein said computer network includes a server and said analyzing step is performed at a point on said computer network intermediate to said one or more workstations and said server, or said analyzing step is performed at said server.
43 . The method of claim 24 further comprising the step of providing a supervisor workstation, said supervisor workstation having access to said data repository and viewing said relevant commercial data stored in said data repository.
44 . The method of claim 43 wherein said policy data is accessible by said supervisor workstation, such that a user of said supervisor workstation can edit said policy data.
45 . The method of claim 24 wherein a workstation of said plurality of workstations has access to said data repository and views said relevant commercial data stored in said data repository.
46 . The method of claim 24 wherein said computer network to which said one or more workstations are connected is a public computer network, and wherein said one or more workstations together form a private computer network.
47 . An information management system comprising:
a plurality of workstations connected to a computer network, each workstation having a memory;
storage means for storing data received from each of said workstations;
application means, stored in said memory of each workstation, for transmitting outbound data to said computer network and receiving inbound data from said computer network;
policy storage means for providing policy data containing rules defining relevant commercial data which is to be stored in said storage means; and
analyzing means for monitoring, in conjunction with said policy means, at least one of said outbound data and said inbound data, identifying in at least one of said outbound data and said inbound data, relevant commercial data that is to be stored in said storage means in accordance with said rules in said policy means, and causing said relevant commercial_data to be stored in said storage means.
48 . The system of claim 47 wherein said relevant commercial data that is to be stored in said storage means is encrypted prior to it being transmitted to said storage means.
49 . The system of claim 47 wherein said relevant commercial data that is stored in said storage means is encrypted.
50 . The system of claim 47 wherein said computer network, to which said one or more workstations are connected, is the Internet.
51 . The system of claim 50 wherein said analyzing means identifies, as relevant commercial data, at least one of usernames and passwords used to identify a user, and usernames and passwords used to access web pages on the Internet, and the URL address of the web page at which those usernames and passwords are used, said identified usernames, passwords and said identified URLs being stored in said storage means.
52 . The system of claim 51 wherein said analyzing means identifies usernames and passwords from the field names of data contained in at least one of said outbound data and said inbound data.
53 . The system of claim 51 wherein a representation of the input fields of a web page is stored in said memory of said one or more workstations, and wherein said analyzing means identifies usernames and passwords from said representation.
54 . The system of claim 51 wherein said analyzing means identifies usernames or passwords from the field types of data contained in said outbound or said inbound data.
55 . The system of claim 50 wherein said analyzing means identifies, as relevant commercial data, digital certificates contained in at least one of said outbound or said inbound data or used to digitally sign signed data in said inbound data or said outbound data, or sufficient descriptive data to identify such digital certificates, said digital certificates and/or said descriptive data being stored in said storage means.
56 . The system of claim 55 wherein said analyzing means identifies one or more of the following data as relevant commercial data: whether or not said digital certificate has been revoked; the identity of the holder of said digital certificate; the amount of any eCommerce transaction being made that is related to said digital certificate; the goods or services being sold in any eCommerce transaction being made with said digital certificate; the date of receipt of said digital certificate; and wherein said identified data is stored with said digital certificate in said storage means.
57 . The system of claim 50 wherein the analyzing means identifies when an eCommerce transaction is occurring and if an eCommerce transaction is identified as occurring, identifies in said outbound or said inbound data one or more of the following data as relevant commercial data: the URL address or e-mail address of the remote location to which outbound data is being transmitted or inbound data is being received; the web pages accessed by a user of said one or more workstations during the transaction; the amount of the transaction; the goods or services being traded in the transaction; the date of the transaction; and wherein said relevant commercial data is stored in said storage means.
58 . The system of claim 47 wherein said analyzing means is located on each of said one or more workstations.
59 . The system of claim 47 wherein said application means is a web browser.
60 . The system of claim 59 wherein said analyzing means is a plug-in module of said web browser.
61 . The system of claim 60 wherein said web browser is Microsoft's Internet Explorer and said analyzing means is a Browser Helper Object.
62 . The system of claim 47 wherein said application means is an e-mail client.
63 . The system of claim 62 wherein said analyzing means is a plug-in module of said e-mail client.
64 . The system of claim 63 wherein said e-mail client is Microsoft's Outlook e-mail client and said analyzing means is a Microsoft Exchange client extension.
65 . The system of claim 47 wherein said computer network includes a server and said analyzing means is located at a point on said computer network intermediate to said one or more workstations and said server, or said analyzing means is located at said server.
66 . The system of claim 47 further comprising a supervisor workstation, said supervisor workstation having access to said storage means and viewing said relevant commercial data stored in said storage means.
67 . The system of claim 66 wherein said policy storage means is accessible by said supervisor workstation, such that a user of said supervisor workstation can edit said policy data.
68 . The system of claim 47 wherein a workstation of said plurality of workstations has access to said storage means and views said relevant commercial data stored in said storage means.
69 . The system of claim 47 wherein said computer network to which said one or more workstations are connected is a public computer network, and wherein said one or more workstations together form a private computer network.