IP Library Granted Patent US 8,234,693
Granted Patent B2
US 8,234,693 · App. 12/334,066 · Granted Jul 31, 2012

Secure document management

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,234,693
App. No.
12/334,066
Granted
Jul 31, 2012
Kind
B2
Abstract

A method for providing secure document management includes receiving a document from a user having an associated security access profile and generating a security label to be stored as an attribute of the document. The security label includes a clearance component selected from an authorized subset of clearance components that are determined based on the security access profile associated with the user, and also includes one or more secondary security components selected from an authorized subset of secondary security components that are determined based on the clearance component of the security label and the security access profile associated with the user. The method includes storing the document in a document repository storing a plurality of documents each having an associated security label, and determining whether a third-party user is authorized to access the document based on a comparison of a security access profile of the third-party user and the security label associated with the document.

Claims (70)

1. A method for providing secure document management, comprising:

receiving a document from a user having an associated security access profile;

generating a security label to be stored as an attribute of the document, the security label comprising:

a clearance component selected from an authorized subset of a plurality of clearance components, the authorized subset of the plurality of clearance components determined based on the security access profile associated with the user; and

a secondary security component selected from an authorized subset of a plurality of secondary security components, the authorized subset of the plurality of secondary security components determined based on the clearance component of the security label and the security access profile associated with the user;

storing the document in a document repository storing a plurality of documents each having an associated security label;

determining whether a third-party user is authorized access the document based on a comparison of a security access profile of the third-party user and the security label associated with the document;

allowing, when a determination that the third-party user is authorized to access the document based on the comparison of the security access profile of the third-party user and the security label associated with the document, the third-party user to access the document:

receiving an edited version of the document from the third-party user, the edited version of the document having an associated updated security label, the updated security label comprising:

an updated clearance component selected from an authorized subset of a plurality of clearance components, the authorized subset of a plurality of clearance components determined based on the security access profile associated with the third-party user; and

one or more updated secondary security components selected from a subset of a plurality of secondary security components, the subset of a plurality of secondary security components determined based on the updated clearance component of the updated security label and the security access profile associated with the third-party user; and

storing the edited version of the document in the document repository storing the plurality of documents each having an associated security label.

2. The method of claim 1 , wherein receiving the document from the user comprises receiving a newly-created document.

3. The method of claim 1 , wherein receiving the document from the user comprises importing an existing document.

4. The method of claim 1 , comprising:

generating a first interface to be displayed to the user, the first interface comprising a clearance component field comprising one or more clearance components of the subset of authorized clearance components to the user;

receiving from the user a selection of an authorized clearance component from the one or more clearance components of the subset of authorized clearance components;

determining, in response to the selection of the clearance component of the security label by the user, the one or more authorized subsets of secondary security components from the plurality of secondary security components based on the selected clearance component of the security label and the security access profile associated with the user; and

generating a second interface to be displayed to the user, the second interface comprising one or more secondary security component fields, each secondary security component field comprising one or more secondary security components of a subset of authorized secondary security components.

5. The method of claim 1 , wherein the security label comprises an W1classified component, the unclassified component being independent of the security access profile of the user, the clearance component of the security label, and the one or more secondary security components of the security label.

6. The method of claim 1 , comprising:

scanning, upon receiving the document from the user, the content of the document; and

comparing the content of the document to the security label associated with the document.

7. A system for providing secure document management, comprising: a document repository operable to store a plurality of documents each having an associated security label;

one or more processing units comprising a computer processor operable to: receive a document from a user having an associated security access profile;

generate a security label to be stored as an attribute of the document, the security label comprising:

a clearance component selected from an authorized subset of a plurality of clearance components, the authorized subset of the plurality of clearance components determined based on the security access profile associated with the user; and

a secondary security component selected from an authorized subset of a plurality of secondary security components, the authorized subset of the plurality of secondary security components determined based on the clearance component of the security label and the security access profile associated with the user;

store the document in a document repository, which comprises memory, storing a plurality of documents each having an associated security label;

determine whether a third-party user is authorized access the document based on a comparison of a security access profile of the third-party user and the security label associated with the document;

allow, when a determination that the third-party user is authorized to access the document based on the comparison of the security access profile of the third-party user and the security label associated with the document, the third-party user to access the document;

receive an edited version of the document from the third-party user, the edited version of the document having an associated updated security label, the updated security label comprising:

an updated clearance component selected from an authorized subset of a plurality of clearance component, the authorized subset of a plurality of clearance components determined based on the security access profile associated with the third-party user; and

one or more updated secondary security components selected from a subset of a plurality of secondary security components, the subset of a plurality of secondary security components determined based on the updated clearance component of the updated security label and the security access profile associated with the third-party user; and

store the edited version of the document in the document repository storing the plurality of documents each having an associated security label.

8. The system of claim 7 , wherein the document received from the user comprises a newly-created document.

9. The system of claim 7 , wherein the receiving the document from the user comprises importing an existing document.

10. The system of claim 7 , wherein the one or more processing units are operable to:

generate a first interface to be displayed to the user, the first interface comprising a clearance component field comprising one or more clearance components of the subset of authorized clearance components to the user;

receive from the user a selection of an authorized clearance component from the one or more clearance components of the subset of authorized clearance components;

determine, in response to the selection of the clearance component of the security label by the user, the one or more authorized subsets of secondary security components from the plurality of secondary security components based on the selected clearance component of the security label and the security access profile associated with the user; and

generate a second interface to be displayed to the user, the second interface comprising one or more secondary security component fields, each secondary security component field comprising one or more secondary security components of a subset of authorized secondary security components.

11. The system of claim 7 , wherein the security label comprises an unclassified component, the unclassified component being independent of the security access profile of the user, the clearance component of the security label, and the one or more secondary security components of the security label.

12. The system of claim 7 , wherein the one or more processing units are operable to:

scan, upon receiving the document from the user, the content of the document; and

compare the content of the document to the security label associated with the document.

13. An article, comprising:

a computer readable medium comprising non-transitory stored instructions that enable a machine to:

receive a document from a user having an associated security access profile;

generate a security label to be stored as an attribute of the document, the security label comprising:

a clearance component selected from an authorized subset of a plurality of clearance components, the authorized subset of the plurality of clearance components determined based on the security access profile associated with the user; and

a secondary security component selected from an authorized subset of a plurality of secondary security components, the authorized subset of the plurality of secondary security components determined based on the clearance component of the security label and the security access profile associated with the user;

store the document in a document repository storing a plurality of documents each having an associated security label;

determine whether a third-party user is authorized access the document based on a comparison of a security access profile of the third-party user and the security label associated with the document;

allow, when a determination that the third-party user is authorized to access the document based on the comparison of the security access profile of the third-party/user and the security label associated with the document, the third-party user to access the document;

receive an edited version of the document from the third-party user, the edited version of the document having an associated updated security label, the updated security label comprising:

an updated clearance component selected from an authorized subset of a plurality of clearance components, the authorized subset of a plurality of clearance components determined based on the security access profile associated with the third-party user; and

one or more updated secondary security components selected from a subset of a plurality of secondary security components, the subset of a plurality of secondary security components determined based on the updated clearance component of the updated security label and the security access profile associated with the third-party user; and

store the edited version of the document in the document repository storing the plurality of documents each having an associated security label.

14. The software of claim 13 , wherein the document received from the user comprises one or more of:

a newly-created document; and an imported existing document.

15. The software of claim 13 , operable to:

generate a first interface to be displayed to the user, the first interface comprising a clearance component field comprising one or more clearance components of the subset of authorized clearance components to the user;

receive from the user a selection of an authorized clearance component from the one or more clearance components of the subset of authorized clearance components;

determine, in response to the selection of the clearance component of the security label by the user, the one or more authorized subsets of secondary security components from the plurality of secondary security components based on the selected clearance component of the security label and the security access profile associated with the user; and

generate a second interface to be displayed to the user, the second interface comprising one or more secondary security component fields, each secondary security component field comprising one or more secondary security components of a subset of authorized secondary security components.

16. The software of claim 13 , wherein the security label comprises an unclassified component, the unclassified component being independent of the security access profile of the user, the clearance component of the security label, and the one or more secondary security components of the security label.

17. The software of claim 13 , operable to: scan, upon receiving the document from the user, the content of the document;

and

compare the content of the document to the security label associated with the document.

Assignments (15)
RELEASE OF SECURITY INTEREST Recorded Apr 2, 2025
From: UBS AG, STAMFORD BRANCH
To: FORCEPOINT, LLC; BITGLASS, LLC
Reel/Frame 070706/0263 →
CHANGE OF NAME Recorded Mar 21, 2025
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: EVERFOX HOLDINGS LLC
Reel/Frame 070585/0625 →
SECURITY INTEREST Recorded Sep 29, 2023
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: APOLLO ADMINISTRATIVE AGENCY LLC, AS COLLATERAL AGENT
Reel/Frame 065086/0822 →
CHANGE OF NAME Recorded May 12, 2021
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 056216/0309 →
PATENT SECURITY AGREEMENT Recorded Jan 20, 2021
From: REDOWL ANALYTICS, INC.; FORCEPOINT LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 055052/0302 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: WEBSENSE, INC.; PORTAUTHORITY TECHNOLOGIES, LLC (FKA PORTAUTHORITY TECHNOLOGIES, INC.); RAYTHEON OAKLEY SYSTEMS, LLC; FORCEPOINT FEDERAL LLC (FKA RAYTHEON CYBER PRODUCTS, LLC, FKA RAYTHEON CYBER PRODUCTS, INC.)
Reel/Frame 055492/0146 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 1, 2017
From: FORCEPOINT FEDERAL LLC
To: FORCEPOINT LLC
Reel/Frame 043397/0460 →
CHANGE OF NAME Recorded Feb 16, 2016
From: RAYTHEON CYBER PRODUCTS, LLC
To: FORCEPOINT FEDERAL LLC
Reel/Frame 037821/0818 →
PATENT SECURITY AGREEMENT Recorded Jun 9, 2015
From: WEBSENSE, INC.; RAYTHEON OAKLEY SYSTEMS, LLC; RAYTHEON CYBER PRODUCTS, LLC (FORMERLY KNOWN AS RAYTHEON CYBER PRODUCTS, INC.); PORT AUTHORITY TECHNOLOGIES, INC.
To: RAYTHEON COMPANY
Reel/Frame 035859/0282 →
CHANGE OF NAME Recorded Jun 2, 2015
From: RAYTHEON CYBER PRODUCTS, INC.
To: RAYTHEON CYBER PRODUCTS, LLC
Reel/Frame 035806/0367 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 28, 2015
From: RAYTHEON COMPANY
To: RAYTHEON CYBER PRODUCTS, INC.
Reel/Frame 035774/0322 →
CORRECTIVE ASSIGNMENT TO CORRECT THE INVENTOR?S NAME (DANEIL TEIJIDO) PREVIOUSLY RECORDED ON REEL 031309 FRAME 0881. ASSIGNOR(S) HEREBY CONFIRMS THE CORRECT SPELLING OF THE INVENTOR'S NAME IS DANIEL TEIJIDO. Recorded Oct 4, 2013
From: TEIJIDO, DANIEL
To: RAYTHEON COMPANY
Reel/Frame 031345/0225 →
CORRECTIVE ASSIGNMENT TO CORRECT THE APPLICATION NUMBER (NO. 13/334,066) PREVIOUSLY RECORDED ON REEL 031198 FRAME 0845. ASSIGNOR(S) HEREBY CONFIRMS THE CORRECT APPLICATION NUMBER IS 12/334,066. Recorded Sep 17, 2013
From: TEIJIDO, DANEIL
To: RAYTHEON COMPANY
Reel/Frame 031309/0881 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 13, 2013
From: TEIJIDO, DANIEL
To: RAYTHEON COMPANY
Reel/Frame 031198/0845 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 12, 2008
From: STAHL, NOAH Z.; BARTLETT, WENDY S.; BROOKS, RANDALL S.
To: RAYTHEON COMPANY
Reel/Frame 021973/0299 →