IP Library Granted Patent US 9,460,296
Granted Patent B2
US 9,460,296 · App. 13/946,770 · Granted Oct 4, 2016

Systems, methods and media for selective decryption of files containing sensitive data

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,460,296
App. No.
13/946,770
Granted
Oct 4, 2016
Kind
B2
Abstract

Systems, methods and media are provided for selective decryption of files. One method includes monitoring a secure file storage area including at least one file using a selective decryption process associated with the secure file storage area. Content of each of the at least one file is protected with an encryption. The method also includes detecting a request by an application program for one of the at least one file. The method further includes determining whether the application program needs to access the content of the requested file. The method also includes, when it is determined that the application program does not need to access the content of the requested file, allowing the application program to access the file content without decrypting the encryption.

Claims (50)

1. A method, comprising:

monitoring a secure file storage area including at least one file using a selective decryption process associated with the secure file storage area, wherein content of each of the at least one file is protected with an encryption;

detecting a request by an application program for one of the at least one file;

determining whether the application program needs to access at least a part of the content of the requested file;

when it is determined that the application program does not need to access the at least a part of the content of the requested file, allowing the application program to access the content of the requested file without decrypting the encryption; and

when it is determined that the application program does need to access the at least a part of the content of the requested file:

decrypting the encryption,

allowing the application program to access the decrypted file content,

detecting a write-request by the application program for writing the decrypted file content to an unsecure location outside of the secure file storage area, and

re-encrypting the decrypted file content using the selective decryption process before the file content is written to the unsecure location, wherein the re-encryption of the decrypted file content is performed such that the application program is not aware of the re-encryption of the decrypted file content.

2. The method of claim 1 , wherein the application program includes a backup daemon, wherein allowing the application program to access the file content includes providing a copy of the requested file to the backup daemon without decrypting the encryption and wherein the copy of the requested file is backed up to a backup tape.

3. The method of claim 1 , wherein the application program includes an electronic-mail (e-mail) application, wherein allowing the application program to access the file content includes providing a copy of the requested file to the email application without decrypting the encryption and wherein the copy of the requested file is attached to an e-mail.

4. The method of claim 1 , wherein the application program includes one of (1) a word processing application, (2) an image-processing application, (3) a spreadsheet application, and (4) a multi-media processing application, and wherein the requested file is open and the decrypted file content is displayed.

5. The method of claim 1 , wherein the selective decryption process is configured to encrypt content of a file when the file is initially saved in the secure file storage area and wherein the secure file storage area is communicatively coupled to a computing device running the selective decryption process.

6. The method of claim 1 , wherein the secure file storage area includes one of (1) one or more file folders, (2) one or more segments of a disk and (3) one or more blocks of memory.

7. The method of claim 1 , wherein the selective decryption process includes a file system driver including one of (1) one or more kernel components, (2) one or more user-level application components and (3) a combination of kernel components and user-level application components.

8. The method of claim 1 , wherein the secure file storage area is located at a cloud storage client device running the selective decryption process and further comprising receiving, at the cloud storage client device, one or more of the at least one file from a cloud storage server over a communication network.

9. An apparatus, comprising:

one or more interfaces configured to provide communication with at least one computing device over a network;

a secure file storage area including at least one file; and

a processor, in communication with the secure file storage area and the one or more interfaces, configured to run a selective encryption module stored in memory that is configured to:

monitor the secure file storage area, wherein content of each of the at least one file is protected with an encryption;

detect a request by an application program for one of the at least one file;

determine whether the application program needs to access at least a part of the content of the requested file;

when it is determined that the application program does not need to access the at least a part of the content of the requested file, allowing the application program to access the content of the requested file without decrypting the encryption; and

when it is determined that the application program does need to access the at least a part of the content of the requested file:

decrypt the encryption,

allow the application program to access the decrypted file content,

detect a write-request by the application program for writing the decrypted file content to an unsecure location outside of the secure file storage area, and

re-encrypt the decrypted file content before the file content is written to the unsecure location, wherein the re-encryption of the decrypted file content is performed such that the application program is not aware of the re-encryption of the decrypted file content.

10. The apparatus of claim 9 , wherein the application program includes a backup daemon, wherein allowing the application program to access the file content includes providing a copy of the requested file to the backup daemon without decrypting the encryption and wherein the copy of the requested file is backed up to a backup tape.

11. The apparatus of claim 9 , wherein the application program includes an electronic-mail (e-mail) application, wherein allowing the application program to access the file content includes providing a copy of the requested file to the email application without decrypting the encryption and wherein the copy of the requested file is attached to an e-mail.

12. The apparatus of claim 9 , wherein the application program includes one of (1) a word-processing application, (2) an image-processing application, (3) a spreadsheet application, and (4) a multi-media processing application, and wherein the requested file is open and the decrypted file content is displayed.

13. The apparatus of claim 9 , wherein the secure file storage area includes one of (1) one or more file folders, (2) one or more segments of a disk and (3) one or more blocks of memory.

14. A non-transitory computer readable medium having executable instructions operable to cause an apparatus to:

monitor a secure file storage area that is coupled to the apparatus and includes at least one file, wherein content of each of the at least one file is protected with an encryption;

detect a request by an application program for one of the at least one file;

determine whether the application program holds an access privilege for accessing the requested file;

when it is determined that the application program holds the access privilege for accessing the requested file, further determine whether the application program needs to access at least a part of the content of the requested file by checking a list of application programs that need to access the content of the requested file;

when it is determined that the application program is not in the list, allow the application program to access the content of the requested file by providing a copy of the requested file to the application program without decrypting the encryption;

when it is determined that the application program is included in the list:

decrypt the encryption,

allow the application program to access the decrypted file content,

detect a write-request by the application program for writing the decrypted file content to an unsecure location outside of the secure file storage area, and

re-encrypt the decrypted file content before the file content is written to the unsecure location in a way that the application program is unaware of the re-encryption of the decrypted file content; and

when it is determined that the application program does need to access the at least a part of the content of the requested file:

decrypt the encryption,

allow the application program to access the decrypted file content,

detect a second write-request by the application program for writing the decrypted file content to a second unsecure location outside of the secure file storage area, and

re-encrypt the decrypted file content using the selective decryption process before the file content is written to the second unsecure location, wherein the re-encryption of the decrypted file content is performed such that the application program is not aware of the re-encryption of the decrypted file content.

Assignments (17)
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY 14633493 WHICH WAS ENTERED INCORRECTLY AS 14633793 PREVIOUSLY RECORDED ON REEL 71176 FRAME 315. ASSIGNOR(S) HEREBY CONFIRMS THE FIRST LIEN NEWCO SECURITY AGREEMENT. Recorded Nov 10, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 073818/0515 →
FIRST LIEN NEWCO SECURITY AGREEMENT Recorded May 5, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 071176/0315 →
SECURITY INTEREST Recorded May 3, 2025
From: IVANTI US LLC
To: ALTER DOMUS (US) LLC
Reel/Frame 071165/0089 →
NOTICE OF SUCCESSION OF AGENCY FOR SECURITY INTEREST AT REEL/FRAME 054665/0873 Recorded Apr 29, 2025
From: BANK OF AMERICA, N.A., AS RESIGNING AGENT
To: ALTER DOMUS (US) LLC, AS SUCCESSOR AGENT
Reel/Frame 071123/0386 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; IVANTI, INC.; MOBILEIRON, INC.; IVANTI US LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 054665/0062 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; INVANTI, INC.; MOBILEIRON, INC.; INVANTI US LLC
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 054665/0873 →
RELEASE OF SECURITY INTEREST : RECORDED AT REEL/FRAME - 43971/0495 Recorded Dec 1, 2020
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: APPSENSE US LLC
Reel/Frame 054560/0278 →
RELEASE OF SECURITY INTEREST : RECORDED AT REEL/FRAME - 43971/0549 Recorded Dec 1, 2020
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: APPSENSE US LLC
Reel/Frame 054560/0389 →
CHANGE OF NAME Recorded Mar 5, 2019
From: APPSENSE US LLC
To: IVANTI US LLC
Reel/Frame 048511/0832 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Sep 15, 2017
From: APPSENSE US LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 043971/0495 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Sep 15, 2017
From: APPSENSE US LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 043971/0549 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 25, 2017
From: APPSENSE LIMITED
To: APPSENSE US LLC
Reel/Frame 043406/0821 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORDED AT R/F 038333/0821 Recorded Sep 28, 2016
From: JEFFERIES FINANCE LLC
To: APPSENSE LIMITED
Reel/Frame 040171/0172 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORDED AT R/F 038333/0879 Recorded Sep 28, 2016
From: JEFFERIES FINANCE LLC
To: APPSENSE LIMITED
Reel/Frame 040169/0981 →
SECURITY INTEREST Recorded Apr 20, 2016
From: APPSENSE LIMITED
To: JEFFERIES FINANCE LLC
Reel/Frame 038333/0821 →
SECURITY INTEREST Recorded Apr 20, 2016
From: APPSENSE LIMITED
To: JEFFERIES FINANCE LLC
Reel/Frame 038333/0879 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 2, 2013
From: WALTON, TRAVIS; DELIVETT, PAUL
To: APPSENSE LIMITED
Reel/Frame 030930/0332 →