IP Library Patent Application 14142155
Patent Application
App. No. 14/142,155

Decrypting Files for Data Leakage Protection in an Enterprise Network

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
14/142,155
Abstract

A method of decrypting an encrypted file within an enterprise network is provided. The method includes identifying by a password collecting module a password entered during a file encryption procedure performed at a terminal and storing the password; receiving an encrypted file by a data leakage protection (DLP) module; and attempting to decrypt the encrypted file with the password by the DLP module.

Claims (40)

1 . A method, comprising:

monitoring: an application executed at a terminal;

monitoring a procedure performed with a predetermined application executed at the terminal; and

identifying a password entered by users for a file encryption procedure performed with the predetermined application.

2 . The method of claim 1 , wherein the identifying further comprises identifying meta data of the password.

3 . The method of claim 1 , further comprising:

receiving an encrypted file from the terminal; and

decrypting the encrypted file with the password.

4 . The method of claim 3 , wherein the decrypting is performed in a real-time manner.

5 . The method of claim 3 , wherein the receiving an encrypted file further comprises identifying meta data of the encrypted file, wherein the decrypting further comprises selecting the password by determining that meta data of the encrypted file matches at least a potion of meta data of the password.

6 . The method of claim 3 , wherein the decrypting comprises decrypting the encrypted file with multiple passwords obtained by executing the method of claim 1 two or more times.

7 . The method of claim 6 , wherein the receiving an encrypted file further comprises identifying meta data of the encrypted file, wherein the decrypting further comprises determining priority given to attempting to decrypt with each password according to meta data of the multiple passwords obtained by executing the method of claim 2 several times.

8 . The method of claim 6 , wherein the receiving an encrypted file further comprises identifying meta data of the encrypted file, wherein the decrypting further comprises determining a degree of match between meta data of the encrypted file and meta data of the multiple passwords obtained by executing the method of claim 2 several times, so as to determine priority given to a decryption performed with each password.

9 . An apparatus, comprising:

a processor;

a non-transitory, computer-readable medium coupled to the processor; and

logic, stored on the computer-readable medium and executed on the processor, for:

monitoring an application executed at a terminal;

monitoring a procedure performed with a predetermined application executed at the terminal; and

identifying a password entered by users for a file encryption procedure performed with the predetermined application.

10 . The apparatus of claim 9 , wherein the logic for identifying further comprises logic for identifying meta data of the password.

11 . The apparatus of claim 9 , the logic further comprising logic for:

receiving an encrypted file from the terminal; and

decrypting the encrypted file with the password.

12 . The apparatus of claim 11 , wherein the decrypting is performed in a real-time manner.

13 . The apparatus of claim 11 , wherein the logic for receiving an encrypted file further comprises logic for identifying meta data of the encrypted file, wherein the logic for decrypting further comprises logic for selecting the password by determining that meta data of the encrypted file matches at least a portion of meta data of the password.

14 . The apparatus of claim 11 , wherein the logic for decrypting comprises logic for decrypting the encrypted file with multiple passwords obtained by executing the logic of claim 9 two or more times.

15 . A computer programming product, comprising:

a non-transitory, computer-readable medium; and

logic, stored on the computer-readable medium for execution on a processor, for:

monitoring an application executed at a terminal;

monitoring a procedure performed with a predetermined application executed at the terminal; and

identifying a password entered by users for a file encryption procedure performed with the predetermined application.

16 . The computer programming product of claim 15 , wherein the logic for identifying further comprises logic for identifying meta data of the password.

17 . The computer programming product of claim 15 , the logic further comprising logic for:

receiving an encrypted file from the terminal; and

decrypting the encrypted file with the password.

18 . The computer programming product of claim 17 , wherein the decrypting is performed in a real-time manner.

19 . The computer programming product of claim 17 , wherein the logic for receiving an encrypted file further comprises logic fur identifying meta data of the encrypted file, wherein the logic for decrypting further comprises logic for selecting the password by determining that meta data of the encrypted file matches at least a portion of meta data of the password.

20 . The computer programming product of claim 17 , wherein the logic for decrypting comprises logic for decrypting the encrypted file with multiple passwords obtained by executing the logic of claim 9 two or more times.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 13, 2014
From: TSAI, YA HSUAN; YU, YING-HUNG; MAHADEVAN, HARIHARAN
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 033301/0018 →