IP Library Granted Patent US 9,298,895
Granted Patent B2
US 9,298,895 · App. 14/313,954 · Granted Mar 29, 2016

Preventing conflicts of interests between two or more groups using applications

Inventor: Keng Lim (Atherton, CA)
Assignee: NextLabs, Inc.
G06F21/125G06F11/3006G06F17/30011G06F17/30082G06F17/3089G06F21/316G06F21/604G06F21/6218G06Q10/06G06Q10/10H04L41/0893H04L63/0263H04L63/0272H04L63/10H04L63/102H04L63/1425H04L63/20H04L67/22G06F2216/03G06F2221/032Y10S707/922
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,298,895
App. No.
14/313,954
Granted
Mar 29, 2016
Kind
B2
Abstract

To prevent conflicts of interest, an information management system is used to make sure two or more groups are kept apart so that information does not circulate freely between these groups. The system has policies to implement an “ethical wall” to separate users or groups of users. The user or groups of user may be organized in any arbitrary way, and may be in the same organization or different organizations. The two groups (or two or more users) will not be able to access information belonging to the other, and users in one group may not be able to pass information to the other group. The system may manage access to documents, e-mail, files, and other forms of information.

Claims (53)

1. A method of managing information comprising:

providing an organization comprising a first group and a second group, wherein the organization has an information management system comprising a policy server comprising one or more rules to manage information of the organization;

within the first group of the organization, providing a first user and a first application program managed by the information management system;

when the first user uses the first application program to connect to a second user to transfer a first component of information, seeking approval from the policy server, the seeking approval from the policy server comprises:

determining a first component of information corresponds to an identifier designating the first component of information as confidential includes at least one of accessing contents of the first component of information and detecting a keyword in the contents; or accessing a metadata information associated with the first component of information and detecting a keyword in the metadata information;

extracting at least one attribute associated with the first component of information and the identifier, wherein the at least one attribute is used to determine whether to allow access to the first component of information to a user of the information management system, wherein the identifier is an uniform resource identifier associated with the first component of information;

based on the at least one attribute, evaluating using the policy server whether to allow access to the first component of information includes:

determining whether the first user's use of the first application program to connect to the second user is during a specific time period of the organization,

if approved, with the policy enforcer program, permitting the first user to use the first application program to connect to the second user comprises determining the first user's use of the first application program to connect to the second user is not during the specific time period, and

if not approved, with the policy enforcer program, blocking the first user from using the first application program to connect to the second user comprises determining the first user's use of the first application program to connect to the second user is during the specific time period.

2. The method of claim 1 wherein for the determining whether the first user's use of the first application program to connect to the second user is during a specific time period of the organization, the evaluating using the policy server whether to allow access to the first component of information includes:

determining a location of the first user, and wherein the permitting the first user to use the first application program to connect to the second user and the blocking the first user from using the first application program to connect to the second user are based on the determined location of the first user;

if approved, with the policy enforcer program, permitting the first user to use the first application program to connect to the second user and connecting the first user to the second user without seeking approval from the policy server; and

if not approved, with the policy enforcer program, blocking the first user from using the first application program to connect to the second user.

3. The method of claim 1 wherein the first application program comprises an instant messenger program.

4. The method of claim 1 wherein the first application program comprises an e-mail program.

5. A method of managing information comprising:

providing an organization comprising a first group and a second group, wherein the organization has an information management system comprising a policy server comprising one or more rules to manage information of the organization;

within the first group of the organization, providing a first user and a plurality of application programs, each application program being managed by a policy enforcer program of the information management system;

storing a subset of the one or more rules of the policy server on a first device of the first user;

when the first user uses a first application program of the plurality of application programs to communicate with a second user to transmit a first component of information, evaluating with the policy enforcer program the subset of the one or more rules stored on the first device to determine whether to approve the communication from the first user to the second user further comprising:

determining the first component of information corresponds to an identifier designating the first component of information as confidential wherein the identifier comprises a keyword in the contents of the first component of information;

extracting at least one attribute associated with the first component of information and the identifier; and

based on the at least one attribute, evaluating using the policy server whether to allow access to the first component of information comprising determining to approve when the first user's use is outside a defined time period associated with the organization;

if approved, permitting the first user to use the first application program to communicate with the second user without receiving approval from the policy server;

if not approved, blocking the first user from using the first application program to communicate with the second user,

wherein the at least one attribute is used to determine whether to allow access to the first component of information to a user of the information management system based on a storage location of the first component of information;

when the first user uses a second application program of the plurality of application programs, different from the first application program, to communicate with the second user, evaluating with the policy enforcer program the subset of the one or more rules stored on the first device to determine whether to approve the communication from the first user to the second user;

if approved, permitting the first user to use the second application program to communicate with the second user; and

if not approved, blocking the first user from using the second application program to communicate with the second user.

6. The method of claim 5 wherein the identifier comprises for the keyword in the contents of the first component of information, a keyword in the metadata information associated with the first component of information.

7. The method of claim 5 wherein for the determining to approve when the first user's use is outside a critical period of the organization, the evaluating using the policy server whether to allow access to the first component of information comprising determining to approve the first user's user based on a location of the first user.

8. The method of claim 5 wherein the first application program comprises an instant messenger program and the second application program comprises an e-mail program.

9. The method of claim 5 wherein the first device is remote from the policy server.

10. The method of claim 5 wherein the policy enforcer program and the plurality of application programs are executing on the first device.

11. A method of managing information comprising:

providing an organization comprising a first group and a second group, wherein the organization has an information management system comprising a policy server comprising one or more rules to manage information of the organization;

within the first group of the organization, providing a first user at a first device and a first e-mail application managed by a policy enforcer program of the information management system;

when the first user sends an e-mail using the e-mail application to a second user, with the policy enforcer program, seeking approval from the policy server further comprising:

determining the e-mail corresponds to an identifier designating the first component of information as confidential includes based on information of the e-mail, determining whether the e-mail is designated confidential;

extracting at least one attribute associated with the e-mail and the identifier; and

based on the at least one attribute, evaluating using the policy server whether to allow access to the e-mail by the second user includes determining whether the first user sending the e-mail corresponds to a specific time period of the organization;

if approved, transmitting the e-mail to the second user; and

if not approved, with the policy enforcer program, blocking the first user from transmitting the e-mail to the second user,

wherein the at least one attribute is used to determine whether to allow access to the first component of information to a user of the information management system and the at least one attribute comprises a location in a file structure.

12. The method of claim 11 wherein the information of the e-mail comprises at least one of a body of the e-mail or a header of the e-mail.

13. The method of claim 11 as for the determining whether the first user sending the e-mail corresponds to a specific time period of the organization, the evaluating using the policy server whether to allow access to the e-mail by the second user includes determining whether the first user sending the e-mail corresponds to a prohibited location.

14. The method of claim 11 wherein the determining the e-mail corresponds to an identifier further comprising analyzing text of a body of the e-mail.

15. The method of claim 11 wherein the determining the e-mail corresponds to an identifier further comprising analyzing text of an attachment of the e-mail.

16. The method of claim 11 wherein the policy enforcer program comprises an e-mail server application.

17. The method of claim 11 wherein the information of the e-mail comprises at least one of a body of the e-mail or a header of the e-mail,

the at least one attribute is used to determine whether to allow access to the first component of information to a user of the information management system and the at least one attribute comprises a location in a file structure, and

for the determining whether the first user sending the e-mail corresponds to a specific time period of the organization, the evaluating using the policy server whether to allow access to the e-mail by the second user includes determining whether the first user sending the e-mail corresponds to a prohibited location.

Assignments (1)
SECURITY AGREEMENT Recorded Jun 30, 2020
From: NEXTLABS, INC
To: ROSEBUD CAPITAL, LLC
Reel/Frame 053095/0330 →
Continuity (12)
Continuation 12987857 · Jan 10, 2011
Continuation 11928794 · Oct 30, 2007
Continuation 11615637 · Dec 22, 2006
Continuation In Part 11383159 · May 12, 2006
Continuation In Part 11383161 · May 12, 2006
Continuation In Part 11383164 · May 12, 2006
Provisional Application 60755019 · Dec 29, 2005
Provisional Application 60776036 · Feb 22, 2006
Provisional Application 60743121 · Jan 11, 2006
Provisional Application 60821050 · Aug 1, 2006
Provisional Application 60870195 · Dec 15, 2006
Related Publication 20140310423A1 · Oct 16, 2014