IP Library Granted Patent US 10,033,702
Granted Patent B2
US 10,033,702 · App. 14/975,728 · Granted Jul 24, 2018

Systems and methods of secure data exchange

Inventors: Christopher Todd Ford (Boston, MA); Mayank Choudhary (Shrewsbury, MA); Kevin L. McCarthy (Arlington, MA); Anupam Miharia (Winchester, MA); John William Giudice (Lexington, MA); Kiran Kumar Tadakamalla (Wakefield, MA); Cole Parker Mercer (Portland, OR); Peter Wenzel (Pasadena, CA); Paul Teamen (Seattle, WA); Clement Cazalot (Boston, MA); Salil J. Darji (Quincy, MA); Jonathan Gorin (Forest Hills, NY)
Assignee: Intralinks, Inc.
H04L63/0421G06F17/30864H04L63/083H04W12/06H04L63/102H04L2463/082H04W12/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,033,702
App. No.
14/975,728
Granted
Jul 24, 2018
Kind
B2
Abstract

In embodiments of the present invention, improved secure exchange system features include a federated search facility, hybrid encryption management (adjustable encryption key management), anonymous IRM, disassembled storage of data as chunks rather than files, asynchronous notification process/integrated file upload and messaging, an identity facility, multi-factor authentication, dynamic access authorization, and various enhancements to a customizable exchange system.

Claims (43)

1. A method comprising:

establishing, by a secure exchange server hosted by an intermediate business entity, a user login data authentication procedure that allows each of a plurality of users through at least one corresponding client computing device to access the secure exchange server, wherein communications between the secure exchange server and each of the plurality of users is through a communications network, wherein the plurality of users comprises a user of a second business entity and at least one anonymous user;

storing, by the secure exchange server, data relating to a user login authentication for the user of a second business entity;

receiving computer data content from the user of the second business entity;

receiving from the user of the second business entity an indication of permission for the at least one anonymous user to access the computer data content through an anonymous information rights management (IRM) facility hosted by the intermediate business entity, wherein the anonymous IRM facility limits the retention of information about the at least one anonymous user, and wherein the indication of permission comprises at least one anonymous access condition;

receiving a request to access the computer data content by the at least one anonymous user; and

granting, by the secure exchange server, access to the computer data content, through the anonymous IRM facility, to the at least one anonymous user, wherein retention of information about the at least one anonymous user is limited and the access is granted based on the at least one anonymous access condition.

2. The method of claim 1 , wherein the at least one anonymous access condition is that the at least one anonymous user is a user of a third business entity, wherein the third business entity is specified by the user of the second business entity in the indication of permission.

3. The method of claim 2 , wherein the user of the second business entity is provided access to information comprising the identity of the third business entity but not the identity of the at least one anonymous user.

4. The method of claim 1 , wherein the at least one anonymous access condition is that the at least one anonymous user is a user of a computer domain specified by the user of the second business entity in the indication of permission.

5. The method of claim 1 , wherein the at least one anonymous access condition is that the at least one anonymous user is a user of a geographic region specified by the user of the second business entity in the indication of permission.

6. The method of claim 1 , further comprising collecting metadata, by the anonymous IRM facility, relating to access of the computer data content.

7. The method of claim 6 , wherein the metadata is at least one of a domain from which the computer data content was accessed and a location from which the computer data content was accessed.

8. The method of claim 6 , wherein the metadata comprises data regarding where the computer data content was shared after the computer data content was accessed.

9. The method of claim 6 , wherein the metadata comprises data regarding when the computer data content was accessed.

10. A method comprising:

establishing, by a secure exchange server hosted by an intermediate business entity, a user login data authentication procedure that allows one or more users, including a user of a second business entity, through at least one client computing device to access the secure exchange server, wherein communications between the secure exchange server and each of the one or more users is through a communications network;

providing, by the secure exchange server, an encryption management facility, wherein the encryption management facility is adapted to adjustably configure encryption services based on a selection criteria provided by the user of the second business entity for selection of at least one of:

i. secure exchange server side encryption, wherein computer data content is transmitted from the second business entity to the secure exchange server to be encrypted by the secure exchange server, and

ii. business entity side encryption, wherein computer data content is transmitted from the second business entity to the secure exchange server as encrypted data that was encrypted by the second business entity before it was transmitted;

receiving a selection criteria from the user of the second business entity, wherein the selection criteria establishes the selection of at least one of secure exchange server side encryption and business entity side encryption for a computer data content to be stored on the secure exchange server; and

receiving computer data content from the user of the second business entity, wherein the computer data content is encrypted by the selected mode of encryption based on the received selection criteria.

11. A method comprising:

establishing, by a secure exchange server hosted by an intermediate business entity, a user login data authentication procedure that allows one or more users through at least one client computing device to access the secure exchange server, wherein communications between the secure exchange server and each of the one or more users is through a communications network, wherein the one or more users comprises a user of a second business entity;

providing, by the secure exchange server, a data chunking facility adapted to receive and segment a computer data content transmitted from a client computing device of the one or more users, wherein the received computer data content is stored as a plurality of encrypted computer data content segments;

receiving computer data content from the user of the second business entity, wherein the received computer data content is segmented and each computer data content segment is separately encrypted to form a plurality of encrypted computer data content segments; and

storing, by the secure exchange server, the plurality of encrypted computer data content segments.

12. A method comprising:

establishing, by a secure exchange server hosted by an intermediate business entity, a user login data authentication procedure that allows one or more users through at least one client computing device to access the secure exchange server, wherein communications between the secure exchange server and each of the one or more users is through a communications network, wherein the one or more users comprises a user of a second business entity communicating with the secure exchange server through a second computing device;

providing, by the secure exchange server, an asynchronous notification upload messaging facility adapted to:

i. receive and process computer data content and a computer message transmitted together as a data message composite content from a client computing device of the one or more users, wherein the computer message comprises a data processing preference, and

ii. asynchronously communicate to the client computing device of the one or more users a processing notification related to the processing of the data message composite content;

receiving a data message composite upload from the second computing device comprising computer data content and a computer message comprising a data processing preference;

processing, by the secure exchange server, the received data message composite upload based on the data processing preference; and

notifying, by the secure exchange server, the second computing device of a processing state of the received data message composite upload, wherein the notification is provided asynchronously to the processing of the data messaging composite upload.

13. A method comprising:

establishing, by a secure exchange server hosted by an intermediate business entity, a user login data authentication procedure that allows each of a plurality of users, including a user of a second business entity and a user of a third business entity, through at least one corresponding client computing device, to access the secure exchange server, wherein communications between the secure exchange server and each of the plurality of users is through a communications network;

storing, by the secure exchange server, data relating to a user login authentication for the user of a second business entity and data relating to a user login authentication for the user of the third business entity;

receiving computer data content from the user of the third business entity;

receiving from the user of the third business entity an indication of permission for the user of the second business entity to access the received computer data content;

receiving a request to access the computer data content by the user of the second business entity;

by the secure exchange server, determining a level of access authentication for access to the received computer data content for the user of the second business entity based on an event condition related to a current state of the client computing device of the user of the second business entity at the time of the access request; and

by the secure exchange server, adjusting a level of access authentication based on the event condition, presenting the user of the second business entity the adjusted level of access authentication, and granting access to the received computer data content when the secure exchange server receives the adjusted level of access authentication.

Assignments (12)
RELEASE OF 1ST LIEN SECURITY INTEREST Recorded Nov 16, 2018
From: ROYAL BANK OF CANADA
To: INTRALINKS, INC.
Reel/Frame 047587/0828 →
RELEASE OF 2ND LIEN SECURITY INTEREST Recorded Nov 16, 2018
From: ROYAL BANK OF CANADA
To: INTRALINKS, INC.
Reel/Frame 047587/0836 →
SECURITY INTEREST Recorded Nov 16, 2018
From: INTRALINKS, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 047526/0542 →
CORRECTIVE ASSIGNMENT TO CORRECT THE CONVEYING PARTY NAME PREVIOUSLY RECORDED ON REEL 044123 FRAME 0110. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST. Recorded Nov 30, 2017
From: GOLDMAN SACHS BANK USA
To: INTRALINKS, INC.
Reel/Frame 044566/0919 →
SECOND LIEN SECURITY AGREEMENT Recorded Nov 16, 2017
From: INTRALINKS, INC.
To: ROYAL BANK OF CANADA, AS COLLATERAL AGENT
Reel/Frame 044477/0445 →
FIRST LIEN SECURITY AGREEMENT Recorded Nov 15, 2017
From: INTRALINKS, INC.
To: ROYAL BANK OF CANADA, AS COLLATERAL AGENT
Reel/Frame 044455/0479 →
RELEASE OF SECURITY INTEREST Recorded Nov 14, 2017
From: GOIDMAN SACHS BANK USA
To: INTRALINKS, INC.
Reel/Frame 044123/0110 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 21, 2017
From: TEARNEN, PAUL; WENZEL, PETER
To: ALVAREZ & MARSAL BUSINESS CONSULTING, LLC
Reel/Frame 041656/0719 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 21, 2017
From: ALVAREZ & MARSAL BUSINESS CONSULTING, LLC
To: INTRALINKS, INC.
Reel/Frame 041656/0791 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 21, 2017
From: BARTON, DAVID C.; WELCH, DONALD JAMES; MERCER, COLE PARKER; BARTON LABORATORIES, LLC
To: INTRALINKS, INC.
Reel/Frame 041657/0390 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 21, 2017
From: FORD, CHRISTOPHER TODD; CHOUDHARY, MAYANK; MCCARTHY, KEVIN L.; MIHARIA, ANUPAM; GIUDICE, JOHN WILLIAM; TADAKAMALLA, KIRAN KUMAR; CAZALOT, CLEMENT; DARJI, SALIL J.; GORIN, JONATHAN
To: INTRALINKS, INC.
Reel/Frame 042099/0852 →
SECURITY INTEREST Recorded Jan 23, 2017
From: INTRALINKS, INC., AS GRANTOR
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 041046/0919 →
Continuity (4)
Provisional Application 62201420 · Aug 5, 2015
Provisional Application 62202494 · Aug 7, 2015
Provisional Application 62206987 · Aug 19, 2015
Related Publication 20170041296A1 · Feb 9, 2017
Cited By (33)
US 12,197,616 US 12,216,660 US 12,238,101 US 12,242,504 US 12,272,448 US 12,292,991 US 12,298,877 US 12,299,185 US 12,301,529 US 12,321,894 US 12,321,895 US 12,326,966 US 12,333,497 US 12,412,152 US 12,417,434 US 12,430,614 US 12,435,546 US 12,481,796 US 12,489,806 US 12,512,963 US 12,541,728 US 12,548,087 US 12,574,387 US 12,579,573 US 12,586,044 US 12,598,166 US 12,608,732 US 12,664,595 US 12,705,662 US 12,712,723 US 12,718,258 US 12,719,670 US 12,719,821