IP Library Granted Patent US 10,164,980
Granted Patent B1
US 10,164,980 · App. 15/164,188 · Granted Dec 25, 2018

Method and apparatus for sharing data from a secured environment

Inventors: Yuri Berfeld (Ottawa, CA); Luis Miguel Huapaya (Gloucester, CA)
Assignee: EMC IP HOlding Company LLC
H04L63/10G06F21/602H04L63/0428H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,164,980
App. No.
15/164,188
Filed
May 25, 2016
Granted
Dec 25, 2018
Kind
B1
Examiner
HO, THOMAS
Art Unit
2494
USPC
713/166
Abstract

A method for sharing data from within a secure network perimeter includes providing a sharing folder associated with a first user for transferring data therefrom to destinations outside the secure perimeter. Data stored within the sharing folder is stored in a secured fashion. Semi-trusted applications are provided an ability to retrieve the secured data in a unsecured fashion for sharing of same. The semi-trusted applications are other than able to retrieve and share secured data from at least a folder other than the sharing folder in unsecured form.

Claims (33)

1. A method comprising:

providing a security layer for maintaining security within a security perimeter;

providing a first set of folders having first secured data stored therein;

providing a sharing folder having second secured data stored therein;

providing a trusted application for accessing the stored first secured data from within the first set of folders, the stored first secured data stored in a ciphered form and deciphered by the security layer when accessed by the trusted application;

providing a semi-trusted application for accessing the second secured data from within the sharing folder, the second secured data stored in a ciphered form and deciphered by the security layer when accessed by the semi-trusted application, wherein the semi-trusted application is for sharing the deciphered second secured data with a destination outside the security perimeter and wherein the semi-trusted application is not authorized to access stored secured data deciphered by the security layer from within the first set of folders;

accessing a first data file by the trusted application, the first data file forming at least a portion of the stored first secured data stored within the first set of folders;

using the trusted application, storing a second data file within the sharing folder, the second data file based on the first data file and forming at least a portion of the second secured data stored within the sharing folder;

accessing the second data file by the semi-trusted application, wherein the security layer deciphers the second data file when accessed by the semi-trusted application; and

using the semi-trusted application, sharing the deciphered second data file outside the security perimeter.

2. The method as defined in claim 1 wherein the first secured data comprises stored ciphered data secured with a cipher key.

3. The method as defined in claim 2 wherein the semi-trusted application is provided access to deciphered data from a ciphered data file by the security layer when the cipher data file is stored within the sharing folder and is other than provided access to a deciphered version of an exact same data file as the ciphered data file by the security layer when the exact same data is stored outside the sharing folder.

4. The method as defined in claim 3 wherein the security layer acts to decipher data for the trusted application and to only decipher data for the semi-trusted application when that data is stored within the sharing folder.

5. The method as defined in claim 1 wherein the security perimeter is a virtual security perimeter defining a virtual communication network having data secured therein.

6. The method as defined in claim 1 comprising:

generating a log entry upon storing of the second data file within the sharing folder by the trusted application.

7. A method according to claim 1 wherein storing the second data file within the sharing folder by the trusted application comprises:

requesting user authorization data,

verifying the user authorization data, and

in response to verifying the user authorization data, authorizing the storing operation.

8. A method comprising:

providing a security layer for maintaining security within a security perimeter;

providing a set of folders having secured data stored therein;

providing a trusted application for accessing stored secured data from within the set of folders, the stored secured data stored in a ciphered form and deciphered by the security layer when accessed by the trusted application and re-secured when stored by the trusted application, the security layer configured to not cipher data stored by the trusted application in a first predetermined file type;

providing a non-trusted application for accessing data stored in plain text and not for accessing data deciphered by the security layer;

accessing a first data file by the trusted application, the first data file forming at least a portion of the stored secured data and being a second predetermined file type, wherein the first predetermined data type is not the same as the second predetermined data type; and

using the trusted application, storing a second data file of the first predetermined file type, the second data file based on the first data file,

the security layer for securing the first data file when saved and for other than securing the second data file.

9. The method as defined in claim 8 comprising accessing the second data file by the non-trusted application.

10. The method as defined in claim 8 comprising verifying the storing of the second data file of the first predetermined file type against policy data to determine an authorization result, and in response to determining that the storing should not be authorized, preventing the storing of the second data file.

11. The method as defined in claim 10 wherein verifying comprises analyzing a content of the second data file against an expected content of the second data file.

12. The method as defined in claim 8 comprising, in response to storing the second data file of the first predetermined file type, generating a log entry.

13. The method as defined in claim 8 wherein the first predetermined file type is an exception defined by the security layer.

Assignments (12)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2016
From: EMC CORPORATION
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 040203/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 1, 2016
From: BERFELD, YURI; HUAPAYA, LUIS MIGUEL
To: AFORE SOLUTIONS INC.
Reel/Frame 039611/0536 →
CHANGE OF NAME Recorded Sep 1, 2016
From: AFORE SOLUTIONS INC.
To: CLOUDLINK TECHNOLOGIES INC.
Reel/Frame 039892/0544 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 1, 2016
From: CLOUDLINK TECHNOLOGIES INC.
To: EMC CORPORATION
Reel/Frame 039611/0979 →
Continuity (2)
Continuation 14071254 · Nov 4, 2013
Provisional Application 61721802 · Nov 2, 2012
Cited By (1)
US 12,254,116