IP Library Granted Patent US 9,654,450
Granted Patent B2
US 9,654,450 · App. 15/179,650 · Granted May 16, 2017

Computerized method and system for managing secure content sharing in a networked secure collaborative exchange environment with customer managed keys

Inventors: Christopher Todd Ford (Boston, MA); Wade Callison (Acton, MA); Fahim Siddiqui (Boston, MA); Mushegh Hakhinian (Westwood, MA)
Assignee: Synchronoss Technologies, Inc.
H04L63/0428H04L9/08H04L63/06H04L63/08H04L63/10H04L65/403
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,654,450
App. No.
15/179,650
Granted
May 16, 2017
Kind
B2
Abstract

In embodiments of the present invention, improved capabilities are described for securely sharing computer data content between business entities as managed through an intermediate business entity, where the secure sharing process utilizes encryption provided by the intermediate business entity but where the encryption keys used in the encryption are at least in part managed through one of the business entities as customer managed keys.

Claims (26)

1. A method for managing a networked secure collaborative computer data exchange environment, the method comprising:

establishing, by a secure exchange server managed by an intermediate business entity, a user login data authentication procedure that allows a user through at least one client computing device to access the secure exchange server, wherein the user is one of a plurality of users of a plurality of other business entities and communications between the secure exchange server and the plurality of users are through a communications network;

storing, by the secure exchange server, at least one user login authentication data for at least one of the plurality of users;

receiving and storing at the exchange server an encrypted computer data content from a first of the plurality of users of a first business entity wherein the encrypted computer data content is encrypted using a selected encryption protocol employing encryption keys managed by the first business entity, wherein the first of the plurality of users permits a sharing access to the encrypted computer data content to at least a second of the plurality of users of a second business entity, and wherein management for access to the computer data content is through an exchange content access facility managed by the intermediate business entity, wherein the first business entity manages its own encryption keys for use in encrypting computer data content; and

granting, by the secure exchange server, sharing access to the computer data content to the at least second of the plurality of users when the secure exchange server receives a client login authentication data from the second of the plurality of users.

2. The method of claim 1 , wherein a second of the plurality of other business entities manages their own encryption keys for use in encrypting computer data content provided by the second of the plurality of other business entities.

3. The method of claim 1 , wherein the exchange content access facility managed by the intermediate business entity interfaces with a key management facility of the first business entity to facilitate the sharing access to the encrypted data content by the second of the plurality of users of the second business entity.

4. A method for managing a networked secure collaborative computer data exchange environment, the method comprising:

establishing, by a secure exchange server managed by an intermediate business entity, a user login data authentication procedure that allows a user through at least one client computing device to access the secure exchange server, wherein the user is one of a plurality of users of a plurality of other business entities and communications between the secure exchange server and the plurality of users are through a communications network, wherein at least one of the plurality of other business entities manages its own encryption keys in association with encrypted computer data content provided by the at least one of the plurality of other business entities to the secure exchange server;

storing, by the secure exchange server, at least one user login authentication data for at least one of the plurality of users;

receiving and storing at the exchange server an encrypted computer data content from a first of the plurality of users of a first business entity wherein the encrypted computer data content is encrypted using a selected encryption protocol employing encryption keys managed by the first business entity, wherein the first of the plurality of users permits a sharing access to the encrypted computer data content to at least a second of the plurality of users of a second business entity, and wherein management for access to the computer data content is through an exchange content access facility managed by the intermediate business entity; and

granting, by the secure exchange server, sharing access to the computer data content to the at least second of the plurality of users when the secure exchange server receives from the second of the plurality of users its client login authentication data.

5. The method of claim 4 , wherein a second of the plurality of other business entities manages their own encryption keys in association with encrypted computer data content provided by the second of the plurality of other business entities.

6. The method of claim 4 , wherein the exchange content access facility managed by the intermediate business entity interfaces with a key management facility of the first business entity to facilitate the sharing access to the encrypted data content by the second of the plurality of users of the second business entity.

7. A method for managing a networked secure collaborative computer data exchange environment, the method comprising:

providing a user login data authentication procedure that allows a user through at least one client computing device to access a secure exchange server through an intermediate business entity, wherein the user is one of a plurality of users;

storing in a storage device at least one user login authentication data for at least one of the plurality of users;

by the secure exchange server, receiving and storing encrypted data content from a first user of the plurality of users wherein the encrypted computer data content is encrypted using a selected encryption protocol employing encryption keys managed by the first user, wherein the first user permits a sharing access to the encrypted data content to a subset of the plurality of users, and wherein management for access to the encrypted data content is through an exchange content access facility managed by the intermediate business entity;

by the secure exchange server, granting sharing access to the encrypted data content to at least a second user of the plurality of users when the second user client login authentication data is one of the subset of data for the plurality of users to which sharing access is permitted;

by the secure exchange server, receiving a copy access request from the second user to access a copy of the encrypted data content;

granting, by the secure exchange server in response to the copy access request, copy access to the second user;

by the secure exchange server, receiving from the first user a request to revoke sharing and copy access to the encrypted data content to the second user; and

by the secure exchange server, revoking sharing access to the encrypted data content and copy access to the copy of the encrypted data content by the second user, wherein revoking copy access to the copy of the encrypted data content is a change in the digital rights management of the encrypted data content, and wherein access to the encrypted data content is revocable at any time at the request of the first user.

8. The method of claim 7 , further comprising additional sharing of the encrypted data content with others of the plurality of users, wherein the revoking of sharing access and copy access revokes access to all instances of the shared encryption data content and all copies of the encrypted data content made by any of the others of the plurality of users.

9. The method of claim 7 , wherein the copy of the encrypted data content is deleted from the client computing device.

10. The method of claim 7 , wherein revoking sharing access to the copy of the encrypted data content makes the copy of the encrypted data content inaccessible to the second user.

Assignments (9)
SECURITY INTEREST Recorded Nov 16, 2018
From: INTRALINKS, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 047526/0542 →
CORRECTIVE ASSIGNMENT TO CORRECT THE PATENT NUMBER 9396455 PREVIOUSLY RECORDED ON REEL 044277 FRAME 842. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded May 3, 2018
From: SYNCHRONOSS TECHNOLOGIES, INC.
To: INTRALINKS, INC.
Reel/Frame 046060/0738 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 1, 2017
From: SYNCHRONOSS TECHNOLOGIES, INC.
To: INTRALINKS, INC
Reel/Frame 044277/0842 →
CORRECTIVE ASSIGNMENT TO CORRECT THE CONVEYING PARTY NAME PREVIOUSLY RECORDED ON REEL 044123 FRAME 0110. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST. Recorded Nov 30, 2017
From: GOLDMAN SACHS BANK USA
To: INTRALINKS, INC.
Reel/Frame 044566/0919 →
RELEASE OF SECURITY INTEREST Recorded Nov 14, 2017
From: GOIDMAN SACHS BANK USA
To: INTRALINKS, INC.
Reel/Frame 044123/0110 →
MERGER Recorded Apr 7, 2017
From: INTRALINKS, INC
To: SYNCHRONOSS TECHNOLOGIES, INC.
Reel/Frame 042195/0733 →
SECURITY INTEREST Recorded Jan 23, 2017
From: INTRALINKS, INC., AS GRANTOR
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 041046/0919 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 23, 2016
From: FORD, CHRISTOPHER; CALLISON, WADE; SIDDIQUI, FAHIM
To: INTRALINKS, INC.
Reel/Frame 039000/0524 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 23, 2016
From: HAKHINIAN, MUSHEGH
To: INTRALINKS, INC.
Reel/Frame 039000/0580 →
Continuity (10)
Continuation 14689594 · Apr 17, 2015
Continuation 13960324 · Aug 6, 2013
Continuation In Part 13871593 · Apr 26, 2013
Provisional Application 61680115 · Aug 6, 2012
Provisional Application 61702587 · Sep 18, 2012
Provisional Application 61715989 · Oct 19, 2012
Provisional Application 61734890 · Dec 7, 2012
Provisional Application 61783868 · Mar 14, 2013
Provisional Application 61639576 · Apr 27, 2012
Related Publication 20160285838A1 · Sep 29, 2016