IP Library Granted Patent US 11,184,159
Granted Patent B1
US 11,184,159 · App. 17/008,931 · Granted Nov 23, 2021

Encryption key management for channels with multiple organizations

Inventors: Audrei Drummond (Brooklyn, NY); Michael Demmer (San Francisco, CA); Sri Vasamsetti (San Francisco, CA); Elizabeth Clemenson (San Francisco, CA)
Assignee: Slack Technologies, Inc.
H04L9/0827H04L9/083H04L9/0891H04L9/14H04L63/0428
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,184,159
App. No.
17/008,931
Granted
Nov 23, 2021
Kind
B1
Abstract

Media, system, and method for providing encryption key management to a channel within a group-based communication system. The contents of the channel is encrypted according to the encryption key management policy of the organization to which the author of the content belongs and is stored in a data store. Responsive to a revocation request from a first organization, the encryption keys associated with any content in the channel submitted by the authors of said first organization may be revoked from a second organization, such that users of the second organization no longer have access to the content.

Claims (74)

1. One or more non-transitory computer-readable media storing computer-executable instructions that, when executed by a processor, perform a method for providing encryption key management to a channel within a group-based communication system, the method comprising the steps of:

receiving a first message from a first user belonging to the channel in the group-based communication system,

wherein the first user belongs to a first organization;

displaying the first message in the channel,

wherein the channel is a group-based communication channel providing a communications environment to display communications posted by channel members of the group-based communication channel,

wherein displaying the first message in the channel includes:

encrypting the first message with a first encryption key specific to the first organization according to a first encryption policy of the first organization;

storing the encrypted first message in a data store associated with the channel;

retrieving the encrypted first message from the data store associated with the channel; and

decrypting the encrypted first message and displaying the decrypted first message within the channel on a graphical user interface associated with the group-based communication system;

receiving a second message from a second user belonging to the channel in the group-based communication system,

wherein the second user belongs to a second organization different from the first organization; and

displaying the second message in the channel,

wherein displaying the second message in the channel includes:

encrypting the second message with a second encryption key specific to the second organization that is different from the first encryption key according to a second encryption policy of the second organization; and

storing the second encrypted message in the data store associated with the channel.

2. The media of claim 1 , wherein the method further comprises the steps of:

receiving an override request from an administrator of the first organization; and

upon receiving the override request, re-encrypting the second message with the first encryption key according to the first encryption policy of the first organization.

3. The media of claim 1 , wherein the first encryption key is periodically rotated with a new encryption key according to the first encryption policy of the first organization.

4. The media of claim 1 , wherein the second encryption policy of the second organization comprises no encryption.

5. The media of claim 1 , wherein system generated content within the channel is not encrypted.

6. The media of claim 1 , wherein a reaction to the first message is not encrypted.

7. The media of claim 1 , wherein the channel includes a third user of a third organization, and wherein a third message received from the third user is encrypted with a third encryption key according to a third encryption policy of the third organization.

8. A method for providing encryption key management to a channel within a group-based communication system, the method comprising the steps of:

receiving a first message from a first user belonging to the channel in the group-based communication system,

wherein the first user belongs to a first organization;

displaying the first message in the channel,

wherein the channel is a group-based communication channel providing a communications environment to display communications posted by channel members of the group-based communication channel,

wherein displaying the first message in the channel includes:

encrypting the first message with a first encryption key specific to the first organization according to a first encryption policy of the first organization;

storing the encrypted first message in a data store associated with the channel;

retrieving the encrypted first message from the data store associated with the channel; and

decrypting the encrypted first message and displaying the decrypted first message within the channel on a graphical user interface associated with the group-based communication system;

receiving a second message from a second user belonging to the channel in the group-based communication system,

wherein the second user belongs to a second organization different from the first organization; and

displaying the second message in the channel,

wherein displaying the second message in the channel includes:

encrypting the second message with a second encryption key specific to the second organization that is different from the first encryption key according to a second encryption policy of the second organization; and

storing the second encrypted message in the data store associated with the channel.

9. The method of claim 8 , further comprising the steps of:

receiving an override request from an administrator of the first organization; and

upon receiving the override request, re-encrypting the second message with the first encryption key according to the first encryption policy of the first organization.

10. The method of claim 8 , wherein the first encryption key is periodically rotated with a new encryption key according to the first encryption policy of the first organization.

11. The method of claim 8 , wherein the second encryption policy of the second organization comprises no encryption.

12. The method of claim 8 , wherein system generated content within the channel is not encrypted.

13. The method of claim 8 , wherein a reaction to the first message is not encrypted.

14. The method of claim 8 , wherein the channel includes a third user of a third organization, and wherein a third message received from the third user is encrypted with a third encryption key according to a third encryption policy of the third organization.

15. A system for providing encryption key management to a channel within a group-based communication system, the system comprising:

a data store;

a key server; and

a processor programmed to perform a method for providing encryption key management to a channel within a group-based communication system, the method comprising the steps of:

receiving a first message from a first user belonging to the channel in the group-based communication system,

wherein the first user belongs to a first organization;

displaying the first message in the channel,

wherein the channel is a group-based communication channel providing a communications environment to display communications posted by channel members of the group-based communication channel,

wherein displaying the first message in the channel includes:

encrypting the first message with a first encryption key, received from the key server, specific to the first organization according to a first encryption policy of the first organization;

storing the encrypted first message in the data store;

retrieving the encrypted first message from the data store associated with the channel; and

decrypting the encrypted first message and displaying the decrypted first message within the channel on a graphical user interface associated with the group-based communication system;

receiving a second message from a second user belonging to the channel in the group-based communication system,

wherein the second user belongs to a second organization different from the first organization; and

displaying the second message in the channel,

wherein displaying the second message in the channel includes:

encrypting the second message with a second encryption key that is different from the first encryption key, received from the key server, specific to the second organization according to a second encryption policy of the second organization; and

storing the second encrypted message in the data store.

16. The system of claim 15 , wherein the method further comprises the steps of:

receiving an override request from an administrator of the first organization; and

upon receiving the override request, re-encrypting the second message with the first encryption key according to the first encryption policy of the first organization.

17. The system of claim 15 , wherein the first encryption key is periodically rotated with a new encryption key according to the first encryption policy of the first organization.

18. The system of claim 15 , wherein the second encryption policy of the second organization comprises no encryption.

19. The system of claim 15 , wherein system generated content within the channel is not encrypted, and wherein a reaction to the first message is not encrypted.

20. The system of claim 15 , wherein the channel includes a third user of a third organization, and wherein a third message received from the third user is encrypted with a third encryption key according to a third encryption policy of the third organization.

Assignments (4)
MERGER Recorded Jan 11, 2023
From: SLACK TECHNOLOGIES, LLC
To: SALESFORCE.COM, INC.
Reel/Frame 062354/0073 →
CHANGE OF NAME Recorded Jan 11, 2023
From: SALESFORCE.COM, INC.
To: SALESFORCE, INC.
Reel/Frame 062354/0100 →
MERGER AND CHANGE OF NAME Recorded Oct 1, 2021
From: SLACK TECHNOLOGIES, INC.; SLACK TECHNOLOGIES, LLC
To: SLACK TECHNOLOGIES, LLC
Reel/Frame 057683/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 1, 2020
From: DRUMMOND, AUDREI; DEMMER, MICHAEL; VASAMSETTI, SRI; CLEMENSON, ELIZABETH
To: SLACK TECHNOLOGIES, INC.
Reel/Frame 053657/0248 →