IP Library Granted Patent US 12,003,623
Granted Patent B2
US 12,003,623 · App. 17/126,070 · Granted Jun 4, 2024

Multilayer encryption for user privacy compliance and corporate confidentiality

Inventors: Charles D. Robison (Buford, GA); Nicholas D. Grobelny (Austin, TX); Ricardo L. Martinez (Leander, TX)
Assignee: Dell Products, L.P.
H04L9/0852G06F9/45558H04L9/14G06F2009/45587
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,003,623
App. No.
17/126,070
Granted
Jun 4, 2024
Kind
B2
Abstract

Systems and methods for multilayer encryption for user privacy compliance and corporate confidentiality are described. In some embodiments, an Information Handling System (IHS) may include a processor and a memory coupled to the processor, the memory having program instructions stored thereon that, upon execution, cause the IHS to: transmit, from a workspace instantiated by a local management agent to a portal managed by an enterprise: (i) a request to store a once-encrypted document, and (ii) an indication that the once-encrypted document is encrypted with a controlvault key; receive, from the portal at the workspace, a request to encrypt the once-encrypted document with an enterprise-issued cryptographic key to produce a twice-encrypted document; and transmit, from the workspace to the portal, a copy of the twice-encrypted document.

Claims (38)

1. An Information Handling System (IHS), comprising:

a processor; and

a memory coupled to the processor, the memory having program instructions stored thereon that, upon execution, cause the IHS to:

transmit, from a workspace instantiated by a local management agent to a portal managed by an enterprise: (i) a request to store a once-encrypted document, and (ii) an indication that the once-encrypted document is encrypted with a controlvault key;

receive, from the portal at the workspace, a request to encrypt the once-encrypted document with an enterprise-issued cryptographic key to produce a twice-encrypted document;

encrypt, by the workspace, the once-encrypted document with the enterprise-issued cryptographic key to produce the twice-encrypted document; and

transmit, from the workspace to the portal, a copy of the twice-encrypted document.

2. The IHS of claim 1 , wherein the workspace is instantiated by a local management agent based upon a workspace definition received from a workspace orchestration service.

3. The IHS of claim 2 , wherein the workspace orchestration service is part of, or accessible to the IHS through, the portal.

4. The IHS of claim 2 , wherein the workspace definition comprises at least one of: a threat monitoring level, a threat detection level, a threat analytics level, a threat response level, a storage confidentiality level, a network confidentiality level, a memory confidentiality level, a display confidentiality level, a user authentication level, an Information Technology (IT) administration level, a regulatory compliance level, a local storage control level, a Central Processing Unit (CPU) access level, a graphics access level, an application usage level, or an application installation level.

5. The IHS of claim 2 , wherein the workspace definition comprises a security policy that indicates two-level encryption for a selected one or more of a plurality of different types of document, and wherein the document is of the selected one or more types.

6. The IHS of claim 1 , wherein the encryption with the controlvault key uses a first type of cryptographic algorithm, and wherein the encryption with the enterprise-issued cryptographic key uses a second type of cryptographic algorithm.

7. The IHS of claim 6 , wherein the first cryptographic algorithm is an Advanced Encryption Standard (AES) algorithm, and wherein the second cryptographic algorithm is a lattice-based, quantum computing resistant algorithm.

8. The IHS of claim 1 , wherein the program instructions, upon execution, further cause the IHS to:

receive a wake message from the portal; and

in response to the wake message, provide a copy of the controlvault key to the portal, wherein the wake message is transmitted by the portal to the IHS in response to a request for document access received during a web session.

9. A memory storage device having program instructions stored thereon that, upon execution by an Information Handling System (IHS), cause the IHS to:

receive, from a workspace instantiated by a local management agent executed by a client device: (i) a request to store a once-encrypted document, and (ii) an indication that the once-encrypted document is encrypted with a controlvault key;

transmit, to the workspace, a request to encrypt the once-encrypted document with an enterprise-issued cryptographic key to produce a twice-encrypted document; and

receive, from the workspace, a copy of the twice-encrypted document, wherein the workspace encrypted the once-encrypted document with the enterprise-issued cryptographic key to produce the twice-encrypted document.

10. The memory storage device of claim 9 , wherein the workspace is instantiated by a local management agent based upon a workspace definition received from a workspace orchestration service.

11. The memory storage device of claim 10 , wherein the workspace definition comprises at least one of: a threat monitoring level, a threat detection level, a threat analytics level, a threat response level, a storage confidentiality level, a network confidentiality level, a memory confidentiality level, a display confidentiality level, a user authentication level, an Information Technology (IT) administration level, a regulatory compliance level, a local storage control level, a Central Processing Unit (CPU) access level, a graphics access level, an application usage level, or an application installation level.

12. The memory storage device of claim 10 , wherein the workspace definition comprises a security policy that indicates two-level encryption for a selected one or more of a plurality of different types of document, and wherein the document is of the selected one or more types.

13. The memory storage device of claim 9 , wherein the encryption with the controlvault key uses a first type of cryptographic algorithm, and wherein the encryption with the enterprise-issued cryptographic key uses a second type of cryptographic algorithm.

14. The memory storage device of claim 13 , wherein the first cryptographic algorithm is an Advanced Encryption Standard (AES) algorithm, and wherein the second cryptographic algorithm is a lattice-based, quantum computing resistant algorithm.

15. The memory storage device of claim 9 , wherein the program instructions, upon execution, further cause the IHS to:

receive a request for access from a web server;

in response to the request, retrieve a copy of the controlvault key from the client device; and

provide the copy of the controlvault key, a copy of the enterprise-issued cryptographic key, and a copy of the twice-encrypted document to the web server.

16. The memory storage device of claim 15 , wherein the program instructions, upon execution, further cause the IHS to send a wake event to out-of-band agent of the client device in response to the request.

17. The memory storage device of claim 15 , wherein the program instructions, upon execution, further cause the IHS to, prior to transmitting the copy of the twice-encrypted document to the web server, encrypt the twice-encrypted document with a session key.

18. A method, comprising:

receiving a request to access a twice-encrypted document via a web server;

retrieving a copy of a controlvault key of a client device;

encrypting the twice-encrypted document with a session key; and

transmitting, to the web server, a copy of the controlvault key used by a workspace instantiated by a local management agent to perform a first level of encryption of the twice-encrypted document, a copy of an enterprise-issued cryptographic key used by the workspace to perform a second level of encryption of the twice-encrypted document, and a copy of the twice-encrypted document further encrypted with the session key,

wherein the first level of encryption with the controlvault key uses a first type of cryptographic algorithm, and wherein the second level of encryption with the enterprise-issued cryptographic key uses a second type of cryptographic algorithm.

19. The method of claim 18 , wherein the encryption with the controlvault key uses an Advanced Encryption Standard (AES) algorithm, and wherein the encryption with the enterprise-issued cryptographic key uses a lattice-based, quantum computing resistant algorithm.

Assignments (9)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (055479/0342) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 062021/0460 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (055479/0051) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 062021/0663 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (056136/0752) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 062021/0771 →
RELEASE OF SECURITY INTEREST AT REEL 055408 FRAME 0697 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 058001/0553 →
SECURITY INTEREST Recorded Mar 3, 2021
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 056136/0752 →
SECURITY INTEREST Recorded Mar 3, 2021
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 055479/0051 →
SECURITY INTEREST Recorded Mar 3, 2021
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 055479/0342 →
SECURITY AGREEMENT Recorded Feb 25, 2021
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 055408/0697 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 18, 2020
From: ROBISON, CHARLES D.; GROBELNY, NICHOLAS D.; MARTINEZ, RICARDO L.
To: DELL PRODUCTS, L.P.
Reel/Frame 054688/0425 →
Continuity (1)
Related Publication 20220200796A1 · Jun 23, 2022