IP Library Granted Patent US 11,762,981
Granted Patent B2
US 11,762,981 · App. 17/221,910 · Granted Sep 19, 2023

Systems, methods, and apparatus for securing user documents

Inventors: Brian John Cepuran (Oakville, CA); Daryl McMillan (Kitchener, CA); David Robert Lockhart (Waterloo, CA); Dariusz Grabka (Kitchener, CA)
Assignee: D2L Corporation
G06F21/51H04L63/101H04L63/102H04L63/145G06F2221/2119G06F2221/2149
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,762,981
App. No.
17/221,910
Granted
Sep 19, 2023
Kind
B2
Abstract

The invention is directed to systems, methods and apparatus for securing documents. The system comprises a server having a processor and a data storage device for storing documents, at least one document provider connected to the server, the at least one document provider operable to provide user documents to the server for storage in the data storage device, the user documents containing at least one object of security concern, and at least one document consumer connected to the server, the at least one document consumer operable to receive the user documents containing the at least one object of security concern from the server. The processor in the server is operable to determine whether to provide the at least one object of security concern to the at least one document consumer based on at least one security setting, and based on the decision either provide the documents with the at least one object of security concern or provide a replacement documents without the security of concern and an indication on each replacement document that that the at least one object of security concern has been excluded.

Claims (70)

1. A system for securing documents comprising:

a) a server having at least one hardware processor and at least one data storage device for storing documents;

b) at least one document provider connected to the server, the at least one document provider operable to provide at least one user document to the server for storage in the at least one data storage device, the at least one user document containing at least one object of security concern; and

c) at least one document consumer connected to the server, the at least one document consumer operable to receive the at least one user document containing the at least one object of security concern from the server;

d) wherein the at least one hardware processor in the server is operable to:

i) receive at least one centralized security list managed by the server;

ii) provide a screening document such that at least one user of the at least one document consumer is able to provide security preference information to the server;

iii) modify the at least one centralized security list to generate a personalized security list for the at least one user based on the preference information;

iv) store the personalized security list in the at least one storage device and associate the personalized security list with at least one user profile associated with the at least one document consumer;

v) receive a request from the at least one document consumer for the at least one user document;

vi) determine, in response to receiving the request, whether to provide the at least one object of security concern to the at least one document consumer based on at least one security setting, the at least one security setting including consulting the personalized security list to determine if the at least one object of security concern should be provided, and consulting the centralized security list if and only if the personalized security list does not contain information about the object of security concern;

vii) if it is determined that the at least one object of security concern should be provided, provide the at least one user document with the at least one object of security concern to the at least one document consumer, and

viii) if it is determined that the at least one object of security concern should not be provided, then:

(1) generate at least one replacement document containing the at least one user document without the at least one object of security concern and including an indication that the at least one object of security concern has been excluded, and

(2) provide the at least one replacement document to the at least one document consumer.

2. The system according to claim 1 , wherein the at least one centralized list comprises a black list indicative of a list of objects of security concern that should not be provided to the at least one document consumer.

3. The system according to claim 1 , wherein the at least one centralized list comprises a white list indicative of a list of objects of security concern that should be provided to the at least one document consumer.

4. The system according to claim 1 , wherein the at least one centralized list is applicable to all user documents provided by the at least one document provider.

5. The system according to claim 1 , wherein the screening document contains information about the at least one object of security concern such that at least one user of the at least one document consumer is able to use that information to assess security risk associated with the object of security concern.

6. The system according to claim 5 , wherein the information contained in the screening document comprises a non-executable rendering of the object of security concern.

7. The system according to claim 6 , wherein the non-executable rendering of the object of security concern comprises at least one of:

a) an image representation of the object of security concern;

b) if the object of security concern comprises instructions executable by the at least one document consumer, then text of the instructions; and

c) information about the at least one document provider that provided the at least one user document containing the at least one object of security concern.

8. The system according to claim 5 , wherein the screening document further comprises at least one other option for the at least one user to indicate a scope of applicability of the preference information, the scope of applicability being indicative of when the server should apply the preference information provided by the at least one user to determine whether to provide the object of security concern.

9. The system according to claim 8 , wherein the scope of applicability includes at least one of:

a) applicability for a current session;

b) applicability for the at least one document consumer from that point on;

c) applicability for a particular external domain referenced in the at least one user document;

d) applicability for a particular document provider; and

e) applicability for a particular type of object of security concern.

10. The system according to claim 8 , wherein the at least one hardware processor is further operable to:

a) associate the scope of applicability provided by the at least one user with the personalized security list; and

b) store the scope of applicability in the at least one data storage device.

11. The system according to claim 1 , wherein the server manages information relating to the centralized list based on intrinsic information obtained by the at least one hardware processor from the at least one user document provided.

12. The system according to claim 11 , wherein the intrinsic information obtained by the at least one hardware processor from the at least one user document comprises at least one of:

a) a source of the at least one user document;

b) a type of the at least one user document;

c) a type of the at least one object of security concern contained in the at least one user document; and

d) when the at least one object of security concern contains at least one reference to another document, then information about the document that is referenced.

13. The system according to claim 1 , wherein the server centrally manages information relating to the centralized list based on location information indicative of the location in the server to which the at least one user document is provided.

14. The system according to claim 13 , wherein the server centrally manages information relating to the centralized list based on extrinsic information provided by one or more users in response to one or more screening documents.

15. The system according to claim 1 , wherein the at least one object of security concern comprises at least one of:

a) instructions executable by the at least one document consumer in JavaScript language;

b) instructions executable by the at least one document consumer to obtain information from an external domain.

16. A server for securing documents comprising:

a) at least data storage device for storing a plurality of user documents, at least one of the user documents containing at least one object of security concern;

b) at least one network device for connecting to at least one document provider and at least one document consumer, the at least one document provider operable to provide at least one of the user documents to the server, the at least one document consumer operable to receive at least one of the plurality of user documents from the server;

c) at least one hardware processor coupled to the at least one data storage device and the at least one network device, the at least one hardware processor in the server is operable to:

i) receive at least one centralized security list managed by the server;

ii) provide a screening document such that at least one user of the at least one document consumer is able to provide security preference information to the server;

iii) modify the at least one centralized security list to generate a personalized security list for the at least one user based on the preference information;

iv) store the personalized security list in the at least one storage device and associate the personalized security list with at least one user profile associated with the at least one document consumer;

v) receive a request from the at least one document consumer for the at least one user document;

vi) determine, in response to receiving the request, whether to provide the at least one object of security concern in the at least one of the user documents concern to the at least one document consumer based on at least one security setting, the at least one security setting including consulting the personalized security list to determine if the at least one object of security concern should be provided, and consulting the centralized security list if and only if the personalized security list does not contain information about the object of security concern;

vii) if it is determined that the at least one object of security concern should be provided, then provide the at least one user document with the at least one object of security concern to the at least one document consumer, and

viii) if it is determined that the at least one object of security concern should not be provided, then generate at least one replacement document containing the at least one user document without the at least one object of security concern and an indication that the at least one object of security concern has been excluded, and provide the at least one replacement document to the at least one document consumer.

17. A method for securing documents at a server having at least one server processor and at least one data storage device comprising:

a) receiving at least one document from at least one document provider containing at least one object of security concern;

b) storing the at least one document in at least one data storage device;

c) receiving at least one centralized security list managed by the server;

d) providing a screening document such that at least one user of at least one document consumer is able to provide security preference information to the server;

e) modifying the at least one centralized security list to generate a personalized security list for the at least one user based on the preference information;

f) storing the personalized security list in the at least one storage device and associate the personalized security list with at least one user profile associated with the at least one document consumer;

g) receiving a request from the at least one document consumer for the at least one user document;

h) using the at least one server processor to determine whether to provide the at least one object of security concern to the at least one document consumer based on at least one security setting, the at least one security setting including consulting the personalized security list to determine if the at least one object of security concern should be provided, and consulting the centralized security list if and only if the personalized security list does not contain information about the object of security concern;

i) if it is determined that the at least one object of security concern should be provided, then using the at least one server processor to provide the at least one document with the at least one object of security concern to the at least one document consumer; and

j) if it is determined that the at least one object of security concern should not be provided, then using the at least one server processor to generate at least one replacement document containing the at least one document without the at least one object of security concern and further containing an indication that the at least one object of security concern has been excluded, and providing the at least one replacement document to the at least one document consumer.

18. The method according to claim 17 , wherein the at least one centralized list comprising a black list indicative of a list of objects of security concern that should not be provided to the at least one document consumer.

19. The method according to claim 17 , wherein the at least one centralized list comprising a white list indicative of a list of objects of security concern that should be provided to the at least one document consumer.

Assignments (4)
NUNC PRO TUNC ASSIGNMENT Recorded Apr 20, 2023
From: CEPURAN, BRIAN JOHN; MCMILLAN, DARYL; LOCKHART, DAVID ROBERT; GRABKA, DARIUSZ
To: D2L CORPORATION
Reel/Frame 063394/0100 →
CHANGE OF NAME Recorded Apr 20, 2023
From: D2L INCORPORATED
To: D2L CORPORATION
Reel/Frame 063407/0719 →
CHANGE OF NAME Recorded Apr 20, 2023
From: DESIRE2LEARN.COM INCORPORATED
To: DESIRE2LEARN INCORPORATED
Reel/Frame 063407/0722 →
CHANGE OF NAME Recorded Apr 20, 2023
From: DESIRE2LEARN INCORPORATED
To: D2L INCORPORATED
Reel/Frame 063407/0759 →
Continuity (5)
Continuation 16535295 · Aug 8, 2019
Continuation 15148644 · May 6, 2016
Continuation 13156045 · Jun 8, 2011
Provisional Application 61354015 · Jun 11, 2010
Related Publication 20210357495A1 · Nov 18, 2021