IP Library Granted Patent US 12,212,593
Granted Patent B2
US 12,212,593 · App. 17/376,110 · Granted Jan 28, 2025

Acquiring electronic-based signatures

Inventors: Seth Morgan Luce Voltz (San Francisco, CA); Jón Tómas Grétarsson (Redwood City, CA)
Assignee: Box, Inc.
H04L63/1433H04L9/3247
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,212,593
App. No.
17/376,110
Filed
Jul 14, 2021
Granted
Jan 28, 2025
Kind
B2
Art Unit
2495
USPC
726/25
Abstract

Securely acquiring and managing electronic-based signatures by a content management system. A content management system exposes content objects to a plurality of collaborators. Executable modules of the content management system implement an Internet-based interface that is configured to acquire electronic-based signatures from a user device. A particular user device is configured to access particular content objects over the Internet-based interface and to acquire an electronic-based signature corresponding to one or more of the particular content objects. When one or more conditions are detected that would at least potentially influence how the acquisition of the electronic-based signature is carried out, then one or more remediation actions are invoked. Various security-specific remediation actions address corresponding security vulnerabilities. Various document-specific remediation actions are determined based on the document conditions that had been detected. In some cases, a plurality of remediation actions are carried out to securely acquire electronic-based signatures from a user device.

Claims (80)

1. A method for securely acquiring and managing electronic-based signatures by a content management system, the method comprising:

identifying an executable module from a content management system that hosts and exposes a content object to a plurality of collaborators for collaboration, wherein

the collaboration comprises collaboratively modifying the content object or metadata pertaining to the content object by at least some of the plurality of collaborators in a collaboration event hosted on the content management system, and

the executable module implements an Internet-based interface that is used to acquire an electronic-based signature for the content object, using a user device connected to an electronic signature system or subsystem;

determining a document processing result pertaining to a request from the user device to access the content object over the Internet-based interface;

when the document processing result is determined to arise out of the electronic signature system or subsystem,

performing, by the content management system, an action on the content object to remediate the document processing result based at least in part upon a multi-stage check that is performed on the content object or the collaboration event, wherein

the document processing result arising out of the electronic signature system or subsystem indicates a first vulnerability or risk and pertains to acquiring the electronic-based signature on the electronic signature system or subsystem; and

when the document processing result is determined to arise out of the content management system,

determining and sending an instruction from the content management system to the electronic signature system or subsystem, wherein

execution of the instruction on the electronic signature system or subsystem remediates the document processing result, and the document processing result arising out of the content management system indicates a second vulnerability or risk in acquiring the electronic-based signature on the electronic signature system or subsystem; and

triggering the electronic-signature system or subsystem that carries out at least the instruction to securely acquire the electronic-based signature.

2. The method of claim 1 , further comprising remediating the first vulnerability or risk by causing the content management system to take the action based at least in part on the first security vulnerability or risk, wherein

the action is determined based at least in part upon a bilateral information exchange in which the content management system and the electronic signature system or subsystem send derived information to one another, and

the bilateral information exchange comprising information pertaining to the first security vulnerability or risk and information pertaining to the plurality of collaborators or the collaboration event.

3. The method of claim 1 , further comprising:

performing the multi-stage check at least by:

in response to a determination that the content object is subject to an electronic signature processing at the electronic signature system or subsystem, performing, on the content management system, a security check on the content object.

4. The method of claim 3 , performing the multi-stage check further comprising in response to a completion of the security check, performing, on the content management system, a content check on the content object.

5. The method of claim 1 , wherein the second vulnerability or risk corresponds to a network path that involves a hop that is deemed to be a suspicious location, and the action taken by the content management system is to send the instruction to disallow an e-signature from taking place over the network path.

6. The method of claim 4 , performing the multi-stage check further comprising in response to a completion of the content check, performing, on the content management system, an event check on the collaboration event.

7. The method of claim 6 , further comprising:

passing a finding of failure of the security check, the content check, or the event check to a remediation process; and

remediating, by at least the remediation process, the first vulnerability or risk by causing the user device to take the action based on the first vulnerability or risk.

8. The method of claim 1 , wherein an indication from the user device that the first vulnerability or risk has been detected by the user device corresponds to a network path change, the action taken by the content management system is to disallow acquisition of the electronic-based signature from taking place over the network path, and the method further comprises at least one of a plurality of acts, the plurality of acts comprising:

downloading, from the content management system to the user device, an additional executable module that implements at least a call to the Internet-based interface;

upon the indication that the first vulnerability or risk has been detected, then deferring acquisition of the electronic-based signature to a later time; or

performing document hardening by watermarking a subject content object with a visible identification corresponding to a user of the user device and advising the user device that a hardened document is available as a new subject document.

9. A non-transitory computer readable medium having stored thereon a sequence of instructions which, when stored in memory and executed by one or more processors causes the one or more processors to perform a set of acts for securely acquiring and managing electronic-based signatures by a content management system, the set of acts comprising:

identifying an executable module from a content management system that hosts and exposes a content object to a plurality of collaborators for collaboration, wherein

the executable module implements an Internet-based interface that is used to acquire an electronic-based signature for the content object, using a user device connected to an electronic signature system or subsystem;

determining a document processing result pertaining to a request from the user device to access the content object over the Internet-based interface;

when the document processing result is determined to arise out of the electronic signature system or subsystem,

performing, by the content management system, an action based at least in part upon a multi-stage check that is performed on the content object or the collaboration event, wherein

the document processing result arising out of the electronic signature system or subsystem indicates a first vulnerability or risk and pertains to acquiring the electronic-based signature on the electronic signature system or subsystem; and

when the document processing result is determined to arise out of the content management system,

determining and sending an instruction from the content management system to the electronic signature system or subsystem, wherein

execution of the instruction on the electronic signature system or subsystem remediates the document processing result, and the document processing result arising out of the content management system indicates a second vulnerability or risk in acquiring the electronic-based signature on the electronic signature system or subsystem; and

triggering the electronic-signature system or subsystem that carries out at least the instruction to securely acquire the electronic-based signature.

10. The non-transitory computer readable medium of claim 9 , further comprising instructions which, when stored in memory and executed by the one or more processors causes the one or more processors to perform acts of remediating the first vulnerability or risk by causing the content management system to take an action based on the security vulnerability or risk, wherein

the action is determined based at least in part upon a bilateral information exchange in which the content management system and the electronic signature system or subsystem send derived information to one another, and

the bilateral information exchange comprising information pertaining to the first vulnerability or risk and information pertaining to the plurality of collaborators or the collaboration event.

11. The non-transitory computer readable medium of claim 9 , further comprising instructions which, when stored in memory and executed by the one or more processors causes the one or more processors to perform acts, the acts further comprising:

performing the multi-stage check at least by:

in response to a determination that the content object is subject to an electronic signature processing at the electronic signature system or subsystem, performing, on the content management system, a security check on the content object.

12. The non-transitory computer readable medium of claim 9 , further comprising instructions which, when stored in memory and executed by the one or more processors causes the one or more processors to perform the multi-stage check, performing the multi-stage check further comprising: in response to a completion of the security check, performing a content check, on the content management system, on the content object on the content management system.

13. The non-transitory computer readable medium of claim 9 , wherein the second vulnerability or risk corresponds to a network path that involves a hop that is deemed to be a suspicious location, and the action taken by the content management system is to send the instruction to disallow an e-signature from taking place over that network path.

14. The non-transitory computer readable medium of claim 12 , further comprising instructions which, when stored in memory and executed by the one or more processors causes the one or more processors to perform the multi-stage check, performing the multi-stage check further comprising in response to a completion of the content check, performing, on the content management system, an event check on the collaboration event.

15. The non-transitory computer readable medium of claim 14 , further comprising instructions which, when stored in memory and executed by the one or more processors causes the one or more processors to perform acts, the acts comprising:

passing a finding of failure of the security check, the content check, or the event check to a remediation process; and

remediating, by at least the remediation process, the first vulnerability or risk by causing the user device to take the action based at least in part on the first vulnerability or risk.

16. The non-transitory computer readable medium of claim 9 , wherein the indication from the user device that the first vulnerability or risk has been detected by the user device corresponds to a network path change, the action taken by the content management system is to disallow acquisition of the electronic-based signature from taking place over the network path, and the non-transitory computer readable medium further comprises instructions which, when executed by the one or more processors, cause the one or more processor to perform at least one of a plurality of acts, the plurality of acts comprising:

downloading, from the content management system to the user device, an additional executable module that implements at least a call to the Internet-based interface;

remediating the first vulnerability or risk by causing the user device to take the action based at least in part on the security vulnerability or risk;

upon the indication that the security vulnerability or risk has been detected, then deferring acquisition of the electronic-based signature to a later time; or

performing document hardening by watermarking a subject content object with a visible identification corresponding to a user of the user device and advising the user device that a hardened document is available as a new subject document.

17. A system for securely acquiring and managing electronic-based signatures by a content management system, the system comprising:

a storage medium having stored thereon a sequence of instructions; and

one or more processors that execute the sequence of instructions, execution of the sequence of instructions causes the one or more processors to perform a set of acts, the set of acts comprising,

identifying an executable module from a content management system that hosts and exposes a content object to a plurality of collaborators for collaboration, wherein

the collaboration comprises collaboratively modifying the content object or metadata pertaining to the content object by at least some of the plurality of collaborators in a collaboration event hosted on the content management system, and

the executable module implements an Internet-based interface that is used to acquire an electronic-based signature for the content object, using a user device connected to an electronic signature system or subsystem;

determining a document processing result pertaining to a request from the user device to access the content object over the Internet-based interface;

when the document processing result is determined to arise out of the electronic signature system or subsystem,

performing, by the content management system, an action on the content object to remediate the document processing result based at least in part upon a multi-stage check that is performed on the content object or the collaboration event, wherein

the document processing result arising out of the electronic signature system or subsystem indicates a first vulnerability or risk and pertains to acquiring the electronic-based signature on the electronic signature system or subsystem; and

when the document processing result is determined to arise out of the content management system,

determining and sending an instruction from the content management system to the electronic signature system or subsystem, wherein

execution of the instruction on the electronic signature system or subsystem remediates the document processing result, and the document processing result arising out of the content management system indicates a second vulnerability or risk in acquiring the electronic-based signature on the electronic signature system or subsystem; and

triggering the electronic-signature system or subsystem that carries out at least the instruction to securely acquire the electronic-based signature.

18. The system of claim 17 , the set of acts further comprising:

performing the multi-stage check at least by:

in response to a determination that the content object is subject to an electronic signature processing at the electronic signature system or subsystem, performing, on the content management system, a security check on the content object; and

in response to a completion of the security check, performing, on the content management system, a content check on the content object.

19. The system of claim 17 , performing the multi-stage check further comprising:

performing the multi-stage check further comprising in response to a completion of the content check, performing, on the content management system, an event check on the collaboration event; and

passing a finding of failure of the security check, the content check, or the event check to a remediation process.

20. The system of claim 17 , further comprising remediating, by at least the remediation process, the first vulnerability or risk by causing the user device to take the action based at least in part on the first vulnerability or risk and at least one of a plurality of acts, the plurality of acts comprising:

downloading, from the content management system to the user device, an additional executable module that implements at least a call to the Internet-based interface; or

remediating the first vulnerability by causing the user device to take an action based on the security vulnerability.

Assignments (2)
SECURITY INTEREST Recorded Jul 26, 2023
From: BOX, INC.
To: WELLS FARGO BANK, NATIONAL ASSOCIATION
Reel/Frame 064389/0686 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 14, 2021
From: VOLTZ, SETH MORGAN LUCE; GRÉTARSSON, JON TOMÁS
To: BOX, INC
Reel/Frame 056858/0671 →
Continuity (1)
Related Publication 20230016689A1 · Jan 19, 2023
References Cited (28)
US 20060193474A1 · Fransdonk · 2006 [cited by examiner]
US 20070192609A1 · Yoshioka et al. · 2007 [cited by applicant]
US 20110276875A1 · Mccabe et al. · 2011 [cited by applicant]
US 20120086971A1 · Bisbee et al. · 2012 [cited by applicant]
US 20140007241A1 · Gula · 2014 [cited by examiner]
US 20140019761A1 · Shapiro · 2014 [cited by examiner]
US 20140297629A1 · Lin · 2014 [cited by applicant]
US 20150213568A1 · Follis et al. · 2015 [cited by applicant]
US 20160162697A1 · Follis · 2016 [cited by applicant]
US 20160314102A1 · Bezar et al. · 2016 [cited by applicant]
US 20170041296A1 · Ford · 2017 [cited by examiner]
US 20170220605A1 · Nivala et al. · 2017 [cited by applicant]
US 20200068026A1 · Morkovine et al. · 2020 [cited by applicant]
US 20200145232A1 · Haddad · 2020 [cited by applicant]
US 20210191794A1 · Morkovine et al. · 2021 [cited by applicant]
US 20220206644A1 · Spaetzel · 2022 [cited by examiner]
“Dotloop's Accept Or Counter Flow: A BetterEsign Experience,” dotloop, Inc., dated May 4, 2017. [cited by applicant]
“Sending and Signing with eHanko,” DocuSign Support, date found via WayBack as Aug. 13, 2020. [cited by applicant]
“Allow DocuSign recipients to edit documents,” date found via Google as Sep. 3, 2020. [cited by applicant]
Walker, A., “How do I edit a signed PDF document,” Acrobat Library, date found via Google as Nov. 3, 2021 URL: https://answers.acrobatusers.com/How-I-edit-signed-PDF-document-q58365.aspx. [cited by applicant]
“Can I edit a PDF that I signed?,” Adobe, last edited Mar. 2, 2022. [cited by applicant]
Dizon-Ngo, J., “How to edit and resend a signature request,” HelloSign, dated Nov. 10, 2021. [cited by applicant]
Miller, R., “Dropbox to acquire secure document sharing startup DocSend for $165M,” techcrunch.com, dated Mar. 9, 2021. [cited by applicant]
Sawers, P., “Dropbox acquires e-signature startup HelloSign for $230 million,” VentureBeat.com, dated Jan. 28, 2019. [cited by applicant]
“Make your first API call in a few steps,” HelloSign API, date obtained via Google as May 14, 2014, URL: https://app.hellosign.com/api/documentation. [cited by applicant]
Hueter, K., “Setting up and Using the Dropbox Integration,” HelloSign, dated Jan. 20, 2022, URL: https://faq.hellosign.com/hc/en-US/articles/205830688-Setting-up-and-Using-the-Dropbox-Integration-. [cited by applicant]
Non-Final Office Action dated Nov. 8, 2023 for U.S. Appl. No. 17/706,500. [cited by applicant]
Notice of Allowance dated Apr. 10, 2024 for U.S. Appl. No. 17/706,500. [cited by applicant]