IP Library Granted Patent US 12,388,808
Granted Patent B2
US 12,388,808 · App. 17/958,154 · Granted Aug 12, 2025

Security and governance policies in electronic signature systems

Inventors: Virender Gupta (Morganville, NJ); Rohit Bakshi (Campbell, CA); Yi Zhao (Redwood City, CA); Shawn Shay (Castro Valley, CA); William Ernest Carlson (Austin, TX)
Assignee: Box, Inc.
H04L63/08H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,388,808
App. No.
17/958,154
Granted
Aug 12, 2025
Kind
B2
Abstract

Policy-informed e-signature processing. An electronic signature system (ESS) is interfaced to a content management system (CMS) that stores instances of shared files and coordinates policy-informed interactions with the shared files. Upon detection of an occurrence of an e-signature request event, electronic signature processing is carried out in a manner that observes one or more governance policies that control handling of shared files. When responding to an e-signature request event, the CMS observes the governance policies by issuing an electronic query to a database of parameters, wherein the parameters define metes and bounds of the governance policies. Upon determination that at least some of the governance policies at least potentially apply to the e-signature processing, the ESS and/or the CMS modifies metadata pertaining to one or more workflow objects that are associated with a computer-implemented workflow. The workflow may terminate or be terminated based upon the one or more governance policies.

Claims (37)

1. A method for e-signature processing comprising:

interfacing an electronic signature system (ESS) to a content management system (CMS) that stores instances of content objects and coordinates user interactions with the content objects, the user interactions being by a plurality of CMS users;

detecting occurrence of an e-signature request event associated with a content object, wherein at least one signatory corresponds to at least one of the plurality of CMS users; and

responding to the e-signature request event by:

issuing an electronic query to a database of parameters, wherein the database stores a plurality of parameter values that define a set of governance policies, and wherein at least some of the plurality of parameters are selected based on a determination that at least some of the governance policies apply to e-signature processing; and

modifying metadata pertaining to the content object that is associated with a workflow, wherein the metadata is modified to set permissions for the content object to be used for the e-signature processing, a workflow trigger for the workflow is generated for the e-signature processing, and the workflow trigger is based upon the determination that at least some of the set of governance policies apply to e-signature processing.

2. The method of claim 1 wherein at least one governance policy of the set of governance policies specifies a security classification.

3. The method of claim 2 , further comprising terminating at least a portion of the e-signature processing when a security classification value of a particular content object of the CMS is higher than a security clearance of a signatory.

4. The method of claim 2 , further comprising determining which ones of a plurality of signatories are registered users of the CMS.

5. The method of claim 4 , further comprising terminating at least a portion of the e-signature processing when a participant specified in the e-signature request event is not one of the registered users of the CMS.

6. The method of claim 1 wherein a risk score is calculated based on (1) the at least some of the governance policies, (2) a security classification value of file, or (3) a security clearance level of one or more of the signatories.

7. The method of claim 1 , further comprising invoking further authentication of a signatory's identity through use of a multi-factor authentication regime.

8. The method of claim 7 , wherein a first factor of the multi-factor authentication regime comprises confirmation of the signatory's identity in the CMS, and a second factor of the multi-factor authentication regime comprises confirmation of the signatory's response to a challenge on a device of record in the CMS.

9. The method of claim 1 , further comprising invoking a process to establish a retention period designation.

10. The method of claim 9 , further comprising applying the retention period designation to one or more content objects of the content management system.

11. The method of claim 1 , further comprising identifying one or more policy conflicts wherein the one or more policy conflicts are identified by comparing parameters of a new policy with respect to parameters of previously stored policies.

12. The method of claim 11 , wherein a check for a policy conflict is carried out upon occurrence of an attempt to introduce the new policy.

13. A non-transitory computer readable medium having stored thereon a sequence of instructions which, when stored in memory and executed by one or more processors causes the one or more processors to perform a set of acts for e-signature processing the set of acts comprising:

interfacing an electronic signature system (ESS) to a content management system (CMS) that stores instances of content objects and coordinates user interactions with the content objects, the user interactions being by a plurality of CMS users;

detecting occurrence of an e-signature request event associated with a content object, wherein at least one signatory corresponds to at least one of the plurality of CMS users; and

responding to the e-signature request event by:

issuing an electronic query to a database of parameters, wherein the database stores a plurality of parameter values that define a set of governance policies, and wherein at least some of the plurality of parameters are selected based on a determination that at least some of the governance policies apply to e-signature processing; and

modifying metadata pertaining to the content object that is associated with a workflow, wherein the metadata is modified to set permissions for the content object to be used for the e-signature processing, occurrence of a workflow trigger for the workflow is generated for the e-signature processing, and the workflow trigger is based upon the determination that at least some of the set of governance policies apply to the e-signature processing.

14. The non-transitory computer readable medium of claim 13 wherein at least one governance policy of the set of governance policies specifies a security classification.

15. The non-transitory computer readable medium of claim 14 , further comprising instructions which, when stored in memory and executed by the one or more processors causes the one or more processors to perform acts of terminating at least a portion of the e-signature processing when a security classification value of a particular content object of the CMS is higher than a security clearance of a signatory.

16. The non-transitory computer readable medium of claim 14 , further comprising instructions which, when stored in memory and executed by the one or more processors causes the one or more processors to perform acts of determining which ones of a plurality of signatories are registered users of the CMS.

17. The non-transitory computer readable medium of claim 16 , further comprising instructions which, when stored in memory and executed by the one or more processors causes the one or more processors to perform acts of terminating at least a portion of the e-signature processing when a participant specified in the e-signature request event is not one of the registered users of the CMS.

18. The non-transitory computer readable medium of claim 13 wherein a risk score is calculated based on (1) the at least some of the governance policies, (2) a security classification value of file, or (3) a security clearance level of one or more of the signatories.

19. A system for e-signature processing comprising:

a storage medium having stored thereon a sequence of instructions; and

one or more processors that execute the sequence of instructions to cause the one or more processors to perform a set of acts, the set of acts comprising,

interfacing an electronic signature system (ESS) to a content management system (CMS) that stores instances of content objects and coordinates user interactions with the content objects, the user interactions being by a plurality of CMS users;

detecting occurrence of an e-signature request event associated with a content object, wherein at least one signatory corresponds to at least one of the plurality of CMS users; and

responding to the e-signature request event by:

issuing an electronic query to a database of parameters, wherein the database stores a plurality of parameter values that define a set of governance policies, and wherein at least some of the plurality of parameters are selected based on a determination that at least some of the governance policies apply to e-signature processing; and

modifying metadata pertaining to the content object that is associated with a workflow, wherein the metadata is modified to set permissions for the content object to be used for the e-signature processing, a workflow trigger for the workflow is generated for the e-signature processing, and the workflow trigger is based upon the determination that at least some of the set of governance policies apply to the e-signature processing.

20. The system of claim 19 wherein at least one governance policy of the set of governance policies specifies a security classification.

Assignments (2)
SECURITY INTEREST Recorded Jul 26, 2023
From: BOX, INC.
To: WELLS FARGO BANK, NATIONAL ASSOCIATION
Reel/Frame 064389/0686 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 30, 2022
From: GUPTA, VIRENDER; BAKSHI, ROHIT; ZHAO, YI; SHAY, SHAWN; CARLSON, WILLIAM ERNEST
To: BOX, INC.
Reel/Frame 061278/0001 →
Continuity (6)
Continuation In Part 16948828 · Oct 1, 2020
Continuation In Part 16553057 · Aug 27, 2019
Provisional Application 63262133 · Oct 5, 2021
Provisional Application 62723314 · Aug 27, 2018
Provisional Application 62723435 · Aug 27, 2018
Related Publication 20230025808A1 · Jan 26, 2023
References Cited (38)
US 10552590B2 · Hamlin et al. · 2020 [cited by applicant]
US 10726152B1 · Durham et al. · 2020 [cited by applicant]
US 10902072B2 · Anders et al. · 2021 [cited by applicant]
US 10943030B2 · Guymon, Jr. · 2021 [cited by examiner]
US 10979432B1 · Frank et al. · 2021 [cited by applicant]
US 11689517B2 · Styliadis · 2023 [cited by examiner]
US 20030018890A1 · Hale et al. · 2003 [cited by applicant]
US 20090307746A1 · Di et al. · 2009 [cited by applicant]
US 20140208425A1 · Palomaki · 2014 [cited by applicant]
US 20150089575A1 · Vepa et al. · 2015 [cited by applicant]
US 20150227756A1 · Barbas · 2015 [cited by applicant]
US 20160048696A1 · Follis · 2016 [cited by examiner]
US 20160070758A1 · Thomson et al. · 2016 [cited by applicant]
US 20160117495A1 · Li et al. · 2016 [cited by applicant]
US 20170083867A1 · Saxena · 2017 [cited by examiner]
US 20170223093A1 · Peterson · 2017 [cited by examiner]
US 20180114015A1 · Nuseibeh et al. · 2018 [cited by applicant]
US 20180124609A1 · Ciano et al. · 2018 [cited by applicant]
US 20190220550A1 · Arasachetty · 2019 [cited by examiner]
US 20200092337A1 · Ojha et al. · 2020 [cited by applicant]
Non-Final Office Action for U.S. Appl. No. 16/948,828 dated Jul. 22, 2022. [cited by applicant]
J. Alqatawna, E. Rissanen and B. Sadighi, “Overriding of Access Control in XACML,” Eighth IEEE International Workshop on Policies for Distributed Systems and Networks (Policy'07), 2007, pp. 87-95 (Year: 2007). [cited by applicant]
International Search Report and Written Opinion dated Dec. 11, 2019 for PCT Appln. No. PCT/US19/48435. [cited by applicant]
Non-Final Office Action Dated Feb. 17, 2022 U.S. Appl. No. 16/553,057. [cited by applicant]
Non-Final Office Action for U.S. Appl. No. 16/553,063 dated Mar. 3, 2022. [cited by applicant]
Final Office Action dated Oct. 7, 2021 U.S. Appl. No. 16/553,063. [cited by applicant]
Non-Final Office Action dated Jun. 8, 2021 U.S. Appl. No. 16/553,063. [cited by applicant]
European Search Report dated Sep. 20, 2021 for related EP Applicatio No. 19853611.2. [cited by applicant]
Notice of Allowance dated Jun. 24, 2022 for U.S. Appl. No. 16/553,063. [cited by applicant]
Final Office Action dated Jul. 21, 2022; U.S. Appl. No. 16/553,057. [cited by applicant]
Chen, Y., et al., “What's New About Cloud Computing Security?,” Electrical Engineering and Computer Sciences, University of California at Berkeley, dated Jan. 20, 2010. [cited by applicant]
Filippi, D., et al., “Cloud Computing: Centralization and Data Sovereignty,” European Journal of Law and Technology, vol. 3, No. 2, 2012. [cited by applicant]
Notice of Allowance dated Apr. 30, 2024 for related U.S. Appl. No. 16/553,057. [cited by applicant]
Notice of Allowance dated Aug. 14, 2024 for related U.S. Appl. No. 16/553,057. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 16/948,828 dated Nov. 16, 2022. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 16/553,063 dated Feb. 1, 2023. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 16/553,063 dated Sep. 21, 2022. [cited by applicant]
Notice of Allowance dated Dec. 20, 2024 for related U.S. Appl. No. 16/553,057. [cited by applicant]