IP Library Granted Patent US 12,488,142
Granted Patent B2
US 12,488,142 · App. 18/129,734 · Granted Dec 2, 2025

Obtaining trusted e-signatures

Inventors: Rohit Bakshi (Campbell, CA); Yi Zhao (Redwood City, CA); Kanav Gandhi (Mountain View, CA); Areg Alimian (Woodland Hills, CA); Will Carlson (Glenview, IL); Virender Gupta (Morganville, NJ); Sanjiv Pandey (Henderson, NV); Kechen Huang (Menlo Park, CA)
Assignee: Box, Inc.
G06F21/6245G06F21/645
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,488,142
App. No.
18/129,734
Granted
Dec 2, 2025
Kind
B2
Abstract

Methods, systems, and computer program products for content management systems. Multiple components are operatively interconnected to carry out operations for establishing a user device trust level. A content management system facilitates interactions between a plurality of user devices and a plurality of shared content objects. The plurality of user devices are network connected to the content management system. One of the user devices issues a request to access a particular one of the content objects. Responsive to the request, a two-step device check is performed before granting access to the particular one of the content objects. A first step of the two-step device check process is based on environmental information, and a second step of the two-step device check process is based at least in part on analysis of the content of the particular one of the content objects. The actual bits of the content object itself are inspected.

Claims (41)

1 . A method comprising:

receiving, at a content management system, an e-sign event raised in response to an e-sign request from a user device, wherein the content management system facilitates interactions between a plurality of user devices and a plurality of content objects, the content management system performs acts to determine whether to allow or deny access to individual content objects of the plurality of content objects by respective user devices, the e-sign request corresponds to a content object of the plurality of content objects, and the content management system is associated with an e-signature system;

forwarding the e-sign event, by the content management system, to the e-signature system to execute a multiple-step e-signature trust process, wherein the e-signature system responds to the e-sign event by executing the multiple-step e-signature trust process comprising:

calculating a device trust value based at least in part on an environmental condition corresponding to the user device by at least accessing one or more first modules of the content management system, wherein the device trust value is dynamically determined based at least in part on a risk profile generated by a third party; and

calculating a content access trust value based at least in part on a sensitivity level of contents of a content object, wherein the content access trust value is determined based on at least inspection of the content object by the content management system; and

performing further processing of the e-sign event based upon a combination of the content access trust value and the device trust value when the combination fails to satisfy an adaptive risk tolerance threshold, wherein the adaptive risk tolerance threshold is based on at least the contents of the content object or its metadata.

2 . The method of claim 1 , wherein the environmental condition comprises at least one of, a device term, a network term, or a user term.

3 . The method of claim 1 , wherein the sensitivity level comprises at least one of, a document classification term, or a likelihood of personally identifiable information term.

4 . The method of claim 1 , wherein performing the further processing of the e-sign event comprises reevaluating results of deep content inspection.

5 . The method of claim 1 , wherein performing the further processing comprises at least one of, performing a multi-factor authentication challenge or accessing third party device risk profiles.

6 . The method of claim 1 , wherein the device trust value dynamically determined based at least in part on the risk profile generated by the third party corresponds to a non-CMS user and the third party maintains third party security risks or historical risk scores.

7 . The method of claim 1 , wherein generating the content access trust value comprises inspection, by the content management system, of stored bits that comprise the content of the content object.

8 . The method of claim 1 , wherein performing the further processing further comprises:

generating a second content access trust value based at least in part on inspection of at least some stored bits that comprise the content of at the least one of the content objects, and

evaluating a second rule that depends on both the device trust value and the second content access trust value.

9 . The method of claim 8 , wherein a filter, or a precedence regime or a priority ranking is applied to determine a particular one from among multiple additional further processing options.

10 . The method of claim 1 , wherein the content object is associated with a security label determined by inspection of stored bits that comprise the contents ofa content object.

11 . A non-transitory computer readable medium having stored thereon a sequence of instructions which, when stored in memory and executed by one or more processors causes the one or more processors to perform a set of acts, the set of acts comprising:

receiving, at a content management system, an e-sign event raised in response to an e-sign request from a user device, wherein the content management system facilitates interactions between a plurality of user devices and a plurality of content objects, the content management system performs acts to determine whether to allow or deny access to individual content objects of the plurality of content objects by respective user devices, the e-sign request corresponds to a content object of the plurality of content objects, and the content management system is associated with an e-signature system;

forwarding the e-sign event, by the content management system, to the e-signature system to execute a multiple-step e-signature trust process, wherein the e-signature system responds to the e-sign event by executing the multiple-step e-signature trust process comprising:

calculating a device trust value based at least in part on an environmental condition corresponding to the user device by at least accessing one or more first modules of the content management system, wherein the device trust value is dynamically determined based at least in part on a risk profile generated by a third party; and

calculating a content access trust value based at least in part on a sensitivity level of contents of a content object, wherein the content access trust value is determined based on at least inspection of the content object by the content management system; and

performing further processing of the e-sign event based upon a combination of the content access trust value and the device trust value when the combination fails to satisfy an adaptive risk tolerance threshold, wherein the adaptive risk tolerance threshold is based on at least the contents of the content object or its metadata.

12 . The non-transitory computer readable medium of claim 11 , wherein the environmental condition comprises at least one of, a device term, a network term, or a user term.

13 . The non-transitory computer readable medium of claim 11 , wherein the sensitivity level comprises at least one of, a document classification term, or a likelihood of personally identifiable information term.

14 . The non-transitory computer readable medium of claim 11 , wherein performing the further processing of the e-sign event comprises reevaluating results of deep content inspection.

15 . The non-transitory computer readable medium of claim 11 , wherein performing the further processing comprises at least one of, performing a multi-factor authentication challenge or accessing third party device risk profiles.

16 . The non-transitory computer readable medium of claim 11 , wherein the device trust value dynamically determined based at least in part on the risk profile generated by the third party corresponds to a non-CMS user and the third party maintains third party security risks or historical risk scores.

17 . The non-transitory computer readable medium of claim 11 , wherein generating the content access trust value comprises inspection, by the content management system, of stored bits that comprise the content of the content object.

18 . The non-transitory computer readable medium of claim 11 , wherein performing the further processing further comprises instructions which, when stored in memory and executed by the one or more processors causes the one or more processors to perform acts of:

generating a second content access trust value based at least in part on inspection of at least some stored bits that comprise the content of at the least one of the content objects, and

evaluating a second rule that depends on both the device trust value and the second content access trust value.

19 . A system comprising:

a storage medium having stored thereon a sequence of instructions; and

one or more processors that execute the sequence of instructions to cause the one or more processors to perform a set of acts, the set of acts comprising,

receiving, at a content management system, an e-sign event raised in response to an e-sign request from a user device, wherein the content management system facilitates interactions between a plurality of user devices and a plurality of content objects, the content management system performs acts to determine whether to allow or deny access to individual content objects of the plurality of content objects by respective user devices, the e-sign request corresponds to a content object of the plurality of content objects, and the content management system is associated with an e-signature system;

forwarding the e-sign event, by the content management system, to the e-signature system to execute a multiple-step e-signature trust process, wherein the e-signature system responds to the e-sign event by executing the multiple-step e-signature trust process comprising:

calculating a device trust value based at least in part on an environmental condition corresponding to the user device by at least accessing one or more first modules of the content management system, wherein the device trust value is dynamically determined based at least in part on a risk profile generated by a third party; and

calculating a content access trust value based at least in part on a sensitivity level of contents of a content object, wherein the content access trust value is determined based on at least inspection of the content object by the content management system; and

performing further processing of the e-sign event based upon a combination of the content access trust value and the device trust value when the combination fails to satisfy an adaptive risk tolerance threshold, wherein the adaptive risk tolerance threshold is based on at least the contents of the content object or its metadata.

20 . The system of claim 19 , wherein the device trust value dynamically determined based at least in part on the risk profile generated by the third party corresponds to a non-CMS user and the third party maintains third party security risks or historical risk scores.

Assignments (2)
SECURITY INTEREST Recorded Jul 26, 2023
From: BOX, INC.
To: WELLS FARGO BANK, NATIONAL ASSOCIATION
Reel/Frame 064389/0686 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 1, 2023
From: GANDHI, KANAV; BAKSHI, ROHIT; GUPTA, VIRENDER; ALIMIAN, AREG; CARLSON, WILL; PANDEY, SANJIV; HUANG, KECHEN; ZHAO, YI
To: BOX, INC.
Reel/Frame 063198/0264 →
Continuity (3)
Continuation In Part 17390153 · Jul 30, 2021
Provisional Application 62706868 · Sep 14, 2020
Related Publication 20230306133A1 · Sep 28, 2023
References Cited (49)
US 7346668B2 · Willis · 2008 [cited by applicant]
US 7428591B2 · Stebbings · 2008 [cited by applicant]
US 7434048B1 · Shapiro · 2008 [cited by examiner]
US 8640251B1 · Lee et al. · 2014 [cited by applicant]
US 9979500B2 · Raman · 2018 [cited by examiner]
US 10885410B1 · Rule et al. · 2021 [cited by applicant]
US 10949382B2 · Hammer et al. · 2021 [cited by applicant]
US 11327665B2 · Gkoulalas-Divanis · 2022 [cited by examiner]
US 11509658B1 · Kulkarni · 2022 [cited by examiner]
US 11962578B2 · Steeves · 2024 [cited by examiner]
US 20010023421A1 · Numao et al. · 2001 [cited by applicant]
US 20110014972A1 · Herrmann et al. · 2011 [cited by applicant]
US 20130227285A1 · Bracher et al. · 2013 [cited by applicant]
US 20140013422A1 · Janus et al. · 2014 [cited by applicant]
US 20140129942A1 · Rathod · 2014 [cited by applicant]
US 20150213568A1 · Follis · 2015 [cited by examiner]
US 20150271267A1 · Solis et al. · 2015 [cited by applicant]
US 20160179776A1 · Bartley · 2016 [cited by examiner]
US 20160188902A1 · Jin · 2016 [cited by examiner]
US 20160253509A1 · Wibran · 2016 [cited by examiner]
US 20160373515A1 · Jagad et al. · 2016 [cited by applicant]
US 20170041296A1 · Ford · 2017 [cited by examiner]
US 20170251231A1 · Fullerton et al. · 2017 [cited by applicant]
US 20180267862A1 · Aseev et al. · 2018 [cited by applicant]
US 20180278614A1 · Miller et al. · 2018 [cited by applicant]
US 20200067705A1 · Brown · 2020 [cited by examiner]
US 20200092300A1 · Mital et al. · 2020 [cited by applicant]
US 20200145226A1 · Haddad · 2020 [cited by examiner]
US 20200226703A1 · Abad et al. · 2020 [cited by applicant]
US 20200242159A1 · Dain · 2020 [cited by examiner]
US 20200266996A1 · Carrott · 2020 [cited by examiner]
US 20200274861A1 · Black et al. · 2020 [cited by applicant]
US 20210021423A1 · Latorre et al. · 2021 [cited by applicant]
US 20210081923A1 · Rafferty et al. · 2021 [cited by applicant]
US 20210099453A1 · Cohen et al. · 2021 [cited by applicant]
US 20210350011A1 · Ashlock · 2021 [cited by examiner]
US 20210350033A1 · Kapinos et al. · 2021 [cited by applicant]
US 20220210173A1 · Katmor · 2022 [cited by examiner]
“Configure behavior detection,” Okta Help Center, dated obtained via Internet Archive as Apr. 20, 2021, URL: https://help.okta.com/en/prod/Content/Topics/Security/behavior-detection/configure-behavior-detection.htm. [cited by applicant]
“Okta Device Trust solutions,” Okta Help Center, date obtained via Internet Archives as May 7, 2021, URL: https://help.okta.com/en/prod/Content/Topics/device-trust/device-trust-landing.htm. [cited by applicant]
Non-Final Office Action dated Dec. 12, 2022 for U.S. Appl. No. 17/390,153. [cited by applicant]
Final Office Action dated Mar. 31, 2023 for U.S. Appl. No. 17/390,153. [cited by applicant]
Crowstrike, “Falcon Insight: Endpoint Detection and Response (EDR)”, CrowdStrike Products, dated May 19, 2023. [cited by applicant]
Revankar, Mehul, “A Deep Dive into VMDR 2.0 with Qualys TruRisk”, Last updated Mar. 1, 2023. [cited by applicant]
Non-Final Office Action dated Sep. 15, 2023 for U.S. Appl. No. 17/390,153. [cited by applicant]
Final Office Action dated Jan. 24, 2024 for U.S. Appl. No. 17/390,153. [cited by applicant]
Non-Final Office Action dated Sep. 16, 2024 for U.S. Appl. No. 17/390,153. [cited by applicant]
Final Office Action dated Jan. 30, 2025 for U.S. Appl. No. 17/390,153. [cited by applicant]
Notice of Allowance dated Apr. 15, 2025 for U.S. Appl. No. 17/390,153. [cited by applicant]