IP Library Granted Patent US 12,229,288
Granted Patent B2
US 12,229,288 · App. 18/231,623 · Granted Feb 18, 2025

Method for data protection across sharing platforms

Inventors: Arjun Sambamoorthy (Sunnyvale, CA); Prashanth Arun (Sunnyvale, CA); Dhananjay Sampath (Sunnyvale, CA); Sanjay Singh (Sunnyvale, CA); Salil Kanetkar (Sunnyvale, CA)
Assignee: ArmorBlox LLC
G06F21/6209G06F21/604G06F40/40H04L51/08G06F2221/2141
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,229,288
App. No.
18/231,623
Granted
Feb 18, 2025
Kind
B2
Abstract

A method includes: receiving selection of a document; correlating sequences of words, in the document, with a set of language signals; generating a set of document tags representing the set of language signals; and retrieving a first data access policy: associated with a particular document tag in the set of document tags; and including a set of identities permitted to access a document associated with the particular document tag; receiving selection of a recipient account of the document; and in response to detecting the set of identities excluding the recipient account, restricting access to the document by the recipient account.

Claims (89)

1. A method comprising:

storing a set of documents at a computing system, individual documents in the set of documents being associated with document tags that represent language included in the individual documents;

receiving first input indicating of a document of the set of documents;

identifying a document tag associated with the document;

obtaining a data access policy associated with the document tag, the data access policy indicating a set of identities of user accounts that are permitted to access the document associated with the document tag;

receiving second input indicating a recipient account for the document;

determining, using the data access policy, that a particular identity of the recipient account is included in the set of identities of the user accounts that are permitted to access the document;

based on the particular identity of the recipient account being not included in the set of identities, restricting access to the document by the recipient account; or

based on the particular identity of the recipient account being included in the set of identities, allowing access to the document by the recipient account;

receiving third input indicating a second document for the recipient account;

identifying a second document tag associated with the second document;

obtaining a second data access policy associated with the second document tag, the second data access policy indicating a second set of identities of user accounts that are permitted to access the second document associated with the second document tag;

determining, using the second data access policy, that the particular identity of the recipient account is not included in the second set of identities of the user accounts that are permitted to access the second document; and

based on the particular identity of the recipient account being not included in the second set of identities, restricting access to the document and the second document by the recipient account.

2. The method of claim 1 , further comprising:

determining that the document is at least one of an attachment to an outbound message or associated with a link included in the outbound message, the outbound message being destined to the recipient account; and

detecting a workflow associated with the document being the at least one of the attachment or the link,

wherein the workflow indicates that the data access policy is required to evaluate access to the document by the recipient account prior to the outbound message being delivered to the recipient account.

3. The method of claim 1 , further comprising:

receiving fourth input indicating a second recipient account of the document; and

in response to determining that the set of identities includes the second recipient account, encrypting an outbound message, to the second recipient account, comprising the document as an attachment to the outbound message.

4. The method of claim 3 , further comprising determining that the data access policy includes a rule that requires encryption of then outbound message comprising the document, associated with the document tag, as an attachment the outbound message.

5. The method of claim 1 , further comprising:

restricting access to the document by the recipient account;

receiving fourth input indicating authorization of the access to the document by the recipient account;

permitting access to the document by the recipient account; and

modifying the data access policy adding the recipient account to the set of identities.

6. The method of claim 1 , further comprising:

in response to accessing the document tag by a first user account included in the set of identities, generating a first prompt comprising a name of the document tag; and

in response to accessing the document tag by a second user account excluded from the set of identities, generating a second prompt comprising an alternate identifier of the document tag.

7. A computing system comprising:

one or more processors; and

one or more non-transitory computer-readable memory storing computer-executable instructions that, when executed by the one or more processors, cause the one or more processors to perform operations comprising:

storing a set of documents at a computing system, individual documents in the set of documents being associated with document tags that represent language included in the individual documents;

receiving first input indicating of a document of the set of documents;

identifying a document tag associated with the document;

obtaining a data access policy associated with the document tag, the data access policy indicating a set of identities of user accounts that are permitted to access the document associated with the document tag;

receiving second input indicating a recipient account for the document;

determining, using the data access policy, that a particular identity of the recipient account is included in the set of identities of the user accounts that are permitted to access the document;

based on the particular identity of the recipient account being not included in the set of identities, restricting access to the document by the recipient account; or

based on the particular identity of the recipient account being included in the set of identities, allowing access to the document by the recipient account;

in response to accessing the document tag by a first user account included in the set of identities, generating a first prompt comprising a name of the document tag; and

in response to accessing the document tag by a second user account excluded from the set of identities, generating a second prompt comprising an alternate identifier of the document tag.

8. The computing system of claim 7 , the operations further comprising:

determining that the document is at least one of an attachment to an outbound message or associated with a link included in the outbound message, the outbound message being destined to the recipient account; and

detecting a workflow associated with the document being the at least one of the attachment or the link,

wherein the workflow indicates that the data access policy is required to evaluate access to the document by the recipient account prior to the outbound message being delivered to the recipient account.

9. The computing system of claim 7 , the operations further comprising:

receiving third input indicating a second document for the recipient account;

identifying a second document tag associated with the second document;

obtaining a second data access policy associated with the second document tag, the second data access policy indicating a second set of identities of user accounts that are permitted to access the second document associated with the second document tag;

determining, using the second data access policy, that the particular identity of the recipient account is not included in the second set of identities of the user accounts that are permitted to access the second document; and

based on the particular identity of the recipient account being not included in the second set of identities, restricting access to the document and the second document by the recipient account.

10. The computing system of claim 7 , the operations further comprising:

receiving third input indicating a second recipient account of the document; and

in response to determining that the set of identities includes the second recipient account, encrypting an outbound message, to the second recipient account, comprising the document as an attachment to the outbound message.

11. The computing system of claim 10 , the operations further comprising determining that the data access policy includes a rule that requires encryption of then outbound message comprising the document, associated with the document tag, as an attachment the outbound message.

12. The computing system of claim 7 , the operations further comprising:

restricting access to the document by the recipient account;

receiving third input indicating authorization of the access to the document by the recipient account;

permitting access to the document by the recipient account; and

modifying the data access policy adding the recipient account to the set of identities.

13. One or more non-transitory computer-readable media storing computer-executable instructions that, when executed by one or more processors, cause a network orchestrator to perform operations comprising:

storing a set of documents at a computing system, individual documents in the set of documents being associated with document tags that represent language included in the individual documents;

receiving first input indicating of a document of the set of documents;

identifying a document tag associated with the document;

obtaining a data access policy associated with the document tag, the data access policy indicating a set of identities of user accounts that are permitted to access the document associated with the document tag;

receiving second input indicating a recipient account for the document;

determining, using the data access policy, that a particular identity of the recipient account is included in the set of identities of the user accounts that are permitted to access the document;

based on the particular identity of the recipient account being not included in the set of identities, restricting access to the document by the recipient account; or

based on the particular identity of the recipient account being included in the set of identities, allowing access to the document by the recipient account;

receiving third input indicating a second document for the recipient account;

identifying a second document tag associated with the second document;

obtaining a second data access policy associated with the second document tag, the second data access policy indicating a second set of identities of user accounts that are permitted to access the second document associated with the second document tag;

determining, using the second data access policy, that the particular identity of the recipient account is not included in the second set of identities of the user accounts that are permitted to access the second document; and

based on the particular identity of the recipient account being not included in the second set of identities, restricting access to the document and the second document by the recipient account.

14. The one or more non-transitory computer-readable media of claim 13 , the operations further comprising:

determining that the document is at least one of an attachment to an outbound message or associated with a link included in the outbound message, the outbound message being destined to the recipient account; and

detecting a workflow associated with the document being the at least one of the attachment or the link,

wherein the workflow indicates that the data access policy is required to evaluate access to the document by the recipient account prior to the outbound message being delivered to the recipient account.

15. The one or more non-transitory computer-readable media of claim 13 , wherein

receiving fourth input indicating a second recipient account of the document; and

in response to determining that the set of identities includes the second recipient account, encrypting an outbound message, to the second recipient account, comprising the document as an attachment to the outbound message.

16. The one or more non-transitory computer-readable media of claim 13 , the operations further comprising determining that the data access policy includes a rule that requires encryption of then outbound message comprising the document, associated with the document tag, as an attachment the outbound message.

17. The one or more non-transitory computer-readable media of claim 13 , the operations further comprising:

restricting access to the document by the recipient account;

receiving fourth input indicating authorization of the access to the document by the recipient account;

permitting access to the document by the recipient account; and

modifying the data access policy adding the recipient account to the set of identities.

Assignments (2)
CHANGE OF NAME Recorded Oct 13, 2023
From: ARMORBLOX, INC.
To: ARMORBLOX LLC
Reel/Frame 065238/0215 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 6, 2023
From: SAMBAMOORTHY, ARJUN; ARUN, PRASHANTH; SAMPATH, DHANANJAY; SINGH, SANJAY; KANETKAR, SALIL
To: ARMORBLOX, INC.
Reel/Frame 064809/0541 →
Continuity (3)
Continuation 17891426 · Aug 19, 2022
Provisional Application 63235366 · Aug 20, 2021
Related Publication 20240045978A1 · Feb 8, 2024
References Cited (11)
US 11763012B2 · Sambamoorthy et al. · 2023 [cited by applicant]
US 11768950B2 · Sambamoorthy et al. · 2023 [cited by applicant]
US 20100169439A1 · O'Sullivan · 2010 [cited by examiner]
US 20140172497A1 · Kim et al. · 2014 [cited by applicant]
US 20160140328A1 · Pathak · 2016 [cited by examiner]
US 20180082069A1 · Cunico et al. · 2018 [cited by applicant]
US 20180204022A1 · Panchbudhe · 2018 [cited by examiner]
US 20190129968A1 · Neylan · 2019 [cited by examiner]
US 20190166162A1 · Anand · 2019 [cited by examiner]
US 20200259933A1 · Goodyear et al. · 2020 [cited by applicant]
Office Action mailed May 30, 2024 for U.S. Appl. No. 17/971,409 “Method for Data Protection Across Sharing Platforms” Khosrowshahi,F. 11 pages. [cited by applicant]