IP Library Granted Patent US 12,639,448
Granted Patent B2
US 12,639,448 · App. 18/346,137 · Granted May 26, 2026

Defining a security perimeter using knowledge of user behavior within a content management system

Inventors: Areg Alimian (Woodland Hills, CA); Ryan Matthew Knotts (San Jose, CA); Kanav Gandhi (Mountain View, CA)
Assignee: Box, Inc.
G06F21/577H04L63/1425H04L63/20G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,639,448
App. No.
18/346,137
Granted
May 26, 2026
Kind
B2
Abstract

Methods, systems, and computer program products for content management systems. Multiple components are operatively interconnected to carry out operations for content management systems. Content objects of a content management system (CMS) are managed from original creation through to final disposition (e.g., deletion). The CMS communicates with a security threat management facility (STMF). In operation, the STMF establishes a first set of security parameters corresponding to information derived from packet inspection, whereas the CMS establishes a second set of security parameters corresponding to information derived at least in part by analysis of user activities or contents of the content object. A security perimeter is formed by combining the first set of security parameters and a second set of security parameters. Risks or vulnerabilities corresponding to the content object are minimized by choosing the lower of any two compared parameters to define a lower risk perimeter for the content object.

Claims (33)

1 . A method for handling a content object of a content management system (CMS), the method comprising:

establishing, by a threat management facility, a first set of security parameters corresponding to information derived from packet inspection, wherein the first set of security parameters define a first security perimeter;

establishing, by the content management system separate from the threat management facility, a second set of security parameters corresponding to information derived at least in part based on content management system analysis of user activities performed on the content object, wherein the second set of security parameters define a second security perimeter; and

combining the first security perimeter and the second security perimeter to define a security perimeter, wherein the combining is performed at least by comparing the first set of security parameters and the second set of security parameters, the first set of security parameters are derived from a set of non-content-based threat values, and the second set of security parameters are specific to the content object and are derived from a set of content-based threat values.

2 . The method of claim 1 , wherein at least one parameter of the first set of security parameters further corresponds to information derived from an identity access management facility.

3 . The method of claim 1 , wherein the user activities performed on the content object are captured in an event history comprising a history of operations performed over the content object by users who access the content object.

4 . The method of claim 1 , wherein at least one parameter of the second set of security parameters further corresponds to information derived from an active directory.

5 . The method of claim 1 , wherein at least one parameter of the second set of security parameters further corresponds to information derived from one or more of, a user's role in an enterprise, a user's resignation date, or aspects of a user's device-local storage.

6 . The method of claim 1 , wherein at least one parameter of the second set of security parameters further corresponds to information derived from content object metadata.

7 . The method of claim 6 , wherein the content object metadata pertains to at least one of, a security classification, an existence of PII, or a precalculated risk tolerance value.

8 . The method of claim 1 , wherein the content object bears a security watermark.

9 . The method of claim 1 , wherein the content object bears an embedded legend.

10 . The method of claim 1 , wherein contents of the content object refer to one or more business transactions.

11 . A non-transitory computer readable medium having stored thereon a sequence of instructions which, when stored in memory and executed by one or more processors causes the one or more processors to perform a set of acts for handling a content object of a content management system (CMS), the set of acts comprising:

establishing, by a threat management facility, a first set of security parameters corresponding to information derived from packet inspection, wherein the first set of security parameters define a first security perimeter;

establishing, by the content management system separate from the threat management facility, a second set of security parameters corresponding to information derived at least in part based on content management system analysis of user activities performed on the content object, wherein the second set of security parameters define a second security perimeter; and

combining the first security perimeter and the second security perimeter to define a security perimeter, wherein the combining is performed at least by comparing the first set of security parameters and the second set of security parameters, the first set of security parameters are derived from a set of non-content-based threat values, and the second set of security parameters are specific to the content object and are derived from a set of content-based threat values.

12 . The non-transitory computer readable medium of claim 11 , wherein at least one parameter of the first set of security parameters further corresponds to information derived from an identity access management facility.

13 . The non-transitory computer readable medium of claim 11 , wherein the user activities performed on the content object are captured in an event history comprising a history of operations performed over the content object by users who access the content object.

14 . The non-transitory computer readable medium of claim 11 , wherein at least one parameter of the second set of security parameters further corresponds to information derived from an active directory.

15 . The non-transitory computer readable medium of claim 11 , wherein at least one parameter of the second set of security parameters further corresponds to information derived from one or more of, a user's role in an enterprise, a user's resignation date, or aspects of a user's device-local storage.

16 . The non-transitory computer readable medium of claim 11 , wherein at least one parameter of the second set of security parameters further corresponds to information derived from content object metadata.

17 . The non-transitory computer readable medium of claim 16 , wherein the content object metadata pertains to at least one of, a security classification, an existence of PII, or a precalculated risk tolerance value.

18 . The non-transitory computer readable medium of claim 11 , wherein the content object bears a security watermark.

19 . A system for handling a content object of a content management system (CMS), the system comprising:

a storage medium having stored thereon a sequence of instructions; and

one or more processors that execute the sequence of instructions to cause the one or more processors to perform a set of acts, the set of acts comprising,

establishing, by a threat management facility, a first set of security parameters corresponding to information derived from packet inspection, wherein the first set of security parameters define a first security perimeter;

establishing, by the content management system separate from the threat management facility, a second set of security parameters corresponding to information derived at least in part based on content management system analysis of user activities performed on the content object, wherein the second set of security parameters define a second security perimeter; and

combining the first security perimeter and the second security perimeter to define a security perimeter, wherein the combining is performed at least by comparing the first set of security parameters and the second set of security parameters, the first set of security parameters are derived from a set of non-content-based threat values, and the second set of security parameters are specific to the content object and are derived from a set of content-based threat values.

20 . The system of claim 19 ,

wherein at least one parameter of the first set of security parameters further corresponds to information derived from an identity access management facility, and

wherein the user activities performed on the content object are captured in an event history comprising a history of operations performed over the content object by users who access the content object.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 19, 2025
From: ALIMIAN, AREG; KNOTTS, RYAN MATTHEW; GANDHI, KANAV
To: BOX, INC.
Reel/Frame 072964/0684 →
Continuity (2)
Provisional Application 63413210 · Oct 4, 2022
Related Publication 20240114056A1 · Apr 4, 2024
References Cited (17)
US 10686816B1 · Shintre et al. · 2020 [cited by applicant]
US 11483386B1 · Huang · 2022 [cited by examiner]
US 20100063868A1 · Bird · 2010 [cited by examiner]
US 20160191465A1 · Thomas · 2016 [cited by examiner]
US 20200089892A1 · Ojha · 2020 [cited by examiner]
US 20240111877A1 · Alimian · 2024 [cited by examiner]
US 20240114056A1 · Alimian · 2024 [cited by examiner]
EP 3854047B1 · 2024 [cited by applicant]
Foxit (When it Makes Sense to Watermark Your PDF Documents, May 31, 2019, 3 pages) (Year: 2019). [cited by examiner]
Non-Final Office Action dated Apr. 10, 2025 for related U.S. Appl. No. 18/346,156. [cited by applicant]
Final Office Action dated Jul. 30, 2025 for related U.S. Appl. No. 18/346,156. [cited by applicant]
Notice of Allowance dated Oct. 9, 2025 for related U.S. Appl. No. 18/346,156. [cited by applicant]
Crowdstrike, 2023 Global Threat Report, dated 2023. [cited by applicant]
Kaspersky, “Machine Learning for Malware Detection”, Date retrieved from google, Nov. 17, 2017. [cited by applicant]
Kulkarni, “Taking Security to the Next Level: CrowdStrike Now Analyzes over 100 Billion Events Per Day”, Crowdstrike Blog, dated May 23, 2018. [cited by applicant]
Box Support, Introducing modifiable retention policies in Box Governance !. dated Jul. 14, 2022. [cited by applicant]
Box, The Content Cloud, Secure content management and collaboration, date found via Internet Archive as Feb. 2, 2023. [cited by applicant]