IP Library Granted Patent US 9,286,484
Granted Patent B2
US 9,286,484 · App. 14/106,223 · Granted Mar 15, 2016

Method and system for providing document retention using cryptography

Inventor: Satyajit Nath (Cupertino, CA)
Assignee: Intellectual Ventures I LLC
G06F21/6209G06F2221/2137
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,286,484
App. No.
14/106,223
Filed
Dec 13, 2013
Granted
Mar 15, 2016
Kind
B2
Art Unit
2494
USPC
713/189
Abstract

Techniques for utilizing security criteria to implement document retention for electronic documents are disclosed. The security criteria can also limit when, how and where access to the electronic documents is permitted. The security criteria can pertain to keys (or ciphers) used to secure (e.g., encrypt) electronic files (namely, electronic documents), or to unsecure (e.g., decrypt) electronic files already secured. At least a portion of the security criteria can be used to implement document retention, namely, a document retention policy. After a secured electronic document has been retained for the duration of the document retention policy, the associated security criteria becomes no longer available, thus preventing subsequent access to the secured electronic document. In other words, access restrictions on electronic documents can be used to prevent access to electronic documents which are no longer to be retained.

Claims (39)

1. A method for restricting access to an electronic document, comprising:

identifying an electronic document to be secured, the electronic document having at least a data portion that contains data;

encrypting the data portion of the electronic document using a document key to produce an encrypted data portion;

encrypting the document key using a retention access key to produce an encrypted document key, the retention access key being used to enforce a document retention policy on the electronic document; and

forming a secured electronic document based on at least the encrypted data portion and the encrypted document key,

wherein the document retention policy is dependent on a future event that is presently unscheduled, wherein the document retention policy expires at a determined time after the future event occurs, and wherein the future event is scheduled after the document retention policy is associated with the electronic document.

2. The method of claim 1 , wherein the retention access key is a public retention access key.

3. The method of claim 1 , further comprising:

maintaining accessibility to the retention access key from a remote key store while a document retention period of the document retention policy has not been exceeded.

4. The method of claim 3 , further comprising:

receiving, by a client machine, the retention access key from the remote key store over a network.

5. The method of claim 3 , further comprising:

receiving, by a server, the retention access key from the remote key store over a network.

6. The method of claim 1 , further comprising:

extending the determined time of expiration after the future event has occurred.

7. A method for accessing a secured electronic document by a requestor, the secured electronic document having at least a header portion and an encrypted data portion, comprising:

obtaining a retention access key, the retention access key being used to enforce a document retention policy on the secured electronic document;

obtaining an encrypted document key from the header portion of the secured electronic document;

decrypting the encrypted document key using the retention access key to produce a document key; and

decrypting the encrypted data portion of the secured electronic document using the document key to produce a data portion,

wherein the document retention policy is dependent on a future event that is presently unscheduled, wherein the document retention policy expires at a determined time after the future event occurs, and wherein the future event is scheduled after the document retention policy is associated with the electronic document.

8. The method of claim 7 , further comprising:

supplying the data portion to the requestor, wherein the retention access key is identified by an indicator within a header portion of the secured electronic document.

9. The method of claim 7 , wherein the retention access key is a private retention access key.

10. The method of claim 7 , wherein the obtaining a retention access key comprises obtaining the retention access key from a server, wherein the server determines whether the retention access key is permitted to be provided to the requestor based on the document retention policy.

11. The method of claim 7 , wherein the retention access key is available from a remote key store only so long as a document retention period of the document retention policy has not been exceeded.

12. The method of claim 7 , wherein:

the retention access key is available only so long as a document retention period of the document retention policy has not been exceeded, and

the document retention period can be extended to permit extended access to the electronic document.

13. The method of claim 7 , wherein the retention access key is available while a document retention period of the document retention policy has not been exceeded.

14. A non-transitory computer-readable storage medium having control logic recorded thereon that, in response to execution by a processor in a computing system, causes the processor to perform operations to restrict access to an electronic document, the operations comprising:

identifying an electronic document to be secured, the electronic document having at least a data portion that contains data;

encrypting the data portion of the electronic document using a document key to produce an encrypted data portion;

encrypting the document key using a retention access key to produce an encrypted document key, the retention access key being used to enforce a document retention policy on the electronic document; and

forming a secured electronic document based on at least the encrypted data portion and the encrypted document key,

wherein the document retention policy is dependent on a future event that is presently unscheduled, wherein the document retention policy expires at a determined time after the future event occurs, and wherein the future event is scheduled after the document retention policy is associated with the electronic document.

15. The non-transitory computer-readable storage medium of claim 14 , the operations further comprising:

providing the retention access key to a requesting device if the document retention policy has not expired; and

denying, access to the retention access key if the document retention policy has expired.

Assignments (15)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 12, 2024
From: CITRIX SYSTEMS, INC.
To: PROGRESS SOFTWARE CORPORATION
Reel/Frame 069571/0001 →
RELEASE OF CERTAIN PATENT SECURITY INTERESTS AT REEL/FRAME 062112/0262 Recorded Nov 2, 2024
From: BANK OF AMERICA, N.A.
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 069291/0492 →
RELEASE OF CERTAIN PATENT SECURITY INTERESTS AT REEL/FRAME 063340/0164 Recorded Nov 2, 2024
From: WILMINGTON TRUST, NATIONAL ASSOCIATION
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 069291/0503 →
RELEASE OF CERTAIN PATENT SECURITY INTERESTS AT REEL/FRAME 062113/0470 Recorded Nov 2, 2024
From: WILMINGTON TRUST, NATIONAL ASSOCIATION
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 069291/0514 →
RELEASE OF CERTAIN PATENT SECURITY INTERESTS AT REEL/FRAME 062079/0001 Recorded Nov 2, 2024
From: WILMINGTON TRUST, NATIONAL ASSOCIATION
To: CITRIX SYSTEMS, INC.
Reel/Frame 069291/0536 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 21, 2019
From: INTELLECTUAL VENTURES ASSETS 131 LLC
To: CITRIX SYSTEMS, INC.
Reel/Frame 049242/0574 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 17, 2019
From: INTELLECTUAL VENTURES I LLC
To: INTELLECTUAL VENTURES ASSETS 131 LLC
Reel/Frame 049214/0747 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 6, 2019
From: PSS SYSTEMS, INC.
To: GUARDIAN DATA STORAGE, LLC
Reel/Frame 049090/0819 →
MERGER Recorded Feb 4, 2016
From: GUARDIAN DATA STORAGE LLC
To: INTELLECTUAL VENTURES I LLC
Reel/Frame 037667/0273 →
Continuity (2)
Division 10815251 · Mar 30, 2004
Related Publication 20140101457A1 · Apr 10, 2014