IP Library Granted Patent US 9,727,739
Granted Patent B2
US 9,727,739 · App. 14/336,216 · Granted Aug 8, 2017

Decrypting files for data leakage protection in an enterprise network

Inventors: Ya Hsuan Tsai (Taipei, TW); Ying-Hung Yu (Taipei, TW); Mahadevan Hariharan (Taipei, TW)
Assignee: International Business Machines Corporation
G06F21/60G06F21/50G06F21/606H04L63/0227H04L63/0428H04L63/1408
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,727,739
App. No.
14/336,216
Granted
Aug 8, 2017
Kind
B2
Abstract

Techniques are provided for decrypting an encrypted file within an enterprise network. The techniques include identifying by a password collecting module a password entered during a file encryption procedure performed at a terminal and storing the password; receiving an encrypted file by a data leakage protection (DLP) module; and attempting to decrypt the encrypted file with the password by the DLP module.

Claims (53)

1. A method for providing data leak protection (DLP), comprising:

monitoring an application executed at a terminal;

monitoring a procedure performed with a predetermined application executed at the terminal to determine that an encrypted file is in the process of being transmitted from the terminal; and,

in response to determining that the encrypted file is being transmitted from the terminal, identifying a password entered by users for a file encryption procedure performed with the predetermined application that decrypts the encrypted file;

decrypting the encrypted file to generated a decrypted file;

identifying meta data of the encrypted file, wherein the decrypting comprises selecting the password by determining that the meta data of the encrypted file matches at least a portion of meta data of the password;

determining that the decrypted file is a file subject to DLP; and

in response to determining that the decrypted file is a the subject to DLP, preventing the transmitting of the file from the terminal.

2. The method of claim 1 , wherein the identifying further comprises identifying meta data of the password.

3. The method of claim 1 , further comprising:

receiving an encrypted file from the terminal; and

decrypting the encrypted file with the password.

4. The method of claim 3 , wherein the decrypting is performed in a real-time manner.

5. The method of claim 3 , wherein the decrypting comprises decrypting the encrypted file with multiple passwords obtained by executing the method of claim 1 two or more times.

6. The method of claim 5 , wherein the receiving an encrypted file further comprises identifying meta data of the encrypted file, wherein the decrypting further comprises determining priority given to attempting to decrypt with each password according to meta data of the multiple passwords obtained by executing the method of claim 2 several times.

7. The method of claim 5 , wherein the receiving an encrypted file further comprises identifying meta data of the encrypted file, wherein the decrypting further comprises determining a degree of match between meta data of the encrypted file and meta data of the multiple passwords obtained by executing the method of claim 2 several times, so as to determine priority given to a decryption performed with each password.

8. An apparatus for providing data leak protection (DLP), comprising:

a processor;

a non-transitory, computer-readable medium coupled to the processor; and

logic, stored on the computer-readable medium and executed on the processor, for:

monitoring an application executed at a terminal;

monitoring a procedure performed with a predetermined application executed at the terminal to determine that an encrypted file is in the process of being transmitted from the terminal; and

in response to determining that the encrypted file is being transmitted from the terminal, identifying a password entered by users for a file encryption procedure performed with the predetermined application that decrypts the encrypted file;

decrypting the encrypted file to generated a decrypted file;

identifying meta data of the encrypted file, wherein the decrypting comprises selecting the password by determining that the meta data of the encrypted file matches at least a portion of meta data of the password;

determining that the decrypted file is a file subject to DLP; and

in response to determining that the decrypted file is a file subject to DLP, preventing the process of transmitting the file from the terminal.

9. The apparatus of claim 8 , wherein the logic for identifying further comprises logic for identifying meta data of the password.

10. The apparatus of claim 8 , the logic further comprising logic for:

determining that a second encrypted file is in the process of being transmitted from the terminal;

decrypting the second encrypted file with the password to generate a second decrypted file;

determining that the second decrypted file in not a file subject to DLP; and

in response to determining that the second file is not a file subject to DLP, enabling the process of transmitting the second encrypted file from the terminal.

11. The apparatus of claim 8 , wherein the decrypting is performed in a real-time manner.

12. The apparatus of claim 8 , wherein the logic for decrypting comprises logic for decrypting the encrypted file with multiple passwords obtained by executing the logic of claim 8 two or more times.

13. A computer programming product for providing data leak protection (DLP), comprising:

a non-transitory, computer-readable medium; and

logic, stored on the computer-readable medium for execution on a processor, for:

monitoring an application executed at a terminal;

monitoring a procedure performed with a predetermined application executed at the terminal to determine that an encrypted file is in the process of being transmitted from the terminal; and,

in response to determining that the encrypted file is being transmitted from the terminal, identifying at password entered by users for a file encryption procedure performed with the predetermined application that decrypts the encrypted file;

decrypting the encrypted file to generated a decrypted file;

identifying meta data of the encrypted file, wherein the decrypting comprises selecting the password by determining that the meta data of the encrypted file matches at least a portion of meta data of the password;

determining that the decrypted file is a file subject to DLP; and

in response to determining that the decrypted file is a file subject to DLP, preventing the process of transmitting the file from the terminal.

14. The computer programming product of claim 13 , wherein the logic for identifying further comprises logic for identifying meta data of the password.

15. The computer programming product of claim 13 , the logic further comprising logic for:

determining that a second encrypted file is in the process of being transmitted from the terminal;

decrypting the second encrypted file with the password to generate a second decrypted file;

determining that the second decrypted file in not a file subject to DLP; and

in response to determining that the second file is not a file subject to DLP, enabling the process of transmitting the second encrypted file from the terminal.

16. The computer programming product of claim 13 , wherein the decrypting is performed in a real-time manner.

17. The computer programming product of claim 13 , wherein the logic for decrypting comprises logic for decrypting the encrypted file with multiple passwords obtained by executing the logic of claim 13 two or more times.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 21, 2014
From: TSAI, YA-HSUAN; YU, YING-HUNG; HARIHARAN, MAHADEVAN
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 033352/0250 →
Priority Claims (1)
TW 101151161 A · Dec 28, 2012 · national
Continuity (2)
Continuation 14142155 · Dec 27, 2013
Related Publication 20140344573A1 · Nov 20, 2014