IP Library Granted Patent US 10,621,549
Granted Patent B2
US 10,621,549 · App. 13/369,307 · Granted Apr 14, 2020

Method and apparatus for secure enterprise collaboration

Inventors: Yakov Faitelson (Elkana, IL); Ohad Korkus (Herzeliya, IL)
Assignee: VARONIS SYSTEMS, LTD.
G06Q10/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,621,549
App. No.
13/369,307
Granted
Apr 14, 2020
Kind
B2
Abstract

A method for exchanging data between a remote computer and a computerized system remotely connected therebetween, the remote computer having a client application and the computerized system having a storage of objects, a system housekeeping and a service operating on an at least one computer, the method comprising retrieving by the remote computer an object of the storage under the system housekeeping by interaction of the client application with the service, affecting the retrieved object at the remote computer and updating the storage with the affected object, and an apparatus for performing the same.

Claims (40)

1. An apparatus for exchanging data, comprising:

a computerized system having one or more processors, wherein the one or more processors are sharing one or more resources such as a memory, a storage of objects, a system housekeeping that maintains a system audit trail, said system audit trail comprising audit trail records indicative of operations applied to objects in the storage, each audit trail record comprising at least the exact timestamp of the applied operation, and a service operating on an at least one computer;

a remote computer separate from the computerized system and connectable to the computerized system and having a client application, the remote computer configured for generating and maintaining therein a remote housekeeping of objects as a remote audit trail,

the client application and the service are configured for:

retrieving, in accordance with security rules of the computerized system, objects of the storage to the remote computer while the remote computer is connected to the computerized system, wherein the client application of the remote computer controls allowing or blocking transfer of the objects from the computerized system to the remote computer based on the security rules of the computerized system and the client application limits what operations can be performed on the objects and the time when the operations applied to the objects are allowed, and wherein objects that are not from the storage of the computerized system are excluded from being handled by the client application;

regardless of the connection of the remote computer to the computerized system, affecting the retrieved objects at the remote computer by operations applied to the retrieved objects, thereby forming affected objects,

generating a remote audit trail by the remote computer, said remote audit trail comprising audit trail records indicative of the operations applied to the affected object by the remote computer,

upon establishing that the remote computer is connected to the computerized system, updating the storage with the affected objects,

and further updating the system audit trail in the computerized system with the generated remote audit trail according to effect on the affected objects, wherein said updating includes forming a synchronized system audit trail with consecutive timestamps of the applied operations;

wherein the remote computer is configured to deliberately disconnect from the computerized system to save bandwidth, and to deliberately reconnect to update the storage with the affected retrieved objects or synchronize the remote housekeeping of objects related to the affected objects with the system housekeeping,

wherein affecting the retrieved objects is an operation selected from reading, writing, deleting, modifying, copying and storing the retrieved objects and

wherein the computerized system prevents the retrieval of the objects by the remote computer based on the security rules related to the objects.

2. The apparatus according to claim 1 , wherein affecting the objects further comprises maintaining versioning data of the affected objects by the remote computer.

3. The apparatus according to claim 2 , wherein updating the storage comprises updating the storage with the versioning data of the affected objects.

4. The apparatus according to claim 2 , wherein data suitable to construct an earlier version of the affected object is maintained on the remote computer.

5. The apparatus according to claim 1 , wherein affecting the objects is controlled by the service, at least partially, via the remote computer.

6. The apparatus according to claim 1 , wherein the remote computer is connected to the computerized system via a communication link.

7. The apparatus according to claim 1 , wherein regardless of the connection of the remote computer to the computerized system entails prior disconnection of the remote computer from the computerized system.

8. The apparatus according to claim 1 , wherein establishing that the remote computer is connected to the computerized system comprises establishing that the remote computer is connected to the computerized system after disconnection therebetween.

9. The apparatus according to claim 1 , wherein the remote computer is configured to obtain the security rules related to the retrieved objects from the computerized system.

10. The apparatus according to claim 9 , wherein the client application and the service are further configured for controlling operations applied to the retrieved objects by the remote computer, based on the operations that the remote computer is allowed to perform according to the security rules.

11. A method for exchanging data, comprising:

providing a remote computer that is remotely connectable to a computerized system,

the remote computer is separate from the computerized system and configured for generating and maintaining therein a remote housekeeping of objects as a remote audit trail

said remote computer further having a client application, the computerized system having: one or more processors,

wherein the one or more processors are sharing one or more resources such as a memory, a storage of objects, a system housekeeping that maintains a system audit trail, said system audit trail comprising audit trail records indicative of operations applied to objects in the storage, each audit trail record comprising at least the exact timestamp of the applied operation and a service operating on an at least one computer of the computerized system,

while the remote computer is connected to the computerized system, retrieving by the remote computer an object of the storage under the system housekeeping regime by interaction of the client application with the service, wherein the client application of the remote computer controls allowing or blocking transfer of the objects from the computerized system to the remote computer based on security rules of the computerized system and the client application limits what operations can be performed on the objects and the time when the operations applied to the objects are allowed; and wherein objects that are not from the storage of the computerized system are excluded from being handled by the client application;

regardless of the connection of the remote computer to the computerized system, affecting the retrieved object at the remote computer by applying operations on the retrieved object, thereby forming an affected object, and consequently generating the remote audit trail, said remote audit trail comprising audit trail records indicative of the operations applied to the affected object by the remote computer; and

upon establishing that the remote computer is connected to the computerized system, further updating the computerized system with the generated remote audit trail according to effect on the affected objects,

wherein said updating includes forming a synchronized system audit trail with consecutive timestamps of the applied operation;

wherein the remote computer is configured to deliberately disconnect from the computerized system to save bandwidth and deliberately reconnect to update the storage with the affected retrieved objects or synchronize the remote housekeeping objects related to the affected objects with the system housekeeping,

wherein affecting the retrieved objects is an operation selected from reading, writing, deleting, modifying, copying and storing the retrieved objects and

wherein the computerized system prevents the retrieval of the objects by the remote computer based on the security rules related to the objects.

12. The method according to claim 11 , wherein affecting the retrieved object further comprises maintaining versioning data of the affected object by the remote computer.

13. The method according to claim 12 , wherein updating the storage with the affected object further comprises updating the storage with the versioning data of the affected object.

14. The method according to claim 11 , wherein affecting the retrieved object at the remote computer is carried out, at least partially, while the remote computer is not connected to the computerized system.

15. The method according to claim 11 , wherein affecting the retrieved object further comprises affecting the affected object by the remote computer, thereby forming an object that is additionally affected.

16. The method according to claim 11 , wherein regardless of the connection of the remote computer to the computerized system entails prior disconnecting the remote computer from the computerized system.

17. The method according to claim 11 , wherein establishing that the remote computer is connected to the computerized system comprises establishing that the remote computer is connected to the computerized system after having disconnected therebetween.

18. The method according to claim 11 , wherein the object comprises a plurality of objects.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 22, 2022
From: VARONIS SYSTEMS LTD.
To: VARONIS SYSTEMS, INC.
Reel/Frame 059332/0426 →
CORRECTIVE ASSIGNMENT TO CORRECT THE NAME AND ADDRESS OF RECEIVING PARTY(ASSIGNEE) PREVIOUSLY RECORDED ON REEL 027674 FRAME 0758. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT OF ASSIGNORS INTEREST. Recorded Aug 5, 2013
From: FAITELSON, YAKOV; KORKUS, OHAD
To: VARONIS SYSTEMS, LTD.
Reel/Frame 030955/0011 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 9, 2012
From: FAITELSON, YAKOV, MR.; KORKUS, OHAD, MR.
To: VARONIS SYSTEMS, INC.
Reel/Frame 027674/0758 →
Continuity (1)
Related Publication 20130212144A1 · Aug 15, 2013