IP Library › Granted Patent US 9,590,971
Granted Patent B2
US 9,590,971 · App. 15/236,649 · Granted Mar 7, 2017

Environment-aware security tokens

Inventor: Robert G. Caffary, Jr. (Jewett City, CT)
Assignee: Document Dynamics, LLC
H04L63/08G06F21/6218H04L9/14H04L9/30H04L63/06H04L63/0807H04L63/10H04L63/102H04L63/20G06F2221/2143H04L9/006H04L63/0815H04L67/306H04L2209/56
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,590,971
App. No.
15/236,649
Granted
Mar 7, 2017
Kind
B2
Abstract

The technology described in this document can be embodied in a computer implemented method that includes receiving, at a processing device, information about one or more assets associated with a network of devices. The method also includes generating, for at least one of the assets, a security token that is based at least on a portion of the received information about the corresponding asset. The security token can be configured to identify a home network defined for the asset, and to restrict access to the corresponding asset upon detecting an occurrence of an unauthorized activity involving the asset. The method further includes storing, in a storage device, information about the security token and information linking the security token to the corresponding asset, and initiating integration of the security token with the corresponding asset.

Claims (55)

1. A computer implemented method comprising:

storing a copy of an electronic file at a first storage location that is authenticated to be a part of a home network associated with the electronic file, wherein the electronic file includes a security token, and the security token is configured to:

authenticate an attempt to access the electronic file,

restrict access to the electronic file upon determining the attempt to be originating from outside the home network, and

allow access to the electronic file in accordance with a security policy upon determining the attempt to be originating from within the home network;

obtaining, at one or more computing devices communicably coupled to the home network, information about changes to the electronic file as a result of the attempt;

updating, by the one or more computing devices, another copy of the electronic file stored at a second storage location; and

storing, by the one or more computing devices on a storage device of a file system, data representing the attempt to access the electronic file.

2. The method of claim 1 , wherein the first storage location is a part of a distributed storage system.

3. The method of claim 1 , wherein the first storage location is a part of a virtual machine of a cloud-based system.

4. The method of claim 1 , wherein the security token is configured to authenticate the attempt by determining that at least one of (i) a user-profile or (ii) a device profile associated with the attempt is associated with the home network.

5. The method of claim 1 , wherein information about the security policy is encoded into the security token, the security policy comprising information about access privileges associated with the electronic file.

6. The method of claim 5 , wherein the access privileges are specific to a user-profile or device-profile associated with the home network.

7. The method of claim 1 , wherein the security token comprises information about a global unit identifier (GUID) associated with the electronic file.

8. The method of claim 1 , wherein the security token comprises an object generated in accordance with Component Object Model (COM).

9. The method of claim 1 , wherein the security token is generated in accordance with one or more security policies associated with the corresponding asset.

10. The method of claim 1 , wherein the security token is configured to restrict access to the electronic file by deleting content of the electronic file upon determining the attempt to be originating from outside the home network.

11. The method of claim 1 , wherein the security token is configured to restrict access to the electronic file upon determining a dissociation of the electronic file from the home network.

12. The method of claim 1 , wherein the security token is included in a header portion of the electronic file or encapsulated with the electronic file in an executable file.

13. The method of claim 1 , wherein the electronic file comprises an electronic document, and the security token is embedded into a page description language of the document.

14. The method of claim 1 , wherein the copy at the second storage location is updated upon receiving an approval for the changes.

15. A system comprising:

memory; and

one or more processors configured to:

store a copy of an electronic file at a first storage location authenticated to be a part of a home network associated with the electronic file, wherein the electronic file includes a security token configured to:

authenticate an attempt to access the electronic file,

restrict access to the electronic file upon determining the attempt to be originating from outside the home network, and

allow access to the electronic file in accordance with a security policy upon determining the attempt to be originating from within the home network;

obtain information about changes to the electronic file as a result of the attempt;

update another copy of the electronic file stored at a second storage location; and

storing on a storage device of a file system, data representing the attempt to access the electronic file,

wherein the one or more processors are communicably coupled to the home network.

16. The system of claim 15 , wherein the first storage location is a part of a distributed storage system.

17. The system of claim 15 , wherein the first storage location is a part of a virtual machine of a cloud-based system.

18. The system of claim 15 , wherein the security token is configured to authenticate the attempt by determining that at least one of (i) a user-profile or (ii) a device profile associated with the attempt is associated with the home network.

19. The system of claim 15 , wherein information about the security policy is encoded into the security token, the security policy comprising information about access privileges associated with the electronic file.

20. The system of claim 19 , wherein the access privileges are specific to a user-profile or device-profile associated with the home network.

21. The system of claim 15 , wherein the security token comprises information about a global unit identifier (GUID) associated with the electronic file.

22. The system of claim 15 , wherein the security token comprises an object generated in accordance with Component Object Model (COM).

23. The system of claim 15 , wherein the security token is generated in accordance with one or more security policies associated with the corresponding asset.

24. The system of claim 15 , wherein the security token is configured to restrict access to the electronic file by deleting content of the electronic file upon determining the attempt to be originating from outside the home network.

25. The system of claim 15 , wherein the security token is configured to restrict access to the electronic file upon determining a dissociation of the electronic file from the home network.

26. The system of claim 15 , wherein the security token is included in a header portion of the electronic file or encapsulated with the electronic file in an executable file.

27. The system of claim 15 , wherein the electronic file comprises an electronic document, and the security token is embedded into a page description language of the document.

28. The system of claim 15 , wherein the copy at the second storage location is updated upon receiving an approval for the changes.

29. One or more machine-readable storage devices storing instructions that are executable by one or more processing devices to perform operations comprising:

storing a copy of an electronic file at a first storage location authenticated to be a part of a home network associated with the electronic file, wherein the electronic file includes a security token configured to:

authenticate an attempt to access the electronic file,

restrict access to the electronic file upon determining the attempt to be originating from outside the home network, and

allow access to the electronic file in accordance with a security policy upon determining the attempt to be originating from within the home network;

obtaining information about changes to the electronic file as a result of the attempt;

updating another copy of the electronic file stored at a second storage location; and

storing on a storage device of a file system, data representing the attempt to access the electronic file,

wherein the one or more processing devices are communicably coupled to the home network.

30. The one or more machine-readable storage devices of claim 29 , wherein the first storage location is a part of a distributed storage system, or a part of a virtual machine of a cloud-based system.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 30, 2016
From: CAFFARY, ROBERT G., JR.
To: DOCUMENT DYNAMICS, LLC
Reel/Frame 039582/0509 →
Continuity (2)
Continuation 14456777 · Aug 11, 2014
Related Publication 20160352718A1 · Dec 1, 2016