IP Library Granted Patent US 9,871,773
Granted Patent B2
US 9,871,773 · App. 14/755,622 · Granted Jan 16, 2018

Method and system for digital rights management of documents

Inventors: Patrick Carson Meehan (Seattle, WA); Zachary Wisenbaker Price (Seattle, WA); Raymond Joseph Zambroski, Jr. (Seattle, WA); William Henry Frenchu (Seattle, WA); Shawn Patrick Hickey (Seattle, WA); Jesse Lee White (Bellevue, WA); Anthony Allen Mohr (Bellevue, WA); Jeremy Wayne Gomsrud (Bellevue, WA)
Assignee: Encryptics, LLC
H04L63/0435G06F21/10H04L9/0861H04L9/3247H04L9/3263H04L63/061G06F2221/2101G06F2221/2137
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,871,773
App. No.
14/755,622
Granted
Jan 16, 2018
Kind
B2
Abstract

A method and system for transmission of digital content via e-mail with point of use digital rights management is disclosed. The secured access rights to the digital content may be customized for individual recipients by the sender, and may evolve over time. The access rights are enforced according to a time-dependent scheme. A key server is used to arbitrate session keys for the encrypted content, eliminating the requirement to exchange public keys prior to transmission of the digital content. During the entire process of transmitting and receiving e-mail messages and documents, the exchange of cryptographic keys remains totally transparent to the users of the system. Additionally, electronic documents may be digitally signed with authentication of the signature.

Claims (43)

1. A method comprising, on at least one computer system:

generating a first symmetric session key for a cryptocontainer;

encrypting, in a first section of the cryptocontainer, a recipient list and the first symmetric session key using a second symmetric session key;

generating a usage rights timeline for each of one or more electronic documents;

encrypting, in a second section of the cryptocontainer, the one or more electronic documents, and each said usage rights timeline using the first symmetric session key;

encrypting the second session key in the cryptocontainer using a public key belonging to a key server;

wherein the cryptocontainer enables the recipient list to be individually decrypted from the cryptocontainer separately from the one or more electronic documents; and

transmitting the cryptocontainer over a communications network to each recipient in the recipient list of the cryptocontainer.

2. The method as recited in claim 1 , wherein the usage rights timeline comprises keyframes for digital rights management for each of the one or more electronic documents in the cryptocontainer, wherein each of the keyframes comprises individual entries for granting rights for opening, copying, viewing, printing, exporting, deleting, making visible, showing thumbnails, renaming, forwarding, attaching, and moving each of the one or more electronic documents in the cryptocontainer for a certain period in time.

3. The method as recited in claim 1 , wherein a recipient is assigned membership to a user group, wherein the user group is selected for generating a usage permission template for each of the one or more electronic documents.

4. The method as recited in claim 1 , further comprising:

recording a timestamped log of each individual operation performed on the cryptocontainer.

5. The method as recited in claim 1 , wherein each said usage rights timeline is predefined and stored as a template for retrieving a set of usage rights for applying to a cryptocontainer.

6. A method for receiving electronic documents over a communications network, wherein digital rights of access for each of the electronic documents are cryptographically managed and secured, comprising, by a computer system:

electronically receiving a cryptocontainer comprising:

an encrypted first section including a recipient list and a first symmetric key, wherein the encrypted first section has been encrypted using a second symmetric key;

an encrypted second section comprising one or more electronic documents, wherein the encrypted second section has been encrypted using the first symmetric session key; and

an encrypted key portion comprising the second symmetric key, wherein the encrypted key portion has been encrypted using a public key of a key server;

opening a secured connection with the key server and authenticating an identity of a recipient with a certificate issued by an authenticating server; and

comparing the identity of the recipient with each of a plurality of recipients listed in the recipient list by the key server, and in case of a match,

issuing a one-time license to decrypt the first symmetric session key to the recipient by the key server,

and in case of no match,

denying access to the recipient to the cryptocontainer.

7. The method as recited in claim 6 , wherein the authenticating the identity of the recipient is performed using a hardware fingerprint together with an electronic address of the recipient.

8. The method as recited in claim 6 , wherein the authenticating the identity of the recipient is performed using a biometric identifier together with an electronic address of the recipient.

9. The method as recited in claim 6 , further comprising:

decrypting the symmetric session key for the cryptocontainer with the one-time license; and

decrypting and accessing the one or more electronic documents by the recipient from the cryptocontainer.

10. The method as recited in claim 9 , further comprising:

recording a timestamped log of each individual operation performed on the cryptocontainer.

11. A computer program product comprising a non-transitory computer-usable medium having computer-readable code embodied therein, the computer-readable code adapted to be executed to implement a method comprising:

generating a first symmetric session key for a cryptocontainer;

encrypting, in a first section of the cryptocontainer, a recipient list and the first symmetric session key using a second symmetric session key;

generating a usage rights timeline for each of one or more electronic documents;

encrypting, in a second section of the cryptocontainer, the one or more electronic documents and each said usage rights timeline using the first symmetric session key;

encrypting the second session key in the cryptocontainer using a public key belonging to a key server; and

wherein the cryptocontainer enables the recipient list to be individually decrypted from the cryptocontainer separately from the one or more electronic documents;

transmitting the cryptocontainer over a communications network to each recipient in the recipient list of the cryptocontainer.

12. The computer program product as recited in claim 11 , wherein the usage rights timeline comprises keyframes for digital rights management for each of the one or more electronic documents in the cryptocontainer, wherein each of the keyframes comprises individual entries for granting rights for opening, copying, viewing, printing, exporting, deleting, making visible, showing thumbnails, renaming, forwarding, attaching, and moving each of the one or more electronic documents in the cryptocontainer for a certain period in time.

13. The computer program product as recited in claim 11 , wherein a recipient is assigned membership to a user group, wherein the user group is selected for generating a usage permission template for each of the one or more electronic documents.

14. The computer program product as recited in claim 11 , the method comprising:

recording a timestamped log of each individual operation performed on the cryptocontainer.

15. The computer program product as recited in claim 11 , wherein each said usage rights timeline is predefined and stored as a template for retrieving a set of usage rights for applying to a cryptocontainer.

Assignments (5)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 15, 2020
From: ENCRYPTICS, LLC
To: KEYAVI DATA CORP
Reel/Frame 053771/0114 →
CHANGE OF NAME Recorded May 4, 2016
From: NL SYSTEMS LLC
To: ENCRYPTICS, LLC
Reel/Frame 038610/0066 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 15, 2015
From: ECFLP IP, LLC
To: NL SYSTEMS, LLC
Reel/Frame 036095/0157 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 8, 2015
From: ESSENTIAL SECURITY SOFTWARE, INC.
To: ECFLP IP, LLC
Reel/Frame 036076/0792 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 6, 2015
From: MEEHAN, PATRICK CARSON; PRICE, ZACHARY WISENBAKER; ZAMBROSKI, RAYMOND JOSEPH, JR.; FRENCHU, WILLIAM HENRY; HICKEY, SHAWN PATRICK; WHITE, JESSE LEE; MOHR, ANTHONY ALLEN; GOMSRUD, JEREMY WAYNE
To: ESSENTIAL SECURITY SOFTWARE, INC.
Reel/Frame 035995/0158 →
Continuity (4)
Continuation 14162979 · Jan 24, 2014
Continuation 13538637 · Jun 29, 2012
Continuation 11237564 · Sep 28, 2005
Related Publication 20160028700A1 · Jan 28, 2016