IP Library Granted Patent US 10,372,929
Granted Patent B1
US 10,372,929 · App. 15/264,200 · Granted Aug 6, 2019

Secure file transfer and notification server

Inventors: John Alan Hensley (Raleigh, NC); Robert Fischer (Durham, NC)
G06F21/6218H04L63/06H04L63/061H04L67/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,372,929
App. No.
15/264,200
Granted
Aug 6, 2019
Kind
B1
Abstract

A system, method and computer readable medium for secure file transfer is disclosed. In one embodiment, the system encrypts a file; sends, via a secure channel, a packet to a group having one or more members, the group authorized to access the encrypted file, the packet associated with the encrypted file and including access information for the encrypted file; receives a first request for the encrypted file from a first requestor; and sends the encrypted file to the first requestor via an unsecured channel that performs caching, wherein the first requestor is able to access the encrypted file using the packet when the first requestor is a member of the group authorized to access the encrypted file and received the packet via the secure channel and unable to access the encrypted file when the first requestor is not a member of the group authorized to access the encrypted file.

Claims (36)

1. A method comprising:

encrypting, using one or more computing devices, a file;

sending, using the one or more computing devices, via a secure channel and separate from the encrypted file, a packet to a group having one or more members, the group authorized to access the encrypted file, the packet associated with the encrypted file and including access information for the encrypted file;

receiving, using the one or more computing devices, a first request for the encrypted file from a first requestor; and

sending, using the one or more computing devices, the encrypted file to the first requestor via an unsecured channel that performs caching of the encrypted file, wherein the first requestor is able to access the encrypted file using the packet when the first requestor is a member of the group authorized to access the encrypted file and received the packet via the secure channel and wherein the first requestor is unable to access the encrypted file when the first requestor is not a member of the group authorized to access the encrypted file.

2. The method of claim 1 , further comprising:

generating, before providing the packet to the group, the packet, the access information comprising identification of the encrypted file with which the packet is associated and a shared key for decrypting the encrypted file with which the packet is associated.

3. The method of claim 1 , further comprising:

sending a notification of an existence of the file to the first requestor, the first requestor located behind a network separation device.

4. The method of claim 3 , wherein the file is a newly created file, the method including determining that the file is newly created and, responsive to determining that the file is newly created file, automatically sending the notification of the existence of the file.

5. The method of claim 3 , wherein the file is a revised version of an existing file, the method including determining that the file is revised version of an existing file and, responsive to determining that the file is the revised version of the existing file, automatically sending the notification of the existence of the file.

6. The method of claim 3 , further comprising:

subsequent to sending the notification of the file, establishing the secure channel for providing the packet to the first requestor located behind the network separation device.

7. The method of claim 1 , wherein a copy of the encrypted file is obtained from a cache of the unsecured channel responsive to a second request for the encrypted file, the second request occurring subsequent to the first request for the encrypted file.

8. The method of claim 1 , wherein the group includes one or more of a persistent group and a file specific group.

9. The method of claim 3 , wherein the network separation device is one or more of a firewall and a network address translator.

10. A system, comprising:

one or more servers executing instructions that cause the one or more servers to:

encrypt a file;

send, via a secure channel and separate from the encrypted file, a packet to a group having one or more members, the group authorized to access the encrypted file, the packet associated with the encrypted file and including access information for the encrypted file;

receive a first request for the encrypted file from a first requestor; and

send the encrypted file to the first requestor via an unsecured channel that performs caching of the encrypted file, wherein the first requestor is able to access the encrypted file using the packet when the first requestor is a member of the group authorized to access the encrypted file and received the packet via the secure channel and unable to access the encrypted file when the first requestor is not a member of the group authorized to access the encrypted file.

11. The system of claim 10 , wherein the one or more servers generate the packet before providing the packet to the group, the access information comprising identification of the encrypted file with which the packet is associated and a shared key for decrypting the encrypted file with which the packet is associated.

12. The system of claim 10 , wherein the one or more servers send a notification of an existence of the file to the first requestor, the first requestor located behind a network separation device.

13. The system of claim 12 , wherein the file is a newly created file, the one or more servers determining that the file is newly created and, responsive to determining that the file is newly created, automatically sending the notification of the existence of the file.

14. The system of claim 12 , wherein the file is a revised version of an existing file, the one or more servers determining that the file is revised version of an existing file and, responsive to determining that the file is the revised version of the existing file, automatically sending the notification of the existence of the file.

15. The system of claim 12 , wherein the one or more servers establish the secure channel for providing the packet to the first requestor located behind the network separation device subsequent to sending the notification of the existence of the file.

16. The system of claim 10 , including a cache of the unsecured channel for caching content sent via the unsecured channel, and wherein a copy of the encrypted file is obtained from the cache of the unsecured channel responsive to a second request of the encrypted file, the second request occurring subsequent to the first request for the encrypted file.

17. The system of claim 10 , wherein the group includes one or more of a persistent group and a file specific group.

18. The system of claim 12 , wherein the network separation device is one or more of a firewall and a network address translator.

19. A non-transitory computing device usable medium including instructions that when executed on a computing device causes the computing device to:

encrypt a file;

send, via a secure channel and separate from the encrypted file, a packet to a group having one or more members, the group authorized to access the encrypted file, the packet associated with the encrypted file and including access information for the encrypted file;

receive a first request for the encrypted file from a first requestor; and

send the encrypted file to the first requestor via an unsecured channel that performs caching of the encrypted file, wherein the first requestor is able to access the encrypted file using the packet when the first requestor is a member of the group authorized to access the encrypted file and received the packet via the secure channel and unable to access the encrypted file when the first requestor is not a member of the group authorized to access the encrypted file.

20. The non-transitory computing device usable medium of claim 19 , wherein the first requestor is located behind a network separation device, the computing device including instructions that when executed notify the first requestor located behind the network separation device of an existence of the file, receive a packet request from the first requestor and send the packet to the first requestor responsive to receiving the packet request and a determination that the first requestor is a member of the group.

Assignments (6)
SECURITY INTEREST Recorded Jul 21, 2025
From: PROGRESS SOFTWARE CORPORATION
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 072094/0790 →
SECURITY INTEREST Recorded Mar 7, 2024
From: PROGRESS SOFTWARE CORPORATION
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 066762/0833 →
SECURITY INTEREST Recorded Jan 25, 2022
From: PROGRESS SOFTWARE CORPORATION
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 058840/0099 →
SECURITY INTEREST Recorded Apr 30, 2019
From: PROGRESS SOFTWARE CORPORATION
To: JPMORGAN CHASE BANK, N.A., ADMINISTRATIVE AGENT
Reel/Frame 049031/0684 →
SECURITY INTEREST Recorded Dec 18, 2017
From: PROGRESS SOFTWARE CORPORATION
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 044889/0325 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 12, 2016
From: HENSLEY, JOHN ALAN; FISCHER, ROBERT
To: PROGRESS SOFTWARE CORPORATION
Reel/Frame 040001/0662 →
Continuity (4)
Continuation 14536468 · Nov 7, 2014
Continuation In Part 14514244 · Oct 14, 2014
Provisional Application 61891290 · Oct 15, 2013
Provisional Application 61904997 · Nov 15, 2013