Nova Patents
EP1369801A1

An information management system

Abstract

An information management system is described comprising one or more workstations running applications which allow a user of the workstation to connect to a network, such as the Internet. Each application has an analyser, which monitors transmission data that the application is about to transmit to the network or has just received from the network, and which determines an appropriate action to take regarding that data. The analyser may consult policy data containing a supervisor-defined policy to govern the workstations in order to determine what action to take. Such actions may be extracting data from the transmission data, such as passwords and usernames, digital certificates or eCommerce transaction details for storage and record keeping; ensuring that the transmission data is transmitted at an encryption strength appropriate to the contents of the transmission data; determining whether a check needs to be made as to whether a digital certificate received in transmission data is valid; determining whether a transaction about to be made by a user of one of the workstations needs third party approval before it is made; and controlling the transmission of messages, such as e-mails according to a policy.

EP1369801A1, drawing sheet 1
Sheet 1 of 27

Term

Term ended

Projected expiry passed 8 November 2021, 4.9 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

57 claims: 34 independent, 23 dependent

  1. 1
    An information management system comprising:one or more workstations adapted for connection to a computer network, each workstation having a memory;an application stored in said memory of each workstation for transmitting outbound messages to said network and receiving inbound messages from said network;policy data containing rules for determining one or more particulars of the outbound message, and for controlling the transmission of said outbound message in dependence on those particulars;and an analyser, said analyser being operable in conjunction with said policy data to determine one or more particulars of the outbound message and to either selectively require that the message be digitally signed before transmission, or to notify the sender of the message that digitally signing is recommended, or to require that a digitally signed message be transmitted without signature, or to notify the sender of the message digitally signing is not recommended.
  2. 3
    The system of claims 1 or 2, wherein whether the message is required to be digitally signed, whether the digitally signed message is required to be transmitted without signature, whether it is recommended that the message be digitally signed, or whether it is recommended that the digitally signed message be transmitted without signature, are dependent on whether the message contains one or more keywords, or combination of keywords, in a pre-determined list of keywords.
  3. 4
    The system of any preceding claim, wherein whether the message is required to be digitally signed, whether the digitally signed message is required to be transmitted without signature, whether it is recommended that the message be digitally signed, or whether it is recommended that the digitally signed message be transmitted without signature, are dependent on the identity author of the outbound message.
  4. 5
    The system of any preceding claim, wherein whether the digitally signed message is required to be transmitted without signature, or whether it is recommended that the digitally signed message be transmitted without signature, are dependent on the type of digital certificate or signing key used to digitally sign the message.
  5. 6
    The system of any preceding claim, wherein the analyser is operable to determine what digital certificates, or signing keys, are available to digitally sign an outbound message, and    wherein whether the message is required to be digitally signed, whether the digitally signed message is required to be transmitted without signature, whether it is recommended that the message be digitally signed, or whether it is recommended that the digitally signed message be transmitted without signature, are dependent on the type of certificate or signing key used to digitally sign the message, and on the types of digital certificate or signing key available to sign the message.
  6. 7
    The system of any preceding claim, wherein the analyser is further operable to cause the outbound message that is to be forwarded to first be re-directed to a third party for approval, wherein if the third party gives his approval, the outbound message is forwarded to the originally intended recipients in the normal way.
  7. 8
    The system of any preceding claim, wherein said analyser is located on each of said one or more workstations.
  8. 9
    The system of any preceding claim, wherein said application is a web browser.
  9. 12
    The system of any of claims 1 to 8, wherein said application is an e-mail client.
  10. 15
    The system of any of claims 1 to 8, wherein said application is an Instant messaging application.
  11. 17
    The system of any of claims 1 to 8, wherein said application is a Voice Messaging application.
  12. 19
    The system of any of claims 1 to 7, wherein said network includes a server and said analyser is located at a point on said network intermediate said one or more workstations and said server, or said analyser is located at said server.
  13. 20
    A method of managing information comprising the steps of:providing one or more workstations adapted for connection to a computer network, each workstation having a memory;providing an application stored in said memory of each workstation for transmitting outbound messages to said network and receiving inbound messages from said network;providing policy data containing rules for determining one or more particulars of the outbound message, and for controlling the transmission of said outbound message in dependence on those particulars;analysing, in conjunction with said policy data said outbound messages, to determine one or more particulars of said outbound messages, in particular, whether said outbound message is digitally signed;and either selectively requiring that the outbound message be digitally signed before transmission, or that the outbound message, if digitally signed, not be digitally signed;or notifying the sender of the message that digitally signing is recommended, or is not recommended.
  14. 23
    The method of any of claims 20 to 22, wherein whether the message is required to be digitally signed, whether the digitally signed message is required to be transmitted without signature, whether it is recommended that the message be digitally signed, or whether it is recommended that the digitally signed message be transmitted without signature, are dependent on the identity of the author of the outbound message.
  15. 24
    The method of any of claims 20 to 23, wherein whether the digitally signed message is required to be transmitted without signature, or whether it is recommended that the digitally signed message be transmitted without signature, are dependent on the type of digital certificate or signing key used to digitally sign the message.
  16. 25
    The method of any of claims of 20 to 24, comprising determining what digital certificates, or signing keys, are available to digitally sign an outbound message, and    wherein whether the message is required to be digitally signed, whether the digitally signed message is required to be transmitted without signature, whether it is recommended that the message be digitally signed, or whether it is recommended that the digitally signed message be transmitted without signature, are dependent on the type of certificate or signing key used to digitally sign the message, and on the types of digital certificate or signing key available to sign the message.
  17. 26
    The method of any of claims 20 to 25, comprising causing the outbound message that is to be forwarded to first be re-directed to a third party for approval, wherein if the third party gives his approval, the outbound message is forwarded to the originally intended recipients in the normal way.
  18. 27
    The method of any of claims 20 to 26, wherein said analysing step is performed at each of said one or more workstations.
  19. 28
    The method of any of claims 20 to 27, wherein said application is a web browser.
  20. 31
    The method of any of claims 20 to 27, wherein said application is an e-mail client.
  21. 34
    The method of any of claims 20 to 27, wherein said application is an Instant messaging application.
  22. 36
    The method of any of claims 20 to 27, wherein said application is a Voice Messaging application.
  23. 38
    The method of any of claims 20 to 26, wherein said network includes a server and said analysing step is performed at a point on said network intermediate said one or more workstations and said server, or is performed at said server.
  24. 39
    A computer software product, for controlling a computer to manage information, said computer being connected to a network and having access to policy data containing rules for controlling transmission of outbound data to the network, comprising a recording medium readable by the computer, having program code recorded thereon which when executed on said computer configures the computer to:analyse, in conjunction with an application running on said computer that is operable to transmit outbound messages to said network and receive inbound messages from said network, said outbound messages to determine in conjunction with said rules of said policy data one or more particulars of said outbound message;and either selectively require that the outbound message be digitally signed before transmission, or that a digitally signed outbound message not be digitally signed;or notify the sender of the outbound message that digitally signing is recommended, or that in the case of a digitally signed message, digitally signing is not recommended.
  25. 42
    The computer software product of any of claims 39 to 41, wherein whether the message is required to be digitally signed, whether the digitally signed message is required to be transmitted without signature, whether it is recommended that the message be digitally signed, or whether it is recommended that the digitally signed message be transmitted without signature, are dependent on the author of the outbound message.
  26. 43
    The computer software product of any of claims 39 to 42, wherein whether the digitally signed message is required to be transmitted without signature, or whether it is recommended that the digitally signed message be transmitted without signature, are dependent on the type of digital certificate or signing key used to digitally sign the message.
  27. 44
    The computer software product of any of claims 39 to 43, wherein the program code is operable to determine what digital certificates, or signing keys, are available to digitally sign an outbound message, and    wherein whether the message is required to be digitally signed, whether the digitally signed message is required to be transmitted without signature, whether it is recommended that the message be digitally signed, or whether it is recommended that the digitally signed message be transmitted without signature, are dependent on the type of certificate or signing key used to digitally sign the message, and on the types of digital certificate or signing key available to sign the message.
  28. 45
    The computer software product of any of claims 39 to 44, wherein the program code is further operable to cause the outbound message that is to be forwarded to first be re-directed to a third party for approval, wherein if the third party gives his approval, the outbound message is forwarded to the originally intended recipients in the normal way.
  29. 46
    The computer program product of any of claims 39 to 45, wherein said program code is executable at each of said computers.
  30. 47
    The computer program product of any of claims 39 to 46, wherein said application is a web browser.
  31. 50
    The computer program product of any of claims 39 to 46, wherein said application is an e-mail client.
  32. 53
    The computer software product of any of claims 39 to 46, wherein said application is an Instant messaging application.
  33. 55
    The computer software product of any of claims 39 to 46, wherein said application is a Voice Messaging application.
  34. 57
    The computer program product of any of claims 39 to 45, wherein said network includes a server and said program code is executable at a point on said network intermediate said one or more workstations and said server, or said program code is executable at said server.
Independent claims34