Method and apparatus for sharing documents
14 claims: 5 independent, 9 dependent
- 1電子ドキュメントの暗号化及び復号化を行うアカウンタビリティ・ ボールト及び監査エンジン を備えるドキュメント記憶システムにおいて前記電子ドキュメントを安全に共有するための方法であって、 前記アカウンタビリティ・ボールトによって、 作成ユーザに関連する電子ドキュメントに特有の暗号キーを生成し、 暗号化された電子ドキュメントを生成するよう、前記暗号キーを用いて前記電子ドキュメントを暗号化し、 前記暗号化された電子ドキュメントを記憶するよう構成されたドキュメント・レポジトリに前記暗号化された電子ドキュメントを送り、 前記暗号化された電子ドキュメントの記憶場所を一意に特定するよう構成されたリソース・ロケータを特定し、 前記暗号キー及び前記リソース・ロケータを前記作成ユーザに送り、前記暗号キーを送った後に、該暗号キーの記録が前記ドキュメント記憶システムに保持されないようにし、 前記暗号キー及び前記リソース・ロケータを要求ユーザから受け取り、 前記リソース・ロケータを用いて前記ドキュメント・レポジトリから前記暗号化された電子ドキュメントを取り出し、 前記暗号キーを用いて前記暗号化された電子ドキュメントを復号化し、 前記復号化された電子ドキュメントを前記要求ユーザに送り、 前記監査エンジンによって、 不正な変更を検出するよう周期的に前記アカウンタビリティ・ ボールト を監査する 方法。
- 2前記暗号キー及び前記リソース・ロケータを前記作成ユーザに送ることは、前記暗号キー及び前記リソース・ロケータの両方を単一のURLにおいて伝えることを含む、 請求項1に記載の方法。
- 3前記暗号キー及び前記リソース・ロケータを前記作成ユーザに送ることは、テキストフォーマットにおいて伝えることを含む、 請求項1に記載の方法。
- 4前記暗号キー及び前記リソース・ロケータを前記作成ユーザに送り、前記暗号キーを送った後に、該暗号キーの記録が前記ドキュメント記憶システムに保持されないようにすることは、前記ドキュメント記憶システムによって以前に保持された暗号キーの如何なるコピーも破棄することを含む、 請求項1に記載の方法。
- 5前記ドキュメント記憶システムは、 更に ポリシー・エンジンを有し 、 前記ポリシー・エンジンによって、 前記要求ユーザが前記電子ドキュメントにアクセスしてよいかどうかを定義する1以上の属性を有する所定のポリシーを前記作成ユーザから受け取り、 前記要求ユーザが前記電子ドキュメントにアクセスしてよいかどうかを決定するよう、前記要求ユーザに関連する1以上の属性に前記所定のポリシーを適用する、 請求項1に記載の方法。
- 6前記アカウンタビリティ・ ボールト を監査することは、 ランタイムより前に前記アカウンタビリティ・ボールトの第1のスナップショットをセーブし、 ランタイムの間に前記アカウンタビリティ・ボールトの第2のスナップショットをセーブし、 前記第1のスナップショットと前記第2のスナップショットとを比較し、 前記第1のスナップショットと前記第2のスナップショットとが一致しない場合は、エラーメッセージを送る ことを含む、請求項1乃至5のうちいずれか一項に記載の方法。
- 7前記第1のスナップショット及び前記第2のスナップショットは、前記アカウンタビリティ・ボールトに関連するハッシュ値を有する、 請求項6に記載の方法。
- 8電子ドキュメントを安全に共有するドキュメント記憶システムであって、 アカウンタビリティ・ボールトと、不正な変更を検出するよう周期的に前記アカウンタビリティ・ボールトを監査するよう構成される監査エンジンとを有し、 該アカウンタビリティ・ボールトは、 作成ユーザに関連する電子ドキュメントに特有の暗号キーを生成し、 暗号化された電子ドキュメントを生成するよう、前記暗号キーを用いて前記電子ドキュメントを暗号化し、 当該アカウンタビリティ・ボールトに通信上結合され、前記暗号化された電子ドキュメントを記憶するよう構成されたドキュメント・レポジトリに前記暗号化された電子ドキュメントを送り、 前記暗号化された電子ドキュメントの記憶場所を一意に特定するよう構成されたリソース・ロケータを特定し、 前記暗号キー及び前記リソース・ロケータを前記作成ユーザに送り、 前記暗号キーを送った後に、該暗号キーの記録が前記ドキュメント記憶システムに保持されないようにし、 前記暗号キー及び前記リソース・ロケータを要求ユーザから受け取り、 前記リソース・ロケータを用いて前記ドキュメント・レポジトリから前記暗号化された電子ドキュメントを取り出し、 前記暗号キーを用いて前記暗号化された電子ドキュメントを復号化し、 前記復号化された電子ドキュメントを前記要求ユーザに送る よう構成される、ドキュメント記憶システム。
- 9前記アカウンタビリティ・ボールトは、更に、前記暗号キー及び前記リソース・ロケータの両方を単一のURLにおいて送ることによって、前記暗号キー及び前記リソース・ロケータを前記作成ユーザに送るよう構成される、 請求項8に記載のドキュメント記憶システム。
- 10前記アカウンタビリティ・ボールトは、更に、テキストフォーマットにおいて送ることによって、前記暗号キー及び前記リソース・ロケータを前記作成ユーザに送るよう構成される、 請求項8に記載のドキュメント記憶システム。
- 11前記アカウンタビリティ・ボールトは、更に、前記ドキュメント記憶システムによって保持されている暗号キーの如何なるコピーも破棄するよう構成される、 請求項8に記載のドキュメント記憶システム。
- 12ポリシー・エンジンを更に有し、 該ポリシー・エンジンは、 前記要求ユーザが前記電子ドキュメントにアクセスしてよいかどうかを定義する1以上の属性を有する所定のポリシーを前記作成ユーザから受け取り、 前記要求ユーザが前記電子ドキュメントにアクセスしてよいかどうかを決定するよう、前記要求ユーザに関連する1以上の属性に前記所定のポリシーを適用する よう構成される、請求項8に記載のドキュメント記憶システム。
- 13前記監査エンジンは、更に、 ランタイムより前に前記アカウンタビリティ・ボールトの第1のスナップショットをセーブし、 ランタイムの間に前記アカウンタビリティ・ボールトの第2のスナップショットをセーブし、 前記第1のスナップショットと前記第2のスナップショットとを比較し、 前記第1のスナップショットと前記第2のスナップショットとが一致しない場合は、エラーメッセージを送る よう構成される、請求項8乃至12のうちいずれか一項に記載のドキュメント記憶システム。
- 14前記第1のスナップショット及び前記第2のスナップショットは、前記アカウンタビリティ・ボールトに関連するハッシュ値を有する、 請求項13に記載のドキュメント記憶システム。
Independent claims14
29 paragraphs, as filed
The present invention generally relates to communication systems, more specifically methods and devices for sharing electronic documents within communication systems.
When sharing electronic documents in a networked environment, whether on the insecure Internet or on a private intranet, it is possible to allow document authors to share documents only with selected groups of other users or devices. desirable. Such security is especially desirable if the electronic document contains information that deals with personal or confidential information. Several methods exist to verify the identity of a user attempting to gain access to a shared electronic document (eg, a username and password combination, and a public / private key combination).
According to these various security methods, it is often for the creator or administrator of an electronic document to hold the security certificate and / or send the required certificate to the user requesting access to the electronic document. It's awkward. In addition, a particular user (eg, a system administrator) may have access to all documents stored in a centralized document repository. Such storage locations are often used in the sharing of electronic documents, and the access required by a particular user to maintain a technical environment also improperly accesses documents stored within that environment. May also be used to.
As more and more electronic documents are stored remotely and access to their data through various services becomes more and more important, only those who want to protect the contents of those documents and allow access to them by the author. Allowing access is correspondingly important.
<p num="0005"> The present disclosure provides methods and devices for secure document sharing that substantially eliminate or reduce at least some of the drawbacks and problems associated with the methods and systems described above.</p>
<p num="0006"> According to one embodiment, a method for securely sharing an electronic document in a document storage system is to receive the electronic document from the creator, generate an encryption key specific to the electronic document, and generate an encrypted electronic document. The encrypted electronic document may be encrypted using the encryption key and sent to the document repository for storage. The method may further identify a resource locator configured to uniquely identify the storage location of the encrypted electronic document and send the encryption key and the resource locator to the creator. The method further receives the encryption key and the resource locator from the requesting user, uses the resource locator to retrieve the encrypted electronic document from the document repository, and uses the encryption key to encrypt the encrypted electronic document. The decrypted electronic document may be decrypted and the decrypted electronic document may be sent to the requesting user.</p><p num="0007"> Also, accountability. A document storage system that has a vault) and securely shares electronic documents is provided. The accountability vault receives an electronic document from the creator, generates an encryption key specific to the electronic document, encrypts the electronic document using the encryption key to generate an encrypted electronic document, and stores the electronic document. It may be configured to send the encrypted electronic document to the document repository for the purpose. The accountability vault is further configured to identify a resource locator that is configured to uniquely identify the storage location of the encrypted electronic document and send the encryption key and the resource locator to the creator. May be done. The accountability vault further receives the encryption key and the resource locator from the requesting user, uses the resource locator to retrieve the encrypted electronic document from the document repository, and uses the encryption key. It may be configured to decrypt the encrypted electronic document and send the decrypted electronic document to the requesting user.</p><p num="0008"> A technical advantage of certain embodiments of the present disclosure is that it provides a secure means of sharing a document among multiple users in a network environment. More specifically, this approach allows the content of documents shared within the document storage system to be protected from views by administrators or other users with advanced access to the document storage system. In addition, the creator is given increased flexibility and control in determining which other users may be granted access to the contents of the electronic document. Other technical advantages will be readily apparent to those skilled in the art from the figures, descriptions, and claims below. Further, although the specific advantages are listed above, the various embodiments may have all or part of the listed advantages, or may not have such advantages at all.</p><p num="0009"> For a more complete understanding of the present invention and its advantages, see the description below in connection with the accompanying drawings.</p>
<figref num="1">FIG. 3 is a schematic block diagram of an electronic document sharing system according to a particular embodiment of the present disclosure.</figref><figref num="2">FIG. 6 is a schematic block diagram representing various functional components of a document storage system according to a particular embodiment of the present disclosure.</figref><figref num="3">A flowchart of an example of a method for sharing an electronic document in a network environment according to a particular embodiment of the present disclosure is shown.</figref>
FIG. 1 is a schematic block diagram of an electronic document sharing system 100 according to a particular embodiment of the present disclosure. According to the embodiments represented, the electronic document sharing system 100 includes a plurality of users 106 that communicate with the document storage system 108 and communicate with other users 106. The document storage system 108 has an accountability vault 102 and a document repository 104 in some embodiments.
For the purposes of this disclosure, an "electronic document" or "document" is any file that user 106 of electronic document sharing system 100 wants to store and / or share with other users 106 of electronic document sharing system 100. It can be an object code, executable code, a data record, or any other electronically recorded data structure. Examples include text files, spreadsheets, emails, medical records, images, and other electronic data. In addition, user 106 of electronic document sharing system 100 may be a person acting as an end user or a device used by such person to access electronic document sharing system 100 (eg, a personal computer, kiosk, or mobile computer). Device).
In general, components of the electronic document sharing system 100 securely store electronic documents edited by user 106, whereby user 106 and other authenticated users 106 can only give the appropriate encryption key to the authenticated user. Given, the electronic document can be accessed later so that the encryption key is not stored in the document storage system 108. User 106 may create a document and send the document to the document storage system 108 via some suitable network (eg, the Internet or a private intranet). The accountability vault 102 of the document storage system 108 may then encrypt the electronic document using an appropriate encryption scheme, as described in more detail below with reference to FIG. Once encrypted, the electronic document may then be stored in the document repository 104. The document repository 104 may be any suitable database and / or database management system (eg, Oracle Database or IBM's DB2) suitable for use in network document sharing systems.
The Accountability Vault 102 may also send an encryption key for the electronic document to the user who created the document (the "creating user") along with the resource locator. The creating user may be the user 106 who actually created the electronic document, or the user 106 who created the document or gained access to the document in another way, in which case the document storage system 108 stores the document. I want to.
The resource locator may be a reference associated with the electronic document that allows the user 106 to find the electronic document or request access to the electronic document. In some embodiments, the document storage system 108 may be possible on the web by storing each electronic document in a document repository 104 assigned a unique URL (Uniform Resource Locator). By entering this URL into a standard web browser, user 106 can request access to a particular electronic document. In some embodiments, the encryption key and resource locator are sent to user 106 in text format. Such communication can allow the user 106 to share this information with other users 106 in a convenient manner. The key and resource locator transmission between the document storage system 108 and the user 106, or between the user 106 and another user 106, may be in any suitable format (eg, email or SMS).
In some configurations, it is most effective to combine the resource locator and the encryption key into a single communication line. In other configurations, it would be more secure to separate the resource locator and cryptographic key into separate transmissions. In configurations that prefer maximum efficiency, a single transmission (eg, a single URL) is preferred. For example, the URL passed to user 106 may take the form of location + resource locator + encryption key. In the above web-enabled environment, this is: http://web_host/retrieve_document?doc_id=1234&key=19da301afe0231823 It may take the form of an example.
In this example, "web_host" may be the network location of database storage system 108, and "retrieve_document" is the name of a process that can be run on database storage system 108 used to retrieve the desired electronic document. Of course, "doc_id" may be the resource locator specific to the desired electronic document, "1234" may be the value of the resource locator, and "key" may be used by the "retrieve_document" process. It may be an identification display of the encryption key, and "19da301afe0231823" may be the value of the encryption key specific to the desired electronic document. This example is given solely to aid in the understanding of FIG. 1 and should not be construed to limit the teachings of this disclosure in any way.
In another example, the user 106 can identify another user 106 who should receive the resource locator and encryption key when the user 106 stores the electronic document in the document storage system 108. Given the information, the Accountability Vault 102 may, in some embodiments, send the resource locator and encryption key directly to another user previously identified by the user 106. This transmission may take the same form as the transmission to the user 106 above.
The user 106 holding the resource locator and encryption key may contact the document storage system 108 at an appropriate time in an attempt to retrieve the electronic document associated with the resource locator and encryption key. In some embodiments, the accountability vault 102 may receive a resource locator and encryption key from user 106, retrieve the identified document from the document repository 104, and decrypt the document using the encryption key. Once decrypted, Accountability Vault 102 may send the unencrypted document to requesting user 106.
Importantly, in the disclosed embodiments, the encryption key is never within the document storage system 108, except to the extent required to perform encryption and decryption of stored electronic documents. Not remembered. This allows for improvements in the security of the contents of electronic documents stored within the document storage system 108. For example, an administrator or other user with a high degree of privilege with respect to the document storage system 108 cannot read the encrypted electronic document stored in the document repository 104.
FIG. 2 is a schematic block diagram representing various functional components of a document storage system 108 according to a particular embodiment of the present disclosure. The document storage system 108 represented may have an accountability vault 102, a document repository 104, a policy engine 106, and a monitoring engine 110. The various components of the document storage system 108 may, in some embodiments, be software programs that are stored on a computer-readable medium and run by the processor of the document storage system 108. For clarity of description, Figure 2 represents the components as separate modules. In some embodiments, the component may be a stand-alone software program. A component is also a component or subroutine of a larger software program, or a hard-coded computer-readable medium, and / or some hardware of a software module configured to perform a desired function. You may.
The accountability vault 102 may be configured to encrypt and decrypt electronic documents in response to transmission from user 106, as described in more detail above with reference to FIG. In some embodiments, the encryption algorithm used by the Accountability Vault 102 to generate an encryption key is any encryption algorithm that is configured to generate an encryption key specific to an electronic document and is randomly generated. There may be. AES (Advanced Encryption Standard) provides a well-known example of such an encryption algorithm.
In some embodiments, the encrypted document is stored in the document repository 104. The document repository 104 can be any computer-readable memory (eg, a database and / or database management system suitable for use in network document sharing systems such as Oracle Database or IBM's DB2). In some embodiments, the user 106 may also predefine a particular policy applicable to a particular electronic document. Such a policy may define, for example, a set of users 106 who may have access to a document. The addition of such a policy helps improve the security of the contents of electronic documents by denying access to users 106 who receive the resource locator and encryption key by mistake or against the will of the document creator. be able to. Also, certain policies include certain certain attributes of user 106, such as physical location (eg, IP address), specific software installed on the requesting machine (eg, strict antivirus software), bio. Access to a particular document may be defined for the metric identifier, or any other appropriate attribute of user 106.
In some embodiments, the document storage system 108 may further include a monitoring engine 110. For some configurations of the document storage system 108, it may be necessary or desired to store electronic documents as securely as possible. To prevent unintended unauthorized changes by the Accountability Vault 102, the administrator of the document storage system 108 may want to perform periodic monitoring of the Accountability Vault 102. In some embodiments, this monitoring compares the state of the Accountability Vault 102 at a particular point in time (a "snapshot" of the Accountability Vault 102) with the same snapshot taken at a later point in time. May include that. If an unacceptable discrepancy appears in the comparison, the document storage system 108 may send an error message indicating that an unauthorized change may have occurred. Such communication may be directed to the creator or requester, or any other user 106, such as the administrator of the document storage system 108. Alternatively, the transmission may be logged in to an electronic file or other recording mechanism.
In some embodiments, the snapshot of the accountability vault 102 may take the form of a hash value that represents the current state of the accountability vault 102. Such hash values may be determined by a number of well-known methods. The hash value may be configured to represent a particular part of the accountability vault 102 (eg, a cryptographic key generator) or the entire accountability vault 102. Hash values at multiple time points may then be compared to each other. In some configurations of the document storage system 108, it is most appropriate to generate a first hash value as a control value prior to the document storage system 108 runtime. During runtime, a second hash value may be generated for comparison with this control value. The second hash value may be taken at regular intervals according to the particular configuration of the document storage system 108.
FIG. 3 illustrates a flow chart of an example of Method 300 for sharing an electronic document in a network environment according to a particular embodiment of the present disclosure. Method 300 sends a document, encrypts the document, sends a resource locator and encryption key, receives a resource locator and encryption key, decrypts the document, and sends an unencrypted document.
According to one embodiment, method 300 preferably begins at step 302. The teachings of the present disclosure may be implemented in various configurations of the document storage system 108. As such, the preferred starting point for method 300 and the order of steps 302 to 316 that make up method 300 may depend on the practice chosen. Further, the steps of method 300 may be performed in any suitable order other than the order shown.
At step 302, document creation user 106 creates an electronic document for storage in the document storage system 108. Creation User 106 may create, edit, or otherwise modify an electronic document in some embodiments. The creator 106 may then independently upload the electronic document to the document storage system 108, or, in some embodiments, save the electronic document directly to the document storage system 108. After receiving the document, the accountability vault 102 of the document storage system 108 may assign the encryption key to the document in step 304. After assigning the encryption key, method 300 may proceed to step 306. At step 306, the accountability vault 102 may encrypt the received electronic document. After encryption, method 300 may then proceed to step 308. At step 308, the encrypted document is stored in the document repository 104 and assigned a resource locator, as described in more detail above with reference to FIGS. 1 and 2. Method 300 may then proceed to step 310. At step 310, the resource locator and encryption key are sent to user 106. In some embodiments, the user 106 receiving the resource locator and encryption key from the document storage system 108 may be the create user 106 or another user 106 pre-designated by the create user 106. After sending the resource locator and encryption key, method 300 may proceed to step 312.
At step 312, method 300 may receive a request from requesting user 106 for an electronic document stored in document storage system 108. This request may include the resource locator of the electronic document and the encryption key required to decrypt the electronic document. After receiving this request, method 300 may proceed to step 314. At step 314, the accountability vault 102 may retrieve the request document from the document repository 104 and decrypt the retrieved document using the received encryption key. If the encryption key is not the proper encryption key for the retrieved document, the decryption process is unsuccessful. If the encryption process is successful (ie, the encryption key was appropriate for the retrieved document), method 300 may proceed to step 316. In step 316, the decrypted 9 cases may be sent to the requesting user 106. After sending the decrypted document to requesting user 106, method 300 may be terminated.
FIG. 3 discloses a specific number of steps to be performed with respect to method 300, which method 300 may be performed with more or fewer steps than shown in FIG. For example, in some embodiments, method 300 includes a further step of monitoring the accountability vault 102 to ensure its integrity, as described in more detail above with reference to FIG. It's fine. In other embodiments, method 300 may include a step involving matching a document request against a given policy associated with the document, as described in more detail above with reference to FIGS. 1 and 2.
Further, FIG. 3 discloses the steps in a particular order that make up the method 300, but the method 300 may be completed in any suitable order. For example, in the embodiment of method 300 illustrated, the document storage system 108 retrieves the encrypted document from the document repository 104 after receiving a request for the document from requesting user 106. In some configurations where the document storage system 108 receives larger capacity document requests, it is possible to consolidate the document requests and retrieve all of them at the same time while performing other steps of the method during the transaction. It is more efficient.
According to the methods and systems disclosed herein, it is associated with keeping the contents of electronic documents stored in a shared document repository secure and sharing those documents among various users 106. Certain problems can be improved, mitigated, or eliminated. For example, the methods and systems disclosed herein allow for each stored document-specific encryption key that is not stored within the document storage system 108, thereby allowing the administrator or other advanced user of the document storage system 108. Does not have access to the contents of the shared electronic document.
3 sheets
Sheet 1 Sheet 2 Sheet 3
Every citation, both ways
| Document | Relation | Office |
|---|---|---|
| US6978366B1 | Cites | United States of America |
| US6314425B1 | Cites | United States of America |
| JP2005123883A | Cites | Japan |
8 members in 5 offices
Priority claims9
| Document | Office | Kind | Date |
|---|---|---|---|
| 12623861 | United States of America | – | |
| 62386109 | United States of America | A | |
| 62386109 | United States of America | A | |
| 2010055194 | United States of America | W | |
| 2010055194 | United States of America | W | |
| 12623861 | – | – | – |
| US20090623861 | – | – | – |
| US2010055194 | – | – | – |
| WO2010US55194 | – | – | – |
Members8
| Document | Office | Kind | |
|---|---|---|---|
| US2011126008A1 | United States of America | A1 | |
| WO2011062758A1 | World Intellectual Property Organization (WIPO) | A1 | |
| CN102483792A | China | A | |
| EP2504788A1 | European Patent Office (EPO) | A1 | |
| JP2013511771A | Japan | A | |
| US8533469B2 | United States of America | B2 | |
| JP5777630B2This record | Japan | B2 | |
| CN102483792B | China | B |
7 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of no payment of annual feesLAPS | LAPS | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Decision of refusalJAPANESE INTERMEDIATE CODE: A02A02 | A02 | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 |
Numbers
- Publication
- 5777630
- Publication, DOCDB
- 5777630
- Publication, EPODOC
- JP5777630B
- Application
- 2012539927
- Application, DOCDB
- 2012539927
- Application, EPODOC
- JP20120539927
Titles2
- Japanese
- ドキュメント共有のための方法及び装置
- English
- Methods and equipment for document sharing
Classification
- CPC, 2
- G06F21/6218
- G06F2221/2107
- IPC, 3
- G06F21 62
- G06F21 64
- H04L9 08
