Document security system that permits external users to gain access to secured files
Claim Score by NHIP
Abstract
A system includes a server with an access manager configured to restrict access to files of an organization and maintain at least encryption keys for internal and external users and an external access server connected to the server and coupled between the server and a data network. The data network is configured to allow the external users use of the external access server. The external access server is also configured to permit file exchange between the internal users and the external users via the server.
Term
Term ended
Expired 30 September 2022, 4 years ago.
- Priority
- Filed
- Granted
- Expired
- Today
27 claims: 4 independent, 23 dependent
- 1A system comprising:a server comprising an access manager configured to : restrict access to a file of an organization having an internal user responsive to a request for the file, the file comprising a header portion including an access rule that restricts access to the file , and a content portion encrypted by a file key;and determine whether a partner relationship exists between the organization and an external partner;a database coupled to the server and configured to store an encryption key for use between the internal user and an the external partner comprising an external user, wherein the access manager is further configured to encrypt the file key, located within security information of the header portion of the file, with the encryption key in response to a determining that the partner relationship existing exists between the organization and the external partner and deny the request in response to determining that the partner relationship does not existing exist ;and an external access server operatively connected to the server and coupled between the server and a data network, the data network configured to allow the external user use of the external access server, wherein the external access server is configured to permit file exchange between the internal user and the external user via the server.
- 8Broadest claimClaim Score 58, broad(NHIP)A method comprising:maintaining, in a database, an encryption key for use between an organization comprising an internal user and an external partner comprising an external user;receiving, by a server coupled to the database, a request to access a file, the file comprising a header portion including an access rule that restricts access to the filer and a content portion encrypted by a file key;determining whether a partner relationship exists between the organization and the external partner;encrypting the file key, located within security information of the header portion, with the encryption key in response to a determining that the partner relationship existing exists between the organization and the external partner;and denying the request in response to determining that the partner relationship does not existing exist .
- 15A computer-readable storage device having instructions stored thereon, execution of which, by a computing device associated with an organization, causes the computing device to perform operations comprising:maintaining an encryption key for use between the organization comprising an internal user and an external partner comprising an external user;receiving a request to access a file at the computing device, the file comprising a header portion including an access rule that restricts access to the file and a content portion encrypted by a file key;determining whether a partner relationship exists between the organization and the external partner;encrypting the file key, located within security information of the header portion, with the encryption key in response to a determining that the partner relationship existing exists between the organization and the external partner;and denying the request in response to determining that the partner relationship does not existing exist .
- 21A system comprising:a server comprising an access manager configured to restrict access to a file of an organization responsive to a request for the file, the file comprising a header portion including an access rule that restricts access to the file, and a content portion encrypted by a file key;a database coupled to the server and configured to store an encryption key associated with an external user, wherein the access manager is further configured to encrypt the file key, located within security information of the header portion of the file, with the encryption key in response to determining that the encryption key associated with the external user is available and deny the request in response to the encryption key not existing;and an external access server operatively connected to the server and coupled between the server and a data network, the data network configured to allow the external user use of the external access server, wherein the external access server is configured to transmit the file to the external user via the data network.
Independent claims4
71 paragraphs in 5 sections, as filed
CROSS-REFERENCE TO RELATED APPLICATION
0001This is a Division of U.S. application Ser. No. 10/262,218, filed Sep. 30, 2002, now allowed, which is hereby incorporated by reference in its entirety for all purposes.
0002U.S. application Ser. No. 10/262,218 is related to U.S. patent application Ser. No. 10/075,194, filed Feb. 12, 2002, now U.S. Pat. No. 8,065,713 issued on Nov. 22, 2011 and entitled “SYSTEM AND METHOD FOR PROVIDING MULTI-LOCATION ACCESS MANAGEMENT TO SECURED ITEMS,” which is hereby incorporated by reference in its entirety for all purposes.
BACKGROUND OF THE INVENTION
00031. Field of the Invention
0004The present invention relates to security systems for data and, more particularly, to security systems that protect data in an inter/intra enterprise environment.
00052. Description of Related Art
0006The Internet is the fastest growing telecommunications medium in history. This growth and the easy access it affords have significantly enhanced the opportunity to use advanced information technology for both the public and private sectors. It provides unprecedented opportunities for interaction and data sharing among businesses and individuals. However, the advantages provided by the Internet come with a significantly greater element of risk to the confidentiality and integrity of information. The Internet is an open, public and international network of interconnected computers and electronic devices. Without proper security measures, an unauthorized person or machine may intercept any information traveling across the Internet, and may even get access to proprietary information stored in computers that interconnect to the Internet, but are otherwise generally inaccessible by the public.
0007As organizations become more dependent on networks for business transactions, data sharing, and everyday communications, their networks have to be increasingly accessible to customers, employees, suppliers, partners, contractors and telecommuters. Unfortunately, as the accessibility increases, so does the exposure of critical data that is stored on the network. Hackers can threaten all kinds of valuable corporate information resources including intellectual property (e.g., trade secrets, software code, and prerelease competitive data), sensitive employee information (e.g., payroll figures and HR records), and classified information (e.g., passwords, databases, customer records, product information, and financial data). Thus data security is becoming increasingly mission-critical.
0008There are many efforts in progress aimed at protecting proprietary information traveling across the Internet and controlling access to computers carrying the proprietary information. Every day hundreds of thousands of people interact electronically, whether it is through e-mail, e-commerce (business conducted over the Internet), ATM machines or cellular phones. The perpetual increase of information transmitted electronically has led to an increased reliance on cryptography.
0009In protecting the proprietary information traveling across the Internet, one or more cryptographic techniques are often used to secure a private communication session between two communicating computers on the Internet. Cryptographic techniques provide a way to transmit information across an unsecure communication channel without disclosing the contents of the information to anyone eavesdropping on the communication channel. An encryption process is a cryptographic technique whereby one party can protect the contents of data in transit from access by an unauthorized third party, yet the intended party can read the data using a corresponding decryption process.
0010Many organizations have deployed firewalls, Virtual Private Networks (VPNs), and Intrusion Detection Systems (IDS) to provide protection. Unfortunately, these various security means have been proven insufficient to reliably protect proprietary information residing on their internal networks. For example, depending on passwords to access sensitive documents from within often causes security breaches when the password of a few characters long is leaked or detected.
0011Enterprise security solutions secure data within an enterprise premise (e.g., internal networks). Some enterprise security solutions prohibit external users (clients) to have any access to secure data. Unfortunately, such enterprise security solutions are not suitable for use in a collaborative environment in which both regular internal users (e.g., employees) and external users (e.g., consultants) need to access some secured data of the enterprise.
0012Thus, there is a need for improved approaches to enable file security systems to permit external users to access secured data without compromising the integrity of an enterprise security system.
SUMMARY OF THE INVENTION
0013The invention relates to an improved system and approaches for exchanging secured files (e.g., documents) between internal users of an organization and external users. A file security system of the organization operates to protect the files of the organization and thus prevents or limits external users from accessing internal documents. Although the external users are unaffiliated with the organization (i.e., not employees or contractors), the external users often have working relationships with internal users. These working relationships (also referred to herein as partner relationships) often present the need for file (document) exchange. According to one aspect of the invention, external users having working relationships with internal users are able to be given limited user privileges within the file security system, such that restricted file (document) exchange is permitted between such internal and external users.
0014The invention can be implemented in numerous ways, including as a method, system, device, and computer readable medium. Several embodiments of the invention are discussed below.
0015An embodiment of the present invention provides a system that includes a server including an access manager configured to restrict access to files of an organization and maintain at least encryption keys for internal and external users and an external access server operatively connected to the server and coupled between the server and a data network. The data network is configured to allow the external users use of the external access server. In addition, the external access server is configured to permit file exchange between the internal users and the external users via the server.
0016Another embodiment of the present invention provides a method that includes restricting access to files in a server including an access manager that restricts access to files of an organization and maintains at least encryption keys for internal and external users, permitting file exchange between the internal users and the external users through an external access server operatively connected to the server and coupled between the server and a data network and using the data network to allow the external users to interact with the external access server.
0017A further embodiment of the present invention provides a computer-readable storage device having instructions stored thereon, execution of which, by a computing device, causes the computing device to perform operations including restricting access to files in a server, including an access manager that restricts access to files of an organization and maintains at least encryption keys for internal and external users, permitting file exchange between the internal users and the external users through an external access server operatively connected to the server and coupled between the server and a data network and using the data network to allow the external users to interact with the external access server.
0018Other objects, features, and advantages of the present invention will become apparent upon examining the following detailed description of an embodiment thereof, taken in conjunction with the attached drawings.
BRIEF DESCRIPTION OF THE DRAWINGS
0019The present invention will be readily understood by the following detailed description in conjunction with the accompanying drawings, wherein like reference numerals designate like structural elements, and in which:
0020<figref idref="DRAWINGS">FIG. 1</figref> is a block diagram of a document security system according to one embodiment of the invention.
0021<figref idref="DRAWINGS">FIG. 2</figref> is a flow diagram of relationship setup processing according to one embodiment of the invention.
0022<figref idref="DRAWINGS">FIG. 3</figref> is a flow diagram of document delivery processing according to one embodiment of the invention.
0023<figref idref="DRAWINGS">FIG. 4</figref> is a flow diagram of document access processing according to one embodiment of the invention.
0024<figref idref="DRAWINGS">FIG. 5</figref> is a flow diagram of access control processing according to one embodiment of the invention.
0025<figref idref="DRAWINGS">FIG. 6</figref> is a flow diagram of client-side document delivery processing according to one embodiment of the invention.
0026<figref idref="DRAWINGS">FIG. 7</figref> is a flow diagram of server-side document delivery processing according to one embodiment of the invention.
0027<figref idref="DRAWINGS">FIG. 8</figref> shows a basic security system in which the invention may be practiced in accordance with one embodiment thereof.
0028<figref idref="DRAWINGS">FIG. 9</figref> shows an exemplary data structure of a secured file that may be used in one embodiment of the invention.
DETAILED DESCRIPTION OF THE INVENTION
0029The invention relates to an improved system and approaches for exchanging secured files (e.g., documents) between internal users of an organization and external users. A file security system of the organization operates to protect the files of the organization and thus prevents or limits external users from accessing internal documents. Although the external users are unaffiliated with the organization (i.e., not employees or contractors), the external users often have working relationships with internal users. These working relationships (also referred to herein as partner relationships) often present the need for file (document) exchange. According to one aspect of the invention, external users having working relationships with internal users are able to be given limited user privileges within the file security system, such that restricted file (document) exchange is permitted between such internal and external users. The invention is suitable for use in an enterprise file security system.
0030A file security system (or document security system) serves to limit access to files (documents) to authorized users. Often, an organization, such as a company, would use a file security system to limit access to its files (documents). For example, users of a group might be able to access files (documents) pertaining to the group, whereas other users not within the group would not be able to access such files (documents). Such access, when permitted, would allow a user of the group to retrieve a copy of the file (document) via a data network.
0031As used herein, a user may mean a human user, a software agent, a group of users, member of a group of users, a device and/or application. Besides a human user who needs to access a secured document, a software application or agent sometimes needs to access secured files in order to proceed. Accordingly, unless specifically stated, the “user” as used herein does not necessarily pertain to a human being.
0032Secured files are files that require one or more keys, passwords, access privileges, etc. to gain access to their content. According to one aspect of the invention, the security is provided through encryption and access rules. The files, for example, can pertain to documents, multimedia files, data, executable code, images and text. In general, a secured file can only be accessed by authenticated users with appropriate access rights or privileges. In one embodiment, each secured file is provided with a header portion and a data portion, where the header portion contains or points to security information. The security information is used to determine whether access to associated data portions of secured files is permitted.
0033In the following description, numerous specific details are set forth in order to provide a thorough understanding of the present invention. However, it will become obvious to those skilled in the art that the invention may be practiced without these specific details. The description and representation herein are the common meanings used by those experienced or skilled in the art to most effectively convey the substance of their work to others skilled in the art. In other instances, well-known methods, procedures, components, and circuitry have not been described in detail to avoid unnecessarily obscuring aspects of the present invention.
0034Reference herein to “one embodiment” or “an embodiment” means that a particular feature, structure, or characteristic described in connection with the embodiment can be included in at least one embodiment of the invention. The appearances of the phrase “in one embodiment” in various places in the specification are not necessarily all referring to the same embodiment, nor are separate or alternative embodiments mutually exclusive of other embodiments. Further, the order of blocks in process flowcharts or diagrams representing one or more embodiments of the invention do not inherently indicate any particular order nor imply any limitations in the invention.
0035Embodiments of the present invention are discussed herein with reference to <figref idref="DRAWINGS">FIGS. 1-9</figref>. However, those skilled in the art will readily appreciate that the detailed description given herein with respect to these figures is for explanatory purposes as the invention extends beyond these limited embodiments.
0036<figref idref="DRAWINGS">FIG. 1</figref> is a block diagram of a document security system <b>100</b> according to one embodiment of the invention. The document security system <b>100</b> is responsible for providing protection of electronic data in an organization and includes a central server <b>102</b> that controls the overall operation of the document security system <b>100</b>. The central server <b>102</b> imposes restrictions on the access to secured documents that are stored centrally or locally.
0037The central server <b>102</b> is assisted by a key store <b>104</b>. Among other things, the key store <b>104</b> can store key pairs (public and private keys). In one embodiment, the key store <b>104</b> can be implemented in a database that stores key pairs (among other things). The central server <b>102</b> is also assisted by local servers <b>106</b> and <b>108</b> that can provide distributed access control. Various internal users to an organization that are utilizing the document security system <b>100</b> interact with the central server <b>102</b> and/or one of the local servers <b>106</b> and <b>108</b>. These internal users are represented by users <b>110</b>-<b>116</b>. As illustrated in the embodiment shown in <figref idref="DRAWINGS">FIG. 1</figref>, user I-A <b>110</b> and user I-B <b>112</b> are affiliated with the local server <b>106</b>, and user I-C <b>114</b> and user I-D <b>116</b> are affiliated with the local server <b>108</b>. It should be understood, however, that various other arrangements or configurations of local servers and users can be utilized.
0038The document security system <b>100</b> also facilitates access by external users to secured documents that are maintained by the document security system <b>100</b>. In this regard, the document security system <b>100</b> includes an external access server <b>118</b>. The external access server <b>118</b> allows external users to be granted access to some of the secured documents. More particularly, the external access server <b>118</b> is coupled between a private network <b>121</b> in the document security system <b>100</b> and a (public) data network <b>120</b> and thus facilitates the access from external users <b>122</b>-<b>128</b> to some of the secured files without compromising the security integrity of the document security system <b>100</b>. The data network <b>120</b> is, for example, a global computer network, a wide area network or a local area network. However, since the external users <b>122</b>-<b>128</b> are not directly affiliated with the organization, the external users are therefore often given limited access rights to some of the secured documents from machines coupled to the data network <b>120</b>. Although the document security system <b>100</b> shown in <figref idref="DRAWINGS">FIG. 1</figref> illustrates multiple local servers <b>106</b> and <b>108</b>, multiple internal users <b>110</b>-<b>116</b>, multiple external users <b>122</b>-<b>128</b>, it should be recognized that the document security system <b>100</b> can, more generally, utilize zero or more local servers, one or more internal users, and one or more external users.
0039According to one embodiment of the invention, external users are permitted to be members of user groups maintained by the central server <b>102</b>. As such, the external users are able to exchange certain secured documents with internal users. In one embodiment, the exchange of the secured documents between internal and external users is limited to exchanges between members of a common user group. Despite document exchange capabilities, the external users are unable to perform various operations with respect to user groups that internal users would be able to perform. For example, external users would be unable to change group membership or to query group membership to determine who are the members of the user group. Typically, an external user would be added to a particular user group when a relationship between the organization and the external user is arranged. The exchange of documents between internal users and external users is secured using public key encryption. The document security system <b>100</b> manages the storage and accessibility of public and private keys for the internal and external users. The document security system <b>100</b> can advantageously minimize the client software needed at the machines utilized by the external users.
0040The invention facilitates exchange of files (e.g., documents) between internal users of an organization and external users. Although the external users are unaffiliated with the organization (i.e., not employees or contractors), the external users often have working relationships with internal users. These working relationships (also referred to herein as partner relationships) often present the need for file (document) exchange. A file security system (e.g., document security system <b>100</b>) of the organization operates to protect the files of the organization and thus prevents or limits external users from accessing internal documents. According to the invention, external users having working relationships with internal users are able to be given limited user privileges within a file security system such that restricted file (document) exchange is permitted between such internal and external users.
0041<figref idref="DRAWINGS">FIG. 2</figref> is a flow diagram of relationship setup processing <b>200</b> according to one embodiment of the invention. The relationship setup processing <b>200</b> operates to arrange or set up a partner relationship between a partner and an organization (e.g., company). The organization is typically represented by an internal user or a group of users, and the partner is typically represented by one or more external users.
0042The relationship setup processing <b>200</b> initially establishes <b>202</b> a partner relationship between a partner and an organization. In this context, the organization is deemed to protect various documents of the organization and its various internal users. In one embodiment, the organization uses a file (document) security system to protect the various documents. The partner is deemed external to the organization. However, the partner is desirous of exchanging documents with the organization. The partner relationship between the partner and the organization (or between respective members thereof) is such that document exchange is permitted so that mutual business objectives can be efficiently achieved. After the partner relationship has been established <b>202</b>, key pairs are created <b>204</b>. The key pairs are used in document exchanges between the partner and the organization (e.g., between respective individuals thereof). For example, each of the partner and the organization would have a public key for encryption, as well as a private key for decryption. For example, to release a document from the organization to the partner, the organization would secure (e.g., encrypt) the document using the public key of the partner and then, upon acquiring the secured document, the partner would unsecure (e.g., decrypt) the secured document using its private key. Similarly, when the partner releases a document to the organization, the partner can secure (e.g., encrypt) the document using the public key of the organization and then, upon acquiring the secured document, the organization can unsecure (e.g., decrypt) the document using its private key. After the key pairs are created <b>204</b>, the key pairs can be stored <b>206</b> to a key store. In one embodiment, the key store is within the file security system. System rights for the partner can then be configured <b>208</b>. The system rights can be configured to permit limited access privileges to the partner. For example, the partner can be configured to include one or more of its employees within a user group maintained for the organization. After the system rights have been configured <b>208</b>, the relationship setup processing <b>200</b> ends.
0043According to one embodiment, a partner relationship between an organization and a partner can confer on the partner: (i) query rights, and (ii) rights to get public keys of the organization. For example query right might include the right to get members of a group used by the file security system. However, having the right to get public keys of the organization does not give access to secured documents of the organization.
0044<figref idref="DRAWINGS">FIG. 3</figref> is a flow diagram of document delivery processing <b>300</b> according to one embodiment of the invention. The document delivery processing <b>300</b> serves to deliver a secured document from an internal user to an external user. The internal user is associated with an organization, and the external user is associated with the partner.
0045The document delivery processing <b>300</b> begins with a decision <b>302</b> that determines whether a request to release a document to an external user has been received. In one embodiment, the request to release a document to an external user is initiated by an internal user. When the decision <b>302</b> determines that a request to release a document to an external user has not yet been received, the document delivery processing <b>300</b> awaits such a request. In other words, the document delivery processing <b>300</b> can be considered to be invoked when a request to release a document to an external user is received.
0046After a request to release a document to an external user has been received, a public key associated with the external user is retrieved <b>304</b> from a key store. In general, the key store serves to store a plurality of keys utilized by a document security system of the organization. In one embodiment, the key store can be the key store <b>104</b> illustrated in <figref idref="DRAWINGS">FIG. 1</figref>. Next, a decision <b>306</b> determines whether a public key associated with the external user was available from the key store. In one embodiment, the availability of the public key is controlled by the partner relationship. When the decision <b>306</b> determines that the key store does not have a public key associated with the external user, then the document is not permitted to be delivered to the external user and thus the request is denied <b>308</b>. Here, the particular external user is deemed not authorized to exchange documents with either the organization in general, or an internal user in particular.
0047On the other hand, when the decision <b>306</b> determines that a public key associated with the external user is available from the key store, then at least a portion of security information for the secured document is encrypted <b>310</b> using the public key. In one embodiment, the secured document that is to be delivered to the external user has a security information portion (also known as a header portion) and a data portion. The security information portion includes the security information providing restrictive access to the secured document. The security information may include access control components, such as keys or access rules that are utilized to control access to the data portion of the secured document. When the decision <b>306</b> determines that a public key is available, then at least a part of the security information portion for the secured document is encrypted <b>310</b> using the public key. Then, access control restrictions can be imposed <b>312</b> on the external user. The access control restrictions can limit the type, character or extent of access that the external user is granted with respect to the secured document. For example, the access control restrictions can be imposed by providing access rules within the security information portion of the secured document. After the access control restrictions are imposed <b>312</b> and encryption <b>310</b> with the public key, the secured document is released <b>314</b> to the external user. In one embodiment, the secured document is released <b>314</b> by being transmitted. Typically, the transmission of the secured document to the external user is performed through one or more networks (e.g., data networks). After the secured document has been released <b>314</b> to the external user (or after operation <b>308</b> when the request to deliver the secured document to the external user is denied), the document delivery processing <b>300</b> is complete and ends.
0048<figref idref="DRAWINGS">FIG. 4</figref> is a flow diagram of document access processing <b>400</b> according to one embodiment of the invention. The document access processing <b>400</b> involves an external user accessing a secured document that has been made available to the external user by an internal user.
0049The document access processing <b>400</b> begins with the external user acting to login <b>402</b> to an external access server. The external access server is associated with the document security system and utilized to permit limited external access to the document security system. As an example, the external access server can be the external access server <b>118</b> illustrated in <figref idref="DRAWINGS">FIG. 1</figref>.
0050A decision <b>404</b> then determines whether the login <b>402</b> has been successful. When the decision <b>404</b> determines that login has not been successful, then access is denied <b>406</b> to the external access server and no secured documents are made available to external users. Following the operation <b>406</b>, the document access processing <b>400</b> is complete and ends as the external user was unable to successfully log into the external access server.
0051On the other hand, when the decision <b>404</b> determines that the external user has successfully logged into the external access server, then a private key associated with the external user is retrieved <b>408</b>. In one embodiment, the private key is downloaded from the document security system via the external access server. In another embodiment, the private key is recovered locally.
0052Next, a decision <b>410</b> determines whether an access request for an encrypted document has been received. When the decision <b>410</b> determines that an access request for the secured document has not yet been received, a decision <b>412</b> determines whether the document access processing <b>400</b> should end. When the decision <b>412</b> determines that the document access processing <b>400</b> should not end, then the document access processing <b>400</b> returns to repeat the decision <b>410</b> and subsequent operations. On the other hand, when the decision <b>412</b> determines that the document access processing <b>400</b> should end, then the document access processing <b>400</b> is complete and ends.
0053Alternatively, when the decision <b>410</b> determines that an access request for the secured document has been received, then at least a portion of the security information for the secured document is decrypted <b>414</b> using the private key. Next, document level security is evaluated <b>416</b> to permit or deny access to the document contents. Following the operation <b>416</b>, the document access processing <b>400</b> is complete and ends.
0054<figref idref="DRAWINGS">FIG. 5</figref> is a flow diagram of access control processing <b>500</b> according to one embodiment of the invention. The access control processing <b>500</b> is, for example, suitable for use as the operations carried out by the operation <b>416</b> illustrated in <figref idref="DRAWINGS">FIG. 4</figref>.
0055The access control processing <b>500</b> initially obtains <b>502</b> access rules associated with the secured document. In one embodiment, the access rules are provided within the security information portion of the secured document. The access rules are then evaluated <b>504</b> against the access privilege of the user attempting to access the secured document. A decision <b>506</b> then determines whether the access rules are satisfied. When the decision <b>506</b> determines that the access rules are not satisfied, then access to the secured document is denied. Alternatively, when the decision <b>506</b> determines that the access rules are satisfied, then a file key associated with the secured document is obtained <b>510</b>. In one embodiment, the file key is provided within the security information portion of the secured document. The file key can be encrypted or in a clear format. In the case in which the file key is itself encrypted, the file key is first decrypted. Next, the secured document is decrypted <b>512</b> using the file key. Following the operation <b>512</b>, the access control processing <b>500</b> is complete and ends.
0056<figref idref="DRAWINGS">FIGS. 6 and 7</figref> pertain to document delivery processing in which an external user provides a secured document to an internal user. <figref idref="DRAWINGS">FIG. 6</figref> is a flow diagram of client-side document delivery processing <b>600</b> according to one embodiment of the invention. The client-side document delivery processing <b>600</b> is referred to as client-side because a client machine associated with the external user is performing or initiating the operations.
0057The client-side document delivery processing <b>600</b> begins with a decision <b>602</b> that determines whether a request (from an external user) to release a document to an internal user has been received. When the decision <b>602</b> determines that a request to release a document to an internal user has not yet been received, the client-side document delivery processing <b>600</b> awaits such a request. Once the decision <b>602</b> determines that a request to release a document to an internal user has been received, the client-side document delivery processing <b>600</b> continues. In other words, the client-side document delivery processing <b>600</b> can be considered to be invoked when the decision <b>602</b> determines that a request to release a document to an internal user has been received. The external user can interact with the client machine to initiate or make such a request.
0058After the decision <b>602</b> determines that a request to release a document to an internal user has been received, a public key associated with the internal user is requested <b>604</b>. Here, according to one embodiment, the public key associated with the internal user is requested <b>604</b> from the document security system. A decision <b>606</b> then determines whether a response has been received. When the decision <b>606</b> determines that a response has not yet been received, the client-side document delivery processing <b>600</b> awaits such a response. When the decision <b>606</b> determines that a response has been received, a decision <b>608</b> first determines whether the request is from an external user who is what they claim to be. According to one embodiment, certificates are used prevent someone from impersonating someone else. Depending on implementation, a certification of the external user may be issued by a third party (e.g., Certificate Authority) or the document security system itself. When the decision <b>608</b> determines that the external user is not who they claim to be, then the request is denied <b>610</b> because the response received was presumably from an unauthorized user or system.
0059On the other hand, when the decision <b>608</b> determines that the external user is who they claim to be (i.e., an authorized user), a decision <b>612</b> determines whether a public key is available. Here, the response received is examined to determine whether the response includes the public key associated with the internal user. Hence, when the public key is available, it is provided with the response being received. In one embodiment, the availability of the public key is controlled by the partner relationship.
0060When the decision <b>612</b> determines that the public key is not available, then the request is denied <b>610</b> because the client machine does not have access to the public key associated with the internal user. On the other hand, when the decision <b>612</b> determines that the public key is available, then at least a portion of the security information for the secured document is encrypted <b>614</b> using the public key. In one embodiment, a file key within the security information for the secured document is encrypted using the public key. Thereafter, the secured document is released <b>616</b> to the internal user. In one embodiment, the secured document is released <b>616</b> by being transmitted. Following the operations <b>610</b> or <b>616</b>, the client-side document delivery processing <b>600</b> is complete and ends.
0061<figref idref="DRAWINGS">FIG. 7</figref> is a flow diagram of server-side document delivery processing <b>700</b> according to one embodiment of the invention. The server-side document delivery processing <b>700</b> is, for example, performed by the document security system, such as the document security system <b>100</b> illustrated in <figref idref="DRAWINGS">FIG. 1</figref>. The server-side document delivery processing <b>700</b> is responsive to a public key request from the client-side document delivery processing <b>600</b>.
0062The server-side document delivery processing <b>700</b> begins with a decision <b>702</b> that determines whether a request for a public key from an external user has been received. In one embodiment, the request is provided by the operation <b>604</b> of the client-side document delivery processing <b>600</b> illustrated in <figref idref="DRAWINGS">FIG. 6</figref>. When the decision <b>702</b> determines that a request for a public key has not yet been received, then the server-side document delivery processing <b>700</b> awaits such a request. When the decision <b>702</b> determines that a request for a public key has been received, then a decision <b>704</b> determines whether the external user (requestor) is authorized to obtain the public key. Here, the authorization can be determined based on whether a partner relationship has been previously established between the external user and an organization. When the decision <b>704</b> determines that the external user is not authorized to receive the public key, then a response is prepared <b>710</b> indicating that access has been denied.
0063On the other hand, when the decision <b>704</b> determines that the external user is authorized to obtain the public key, then the public key associated with the internal user is retrieved <b>706</b> from a key store. The key store can, for example, be implemented as a database provided within the document security system. After the public key associated with the internal user has been retrieved <b>706</b>, a response including the public key can be prepared <b>708</b>. After the response has been prepared in operations <b>708</b> or <b>710</b>, the response is signed <b>712</b> with a certificate for the organization. In one embodiment, the certificate would have been previously embedded a priori in the machine (e.g., client machine) of the external user. The signed response is then transmitted <b>714</b> to the external user. Typically, the transmission of the signed response is sent to the external user over a secured channel through a network (data network, e.g., the Internet). Following the operation <b>714</b>, the server-side document delivery processing <b>700</b> is complete and ends.
0064<figref idref="DRAWINGS">FIG. 8</figref> shows a basic security system <b>800</b> in which the invention may be practiced in accordance with one embodiment thereof. The security system <b>800</b> may be employed in an enterprise or inter-enterprise environment. It includes a first server <b>808</b> (also referred to as a central server) providing centralized access management for the enterprise. The first server <b>808</b> can control restrictive access to files secured by the security system <b>800</b>. To provide dependability, reliability and scalability of the system, one or more second servers <b>804</b> (also referred to as local servers, of which one is shown) may be employed to provide backup or distributed access management for users or client machines serviced locally. For illustration purposes, there are two client machines <b>801</b> and <b>802</b> being serviced by a local server <b>804</b>. Alternatively, one of the client machines <b>801</b> and <b>802</b> may be considered as a networked storage device.
0065Secured files may be stored in either one of the devices <b>801</b>, <b>802</b>, <b>804</b>, <b>806</b> and <b>812</b>. When a user of the client machine <b>801</b> attempts to exchange a secured file with a remote destination <b>812</b> being used by an external user, one or more of the processing <b>200</b>, <b>300</b>, <b>400</b>, <b>500</b>, <b>600</b> and <b>700</b> discussed above are activated to ensure that the requested secured file is delivered without compromising the security imposed on the secured file.
0066<figref idref="DRAWINGS">FIG. 9</figref> shows an exemplary data structure <b>920</b> of a secured file that may be used in one embodiment of the invention. The data structure <b>920</b> includes two portions: a header (or header portion) <b>922</b> and encrypted data (or an encrypted data portion) <b>924</b>. The header <b>922</b> can be generated in accordance with a security template associated with the store and thus provides restrictive access to the data portion <b>924</b> which is an encrypted version of a plain file. Optionally, the data structure <b>920</b> may also include an error-checking portion <b>925</b> that stores one or more error-checking codes, for example, a separate error-checking code for each block of encrypted data <b>924</b>. These error-checking codes may also be associated with a Cyclical Redundancy Check (CRC) for the header <b>922</b> and/or the encrypted data <b>924</b>. The header <b>922</b> includes a flag bit or signature <b>927</b> and security information <b>926</b> that is in accordance with the security template for the store. According to one embodiment, the security information <b>926</b> is encrypted and can be decrypted with a user key associated with an authenticated user (or requestor).
0067The security information <b>926</b> can vary depending upon implementation. However, as shown in <figref idref="DRAWINGS">FIG. 9</figref>, the security information <b>926</b> includes a user identifier (ID) <b>928</b>, access policy (access rules) <b>929</b>, a file key <b>930</b> and other information <b>931</b>. Although multiple user identifiers may be used, a user identifier <b>928</b> is used to identify a user or a group that is permitted to access the secured file. The access rules <b>929</b> provide restrictive access to the encrypted data portion <b>924</b>. The file key <b>930</b> is a cipher key that, once obtained, can be used to decrypt the encrypted data portion <b>924</b> and thus, in general, is protected. In one implementation of the data structure <b>920</b>, the file key <b>930</b> is encrypted in conjunction with the access rules <b>929</b>. In another implementation of the data structure <b>920</b>, the file key <b>930</b> is double encrypted with a protection key and further protected by the access rules <b>929</b>. The other information <b>931</b> is an additional space for other information to be stored within the security information <b>926</b>. For example, the other information <b>931</b> may be used to include other information facilitating secure access to the secured file, such as version number or author identifier.
0068The invention is preferably implemented by software or a combination of hardware and software, but can also be implemented in hardware. The invention can also be embodied as computer readable code on a computer readable medium. The computer readable medium is any data storage device that can store data which can thereafter be read by a computer system. Examples of the computer readable medium include read-only memory, random-access memory, CD-ROMs, DVDs, magnetic tape, optical data storage devices, and carrier waves. The computer readable medium can also be distributed over network-coupled computer systems so that the computer readable code is stored and executed in a distributed fashion.
0069The various embodiments, implementations and features of the invention noted above can be combined in various ways or used separately. Those skilled in the art will understand from the description that the invention can be equally applied to or used in other various different settings with respect to various combinations, embodiments, implementations or features provided in the description herein.
0070The advantages of the invention are numerous. Different embodiments or implementations may yield one or more of the following advantages. One advantage of the invention is that file security systems are able to protect secured files (e.g., documents) even when external users are provided limited access to secured files. Another advantage of the invention is that a file security system can permit external users to access certain secured files (e.g., secured documents) without compromising integrity of the file security system. For example, external users having working relationships with internal users are able to be given limited user privileges within the file security system such that restricted file (document) exchange is permitted between such internal and external users. Still another advantage of the invention is that that amount of specialized software required at machines utilized by external users is minimal.
0071The foregoing description of embodiments is illustrative of various aspects/embodiments of the present invention. Various modifications to the present invention can be made to the preferred embodiments by those skilled in the art without departing from the true spirit and scope of the invention as defined by the appended claims. Accordingly, the scope of the present invention is defined by the appended claims rather than the foregoing description of embodiments.
Contents5
Every citation, both waysCites: the store holds 1,000 of 1,052
| Document | Relation | Office | Cited during |
|---|---|---|---|
| WO0056028A1 | Cites | World Intellectual Property Organization (WIPO) | Applicant |
| WO0161438A2 | Cites | World Intellectual Property Organization (WIPO) | Applicant |
| WO0163387A2 | Cites | World Intellectual Property Organization (WIPO) | Applicant |
| WO0177783A2 | Cites | World Intellectual Property Organization (WIPO) | Applicant |
| WO0178285A1 | Cites | World Intellectual Property Organization (WIPO) | Applicant |
| WO0184271A2 | Cites | World Intellectual Property Organization (WIPO) | Applicant |
| EP0672991A2 | Cites | European Patent Office (EPO) | Applicant |
| EP0674253A1 | Cites | European Patent Office (EPO) | Applicant |
| EP0809170A1 | Cites | European Patent Office (EPO) | Applicant |
| EP0913966A2 | Cites | European Patent Office (EPO) | Applicant |
| EP0913967A2 | Cites | European Patent Office (EPO) | Applicant |
| EP0950941A2 | Cites | European Patent Office (EPO) | Applicant |
| EP1107504A2 | Cites | European Patent Office (EPO) | Applicant |
| EP1130492A2 | Cites | European Patent Office (EPO) | Applicant |
| EP1154348A2 | Cites | European Patent Office (EPO) | Applicant |
| EP1324565A1 | Cites | European Patent Office (EPO) | Applicant |
| US2001000265A1 | Cites | United States of America | Applicant |
| US2001011254A1 | Cites | United States of America | Applicant |
| US2001018743A1 | Cites | United States of America | Applicant |
| US2001021255A1 | Cites | United States of America | Applicant |
| US2001021926A1 | Cites | United States of America | Applicant |
| US2001023421A1 | Cites | United States of America | Applicant |
| US2001032181A1 | Cites | United States of America | Applicant |
| US2001033611A1 | Cites | United States of America | Applicant |
| US2001034839A1 | Cites | United States of America | Applicant |
| JP2001036517A | Cites | Japan | Applicant |
| US2001037290A1 | Cites | United States of America | Search report |
| US2001042110A1 | Cites | United States of America | Applicant |
| US2001044903A1 | Cites | United States of America | Applicant |
| US2001056541A1 | Cites | United States of America | Applicant |
| US2001056550A1 | Cites | United States of America | Applicant |
| US2002003886A1 | Cites | United States of America | Applicant |
| US2002004902A1 | Cites | United States of America | Applicant |
| US2002007335A1 | Cites | United States of America | Applicant |
| US2002007340A1 | Cites | United States of America | Search report |
| US2002010679A1 | Cites | United States of America | Applicant |
| US2002013772A1 | Cites | United States of America | Applicant |
| US2002016910A1 | Cites | United States of America | Search report |
| US2002016921A1 | Cites | United States of America | Applicant |
| US2002016922A1 | Cites | United States of America | Search report |
| US2002023208A1 | Cites | United States of America | Applicant |
| US2002023213A1 | Cites | United States of America | Search report |
| US2002026321A1 | Cites | United States of America | Applicant |
| US2002027886A1 | Cites | United States of America | Applicant |
| US2002029340A1 | Cites | United States of America | Applicant |
| US2002031230A1 | Cites | United States of America | Applicant |
| US2002035624A1 | Cites | United States of America | Applicant |
| US2002036984A1 | Cites | United States of America | Applicant |
| US2002041391A1 | Cites | United States of America | Applicant |
| US2002042756A1 | Cites | United States of America | Applicant |
| US2002046350A1 | Cites | United States of America | Applicant |
| US2002049903A1 | Cites | United States of America | Search report |
| US2002050098A1 | Cites | United States of America | Applicant |
| US2002052796A1 | Cites | United States of America | Search report |
| US2002052981A1 | Cites | United States of America | Applicant |
| US2002056042A1 | Cites | United States of America | Applicant |
| US2002059144A1 | Cites | United States of America | Applicant |
| US2002062240A1 | Cites | United States of America | Applicant |
| US2002062245A1 | Cites | United States of America | Applicant |
| US2002062451A1 | Cites | United States of America | Applicant |
| US2002069077A1 | Cites | United States of America | Applicant |
| US2002069272A1 | Cites | United States of America | Applicant |
| US2002069363A1 | Cites | United States of America | Applicant |
| US2002073320A1 | Cites | United States of America | Applicant |
| US2002077986A1 | Cites | United States of America | Applicant |
| US2002077988A1 | Cites | United States of America | Applicant |
| US2002078239A1 | Cites | United States of America | Applicant |
| US2002078361A1 | Cites | United States of America | Applicant |
| US2002087479A1 | Cites | United States of America | Applicant |
| US2002089602A1 | Cites | United States of America | Applicant |
| US2002091532A1 | Cites | United States of America | Applicant |
| US2002091745A1 | Cites | United States of America | Applicant |
| US2002091928A1 | Cites | United States of America | Applicant |
| US2002093527A1 | Cites | United States of America | Applicant |
| US2002099947A1 | Cites | United States of America | Applicant |
| US2002111885A1 | Cites | United States of America | Search report |
| US2002112035A1 | Cites | United States of America | Applicant |
| US2002112045A1 | Cites | United States of America | Search report |
| US2002112048A1 | Cites | United States of America | Applicant |
| US2002112168A1 | Cites | United States of America | Search report |
| US2002116649A1 | Cites | United States of America | Search report |
| US2002120851A1 | Cites | United States of America | Applicant |
| US2002124180A1 | Cites | United States of America | Applicant |
| US2002129158A1 | Cites | United States of America | Applicant |
| US2002129235A1 | Cites | United States of America | Applicant |
| US2002131601A1 | Cites | United States of America | Search report |
| US2002133500A1 | Cites | United States of America | Applicant |
| US2002133699A1 | Cites | United States of America | Applicant |
| US2002138437A1 | Cites | United States of America | Search report |
| US2002138571A1 | Cites | United States of America | Applicant |
| US2002138726A1 | Cites | United States of America | Applicant |
| US2002138762A1 | Cites | United States of America | Applicant |
| US2002143710A1 | Cites | United States of America | Applicant |
| US2002143906A1 | Cites | United States of America | Applicant |
| US2002150239A1 | Cites | United States of America | Applicant |
| US2002152302A1 | Cites | United States of America | Applicant |
| US2002154635A1 | Cites | United States of America | Search report |
| US2002156726A1 | Cites | United States of America | Applicant |
| US2002157016A1 | Cites | United States of America | Applicant |
| US2002162104A1 | Cites | United States of America | Applicant |
108 members in 5 offices
Priority claims10
| Document | Office | Kind | Date |
|---|---|---|---|
| 26221802 | United States of America | A | |
| 26221802 | United States of America | A | |
| 201213439485 | United States of America | A | |
| 201213439485 | United States of America | A | |
| 201715418263 | United States of America | A | |
| 10262218 | – | – | – |
| 13439485 | – | – | – |
| US20020262218 | – | – | – |
| US201213439485 | – | – | – |
| US201715418263 | – | – | – |
Members108
| Document | Office | Kind | |
|---|---|---|---|
| WO02064840A2 | World Intellectual Property Organization (WIPO) | A2 | |
| US2003108883A1 | United States of America | A1 | |
| US2003110131A1 | United States of America | A1 | |
| US2003110169A1 | United States of America | A1 | |
| US2003110397A1 | United States of America | A1 | |
| EP1320010A2 | European Patent Office (EPO) | A2 | |
| EP1320011A2 | European Patent Office (EPO) | A2 | |
| EP1320012A2 | European Patent Office (EPO) | A2 | |
| EP1320013A2 | European Patent Office (EPO) | A2 | |
| EP1320014A2 | European Patent Office (EPO) | A2 | |
| EP1320015A2 | European Patent Office (EPO) | A2 | |
| EP1320016A2 | European Patent Office (EPO) | A2 | |
| EP1320017A2 | European Patent Office (EPO) | A2 | |
| EP1320018A2 | European Patent Office (EPO) | A2 | |
| EP1320010A3 | European Patent Office (EPO) | A3 | |
| US2003120601A1 | United States of America | A1 | |
| US2003120684A1 | United States of America | A1 | |
| EP1324565A1 | European Patent Office (EPO) | A1 | |
| EP1320012A3 | European Patent Office (EPO) | A3 | |
| EP1326156A2 | European Patent Office (EPO) | A2 | |
| EP1326157A2 | European Patent Office (EPO) | A2 | |
| JP2003218851A | Japan | A | |
| JP2003223353A | Japan | A | |
| US2003154381A1 | United States of America | A1 | |
| JP2003228519A | Japan | A | |
| JP2003228520A | Japan | A | |
| JP2003242015A | Japan | A | |
| JP2003248658A | Japan | A | |
| US2003217281A1 | United States of America | A1 | |
| EP1320011A3 | European Patent Office (EPO) | A3 | |
| EP1326157A3 | European Patent Office (EPO) | A3 | |
| WO02064840A3 | World Intellectual Property Organization (WIPO) | A3 | |
| US2004064710A1 | United States of America | A1 | |
| EP1411411A2 | European Patent Office (EPO) | A2 | |
| US2004103202A1 | United States of America | A1 | |
| US2005071657A1 | United States of America | A1 | |
| EP1320015A3 | European Patent Office (EPO) | A3 | |
| EP1320016A3 | European Patent Office (EPO) | A3 | |
| US6889210B1 | United States of America | B1 | |
| EP1320014A3 | European Patent Office (EPO) | A3 | |
| EP1320013A3 | European Patent Office (EPO) | A3 | |
| EP1320017A3 | European Patent Office (EPO) | A3 | |
| EP1320018A3 | European Patent Office (EPO) | A3 | |
| US2005223242A1 | United States of America | A1 | |
| US2005223414A1 | United States of America | A1 | |
| EP1326156A3 | European Patent Office (EPO) | A3 | |
| US7178033B1 | United States of America | B1 | |
| EP1320011B1 | European Patent Office (EPO) | B1 | |
| DE60218615D1 | Germany | D1 | |
| US7260555B2 | United States of America | B2 | |
| DE60218615T2 | Germany | T2 | |
| US2008034205A1 | United States of America | A1 | |
| US7380120B1 | United States of America | B1 | |
| US7478418B2 | United States of America | B2 | |
| US2009100268A1 | United States of America | A1 | |
| US7562232B2 | United States of America | B2 | |
| US7565683B1 | United States of America | B1 | |
| US2009254972A1 | United States of America | A1 | |
| US7631184B2 | United States of America | B2 | |
| US7681034B1 | United States of America | B1 | |
| US7729995B1 | United States of America | B1 | |
| US7748045B2 | United States of America | B2 | |
| USRE41546E | United States of America | E | |
| US7783765B2 | United States of America | B2 | |
| EP2275894A1 | European Patent Office (EPO) | A1 | |
| EP2285061A1 | European Patent Office (EPO) | A1 | |
| US7913311B2 | United States of America | B2 | |
| US7921284B1 | United States of America | B1 | |
| US7921288B1 | United States of America | B1 | |
| US7921450B1 | United States of America | B1 | |
| US7930756B1 | United States of America | B1 | |
| US8006280B1 | United States of America | B1 | |
| EP1320012B1 | European Patent Office (EPO) | B1 | |
| US2011258438A1 | United States of America | A1 | |
| US8065713B1 | United States of America | B1 | |
| US2011296199A1 | United States of America | A1 | |
| US2011307937A1 | United States of America | A1 | |
| US8176334B2 | United States of America | B2 | |
| US2012137130A1 | United States of America | A1 | |
| EP2275894B1 | European Patent Office (EPO) | B1 | |
| US2012198230A1 | United States of America | A1 | |
| US8266674B2 | United States of America | B2 | |
| EP2503485A2 | European Patent Office (EPO) | A2 | |
| EP2503486A2 | European Patent Office (EPO) | A2 | |
| EP2503485A3 | European Patent Office (EPO) | A3 | |
| EP2503486A3 | European Patent Office (EPO) | A3 | |
| US8341406B2 | United States of America | B2 | |
| US8341407B2 | United States of America | B2 | |
| USRE43906E | United States of America | E | |
| US8543827B2 | United States of America | B2 | |
| US8613102B2 | United States of America | B2 | |
| US2014075206A1 | United States of America | A1 | |
| US2014101457A1 | United States of America | A1 | |
| US2014201850A1 | United States of America | A1 | |
| US8918839B2 | United States of America | B2 | |
| US8943316B2 | United States of America | B2 | |
| US9129120B2 | United States of America | B2 | |
| US9286484B2 | United States of America | B2 | |
| US9542560B2 | United States of America | B2 | |
| US2017116431A1 | United States of America | A1 |
60 transactions on the USPTO file
Allowed after 1 non-final rejection and 1 final rejection.
- Non-final rejections
- 1
- Final rejections
- 1
- RCEs
- 0
- Appeals
- 0
Over time
Point at a mark for the transactionTransactions
| Event | Code | |
|---|---|---|
| Refund - 7.5 yr surcharge - late pmt w/in 6 mo, Large EntityR1555 | R1555 | |
| Refund - Payment of Maintenance Fee, 8th Year, Large EntityR1552 | R1552 | |
| 7.5 yr surcharge - late pmt w/in 6 mo, Large EntityM1555 | M1555 | |
| Payment of Maintenance Fee, 8th Year, Large EntityM1552 | M1552 | |
| Payment of Maintenance Fee, 8th Year, Large EntityM1552 | M1552 | |
| Recordation of Patent Grant MailedPGM/ | PGM/ | |
| Email NotificationEML_NTR | EML_NTR | |
| Issue Notification MailedAllowedWPIR | WPIR | |
| Dispatch to FDCD1935 | D1935 | |
| Email NotificationEML_NTR | EML_NTR | |
| Mail Response to 312 Amendment (PTO-271)MN271 | MN271 | |
| Printer Rush- No mailingTCPB | TCPB | |
| Response to Amendment under Rule 312N271 | N271 | |
| Pubs Case Remand to TCPUBTC | PUBTC | |
| Application Is Considered Ready for IssuePILS | PILS | |
| Amendment after Notice of Allowance (Rule 312)AllowedA.NA | A.NA | |
| Response to Reasons for AllowanceREAS | REAS | |
| Issue Fee Payment VerifiedN084 | N084 | |
| Issue Fee Payment ReceivedIFEE | IFEE | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Notice of AllowanceAllowedMN/=. | MN/=. | |
| Notice of Allowance Data Verification CompletedAllowedN/=. | N/=. | |
| Reasons for AllowanceEX.R | EX.R | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Response after Final ActionA.NE | A.NE | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Final Rejection (PTOL - 326)Final rejectionMCTFR | MCTFR | |
| Final RejectionFinal rejectionCTFR | CTFR | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Response after Non-Final ActionA... | A... | |
| Request for Extension of Time - GrantedXT/G | XT/G | |
| Information Disclosure Statement (IDS) FiledM844 | M844 | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Mail Interview Summary - Applicant Initiated - TelephonicMEXAT | MEXAT | |
| Interview Summary - Applicant Initiated - TelephonicEXAT | EXAT | |
| Electronic request for Examiner InterviewM865E | M865E | |
| Mail Non-Final RejectionNon-final rejectionMCTNF | MCTNF | |
| Non-Final RejectionNon-final rejectionCTNF | CTNF | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Application Dispatched from OIPEOIPE | OIPE | |
| FITF set to NO - revise initial settingFTFI | FTFI | |
| Application Is Now CompleteCOMP | COMP | |
| Filing Receipt - UpdatedFLRCPT.U | FLRCPT.U | |
| Additional Application Filing FeesADDFLFEE | ADDFLFEE | |
| A statement by one or more inventors satisfying the requirement under 35 USC 115, Oath of the ApplicOATHDECL | OATHDECL | |
| Notice of Reissue Published in Official GazetteNRE. | NRE. | |
| Application ready for PDX access by participating foreign officesCCRDY | CCRDY | |
| Filing ReceiptFLRCPT.O | FLRCPT.O | |
| Notice Mailed--Application Incomplete--Filing Date AssignedINCD | INCD | |
| Preliminary AmendmentA.PE | A.PE | |
| Applicants have given acceptable permission for participating foreignAPPERMS | APPERMS | |
| Cleared by OIPE CSRL194 | L194 | |
| Entity Status Set To Undiscounted (Initial Default Setting or Status Change)BIG. | BIG. | |
| Initial Exam Team nnIEXX | IEXX |
5 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| RefundREFUND - PAYMENT OF MAINTENANCE FEE, 8TH YEAR, LARGE ENTITY (ORIGINAL EVENT CODE: R1552); ENTITY STATUS OF PATENT OWNER: LARGE ENTITYREFU | REFU | |
| RefundREFUND - 7.5 YR SURCHARGE - LATE PMT W/IN 6 MO, LARGE ENTITY (ORIGINAL EVENT CODE: R1555); ENTITY STATUS OF PATENT OWNER: LARGE ENTITYREFU | REFU | |
| Fee payment procedure7.5 YR SURCHARGE - LATE PMT W/IN 6 MO, LARGE ENTITY (ORIGINAL EVENT CODE: M1555); ENTITY STATUS OF PATENT OWNER: LARGE ENTITYFEPP | FEPP | |
| Maintenance fee paymentMAFP | MAFP | |
| Maintenance fee paymentMAFP | MAFP |
Numbers
- Publication
- RE047443
- Publication, DOCDB
- RE47443
- Publication, EPODOC
- USRE47443E
- Application
- 15418263
- Application, DOCDB
- 201715418263
- Application, EPODOC
- US201715418263
Titles
- English
- Document security system that permits external users to gain access to secured files
Classification
- CPC, 2
- G06F21/6209
- G06F21/6218
- IPC, 8
- G06F21 00
- H04L29 00
- H04L29 06
- H04N7 16
- G06F15 16
- G06F17 30
- G06F7 04
- G06F21 62