Patents Assigned to Guardian Data Storage, LLC
-
Patent number: 10360545Abstract: Method and Apparatus for access secured electronic data are disclosed. According to one aspect, an off-line access mechanism in a client machine is activated to facilitate those users on the go to access secured electronic data. When a user decides to be away from a network premises or on a business trip, an off-line access request may be generated by the off-line access mechanism and forwarded to a server. In response, the server may grant the off-line access request to the user as well as the client machine from which the user will access the secured electronic data off-line. Depending on implementation, the AC may provide amended or tentative access rules, access privileges or user keys that will automatically expire when a predetermined time ends or become invalid the next time the client machine is connected to the server.Type: GrantFiled: February 12, 2002Date of Patent: July 23, 2019Assignee: Guardian Data Storage, LLCInventors: Chang-Ping Lee, Denis Jacques Paul Garcia, Hal Hildebrand, Klimenty Vainstein
-
Patent number: 8341407Abstract: Even with proper access privilege, when a secured file is classified, at least security clearance (e.g. a clearance key) is needed to ensure those who have the right security clearance can ultimately access the contents in the classified secured file. According to one embodiment, referred to as a two-0pronged access scheme, a security clearance key is generated and assigned in accordance with a user's security access level. A security clearance key may range from most classified to non-classified. Depending on implementation, a security clearance key with a security level may be so configured that the key can be used to access secured files classified at or lower than the security level or multiple auxiliary keys are provided when a corresponding security clearance key is being requested. The auxiliary keys are those keys generated to facilitate access to secured files classified respectively less than the corresponding security or confidentiality level.Type: GrantFiled: April 1, 2011Date of Patent: December 25, 2012Assignee: Guardian Data Storage, LLCInventors: Gary Mark Kinghorn, Denis Jacques Paul Garcia
-
Patent number: 8341406Abstract: With files secured by encryption techniques, keys are often required to gain access to the secured files. Techniques for providing and using multiple levels of keystores for securing the keys are disclosed. The keystores store keys that are needed by users in order to access secured files. The different levels of keystores offer compromises between security and flexibility/ease of use.Type: GrantFiled: April 4, 2011Date of Patent: December 25, 2012Assignee: Guardian Data Storage, LLCInventor: Hal S. Hildebrand
-
Patent number: 8327138Abstract: Techniques for dynamically altering security criteria used in a file security system are disclosed. The security criteria pertains to keys (or ciphers) used by the file security system to encrypt electronic files to be secured or to decrypt electronic files already secured. The security criteria can, among other things, include keys that are required to gain access to electronic files. Here, the keys can be changed automatically as electronic files transition between different states of a process-driven security policy. The dynamic alteration of security criteria enhances the flexibility and robustness of the security system. In other words, access restrictions on electronic files can be dependent on the state of the process-driven security policy.Type: GrantFiled: April 16, 2010Date of Patent: December 4, 2012Assignee: Guardian Data Storage LLCInventors: Satyajit Nath, Klimenty Vainstein, Michael Michio Ouye
-
Patent number: 8307067Abstract: An improved system and approaches for protecting secured files when being used by an application (e.g., network browser) that potentially transmits the files over a network to unknown external locations are disclosed. According to one aspect, access to secured files is restricted so that unsecured versions of the secured files are not able to be transmitted over a network (e.g., the Internet) to unauthorized destinations. In one embodiment, processes operating on a computer system are monitored to determine destination locations, if any, of said processes, and then using such destination locations to determine whether to permit the processes to open files in a secure or unsecured manner.Type: GrantFiled: February 19, 2009Date of Patent: November 6, 2012Assignee: Guardian Data Storage, LLCInventor: Nicholas M. Ryan
-
Patent number: 8301896Abstract: Multi-level file digests for electronic files are disclosed. A top level digest represents a single digest for the associated electronic file. Lower level digests represent digests for portions of the associated electronic file. The top level digest is derived from the lower level digests. The top level digest is useful for facilitating rapid comparison to determine whether electronic files are the same. In one embodiment, electronic files are encrypted with a block encryption scheme, and digests are efficiently calculated and stored on a block-by-block basis. Advantageously, when modifications to an encrypted electronic file occurs, only those modified blocks need to be processed to undergo decryption and re-encryption to determine the appropriate digest.Type: GrantFiled: April 23, 2010Date of Patent: October 30, 2012Assignee: Guardian Data Storage, LLCInventors: Michael Frederick Kenrich, Yevgeniy Gutnik
-
Patent number: 8266674Abstract: Improved approaches for effectuating changes to security policies in a distributed security system are disclosed. The changes to security policies are distributed to those users (e.g., user and/or computers) in the security system that are affected. The distribution of such changes to security policies can be deferred for those affected users that are not activated (e.g., logged-in or on-line) with the security system.Type: GrantFiled: June 19, 2009Date of Patent: September 11, 2012Assignee: Guardian Data Storage, LLCInventors: Weiqing Huang, Senthilvasan Supramaniam, Klimenty Vainstein
-
Publication number: 20120198230Abstract: A system includes a server with an access manager configured to restrict access to files of an organization and maintain at least encryption keys for internal and external users and an external access server connected to the server and coupled between the server and a data network. The data network is configured to allow the external users use of the external access server. The external access server is also configured to permit file exchange between the internal users and the external users via the server.Type: ApplicationFiled: April 4, 2012Publication date: August 2, 2012Applicant: Guardian Data Storage, LLCInventor: Klimenty VAINSTEIN
-
Publication number: 20120159191Abstract: Techniques for dynamically altering security criteria used in a file security system are disclosed. The security criteria pertains to keys (or ciphers) used by the file security system to encrypt electronic files to be secured or to decrypt electronic files already secured. The security criteria can, among other things, include keys that are required to gain access to electronic files. Here, the keys can be changed automatically as electronic files transition between different states of a process-driven security policy. The dynamic alteration of security criteria enhances the flexibility and robustness of the security system. In other words, access restrictions on electronic files can be dependent on the state of the process-driven security policy and enforced in conjunction with one or more cryptographic methods.Type: ApplicationFiled: February 24, 2012Publication date: June 21, 2012Applicant: Guardian Data Storage, LLCInventors: Klimenty VAINSTEIN, Satyajit NATH, Michael Michio OUYE
-
Publication number: 20120137130Abstract: A system and method for providing access management to secured items through use of a plurality of server machines associated with different locations are disclosed. According to one embodiment, a local server can be dynamically reconfigured depending on a user's current location. Upon detecting that a user has moved to a new location, the local server for the new location can be reconfigured to add support for the user, while simultaneously, the local server for the previous location is reconfigured to remove support for the user. As a result, security is enhanced while the access management can be efficiently carried out to ensure that only one access from the user is permitted at any time across an entire organization, regardless of how many locations the organization has or what access privileges the user may be granted.Type: ApplicationFiled: November 21, 2011Publication date: May 31, 2012Applicant: Guardian Data Storage, LLCInventors: Klimenty Vainstein, Hal Hildebrand
-
Patent number: 8176334Abstract: An improved system and approaches for exchanging secured files (e.g., documents) between internal users of an organization and external users are disclosed. A file security system of the organization operates to protect the files of the organization and thus prevents or limits external users from accessing internal documents. Although the external users are unaffiliated with the organization (i.e., not employees or contractors), the external users often have working relationships with internal users. These working relationships (also referred to herein as partner relationships) often present the need for file (document) exchange. According to one aspect, external users having working relationships with internal users are able to be given limited user privileges within the file security system, such that restricted file (document) exchange is permitted between such internal and external users.Type: GrantFiled: September 30, 2002Date of Patent: May 8, 2012Assignee: Guardian Data Storage, LLCInventor: Klimenty Vainstein
-
Patent number: 8127366Abstract: Techniques for dynamically altering security criteria used in a file security system are disclosed. The security criteria pertains to keys (or ciphers) used by the file security system to encrypt electronic files to be secured or to decrypt electronic files already secured. The security criteria can, among other things, include keys that are required to gain access to electronic files. Here, the keys can be changed automatically as electronic files transition between different states of a process-driven security policy. The dynamic alteration of security criteria enhances the flexibility and robustness of the security system. In other words, access restrictions on electronic files can be dependent on the state of the process-driven security policy and enforced in conjunction with one or more cryptographic methods.Type: GrantFiled: September 30, 2003Date of Patent: February 28, 2012Assignee: Guardian Data Storage, LLCInventors: Klimenty Vainstein, Satyajit Nath, Michael Michio Ouye
-
SECURITY SYSTEM FOR GENERATING KEYS FROM ACCESS RULES IN A DECENTRALIZED MANNER AND METHODS THEREFOR
Publication number: 20110307937Abstract: Improved system and approaches for decentralized key generation are disclosed. The keys that can be generated include both public keys and private keys. The public keys are arbitrary strings that embed or encode access restrictions. The access restrictions are used to enforce access control policies. The public keys are used to encrypt some or all portions of files. The private keys can be generated to decrypt the portions of the files that have been encrypted with the public keys. By generating keys in a decentralized manner, not only are key distribution burdens substantially eliminated but also off-line access to encrypted files is facilitated.Type: ApplicationFiled: August 19, 2011Publication date: December 15, 2011Applicant: Guardian Data Storage, LLCInventors: Hal S. Hildebrand, Denis Jacques Paul Garcia -
Publication number: 20110296199Abstract: Even with proper access privilege, when a secured file is classified, at least security clearance (e.g. a clearance key) is needed to ensure those who have the right security clearance can ultimately access the contents in the classified secured file. According to one embodiment, referred to as a two-Opronged access scheme, a security clearance key is generated and assigned in accordance with a user's security access level. A security clearance key may range from most classified to non-classified. Depending on implementation, a security clearance key with a security level may be so configured that the key can be used to access secured files classified at or lower than the security level or multiple auxiliary keys are provided when a corresponding security clearance key is being requested. The auxiliary keys are those keys generated to facilitate access to secured files classified respectively less than the corresponding security or confidentiality level.Type: ApplicationFiled: April 1, 2011Publication date: December 1, 2011Applicants: Pervasive Security Systems, Inc., Guardian Data Storage, LLCInventors: Gary Mark Kinghorn, Denis Jacques Paul Garcia
-
Publication number: 20110258438Abstract: With files secured by encryption techniques, keys are often required to gain access to the secured files. Techniques for providing and using multiple levels of keystores for securing the keys are disclosed. The keystores store keys that are needed by users in order to access secured files. The different levels of keystores offer compromises between security and flexibility/ease of use.Type: ApplicationFiled: April 4, 2011Publication date: October 20, 2011Applicant: Guardian Data Storage, LLCInventor: Hal S. HILDEBRAND
-
Patent number: 7950066Abstract: Techniques and mechanisms for controlling copying of content from a secured file or secured document are disclosed. In one embodiment, the techniques or mechanisms operate to control clipboard usage such that content from a secured document of one application is not able to be copied to another application or a different document of another application by way of a clipboard. According to another embodiment, alternate content is copied to another application or a different document of another application instead of the content from the secured document.Type: GrantFiled: December 21, 2001Date of Patent: May 24, 2011Assignee: Guardian Data Storage, LLCInventor: Patrick Zuili
-
Publication number: 20100205446Abstract: Multi-level file digests for electronic files are disclosed. A top level digest represents a single digest for the associated electronic file. Lower level digests represent digests for portions of the associated electronic file. The top level digest is derived from the lower level digests. The top level digest is useful for facilitating rapid comparison to determine whether electronic files are the same. In one embodiment, electronic files are encrypted with a block encryption scheme, and digests are efficiently calculated and stored on a block-by-block basis. Advantageously, when modifications to an encrypted electronic file occurs, only those modified blocks need to be processed to undergo decryption and re-encryption to determine the appropriate digest.Type: ApplicationFiled: April 23, 2010Publication date: August 12, 2010Applicant: Guardian Data Storage, LLCInventors: Michael Frederick KENRICH, Yevgeniy Gutnik
-
Publication number: 20100199088Abstract: Techniques for dynamically altering security criteria used in a file security system are disclosed. The security criteria pertains to keys (or ciphers) used by the file security system to encrypt electronic files to be secured or to decrypt electronic files already secured. The security criteria can, among other things, include keys that are required to gain access to electronic files. Here, the keys can be changed automatically as electronic files transition between different states of a process-driven security policy. The dynamic alteration of security criteria enhances the flexibility and robustness of the security system. In other words, access restrictions on electronic files can be dependent on the state of the process-driven security policy.Type: ApplicationFiled: April 16, 2010Publication date: August 5, 2010Applicant: Guardian Data Storage, LLCInventors: Satyajit Nath, Klimenty Vainstein, Michael Michio Ouye
-
Patent number: 7703140Abstract: Techniques for dynamically altering security criteria used in a file security system are disclosed. The security criteria pertains to keys (or ciphers) used by the file security system to encrypt electronic files to be secured or to decrypt electronic files already secured. The security criteria can, among other things, include keys that are required to gain access to electronic files. Here, the keys can be changed automatically as electronic files transition between different states of a process-driven security policy. The dynamic alteration of security criteria enhances the flexibility and robustness of the security system. In other words, access restrictions on electronic files can be dependent on the state of the process-driven security policy.Type: GrantFiled: September 30, 2003Date of Patent: April 20, 2010Assignee: Guardian Data Storage, LLCInventors: Satyajit Nath, Klimenty Vainstein, Michael Michio Ouye
-
Patent number: RE43906Abstract: Digital assets are in a secured form that only those with granted access rights can access. Even with the proper access privilege, when a secured file is classified, at least a security clearance key is needed to ensure those who have the right security clearance can ultimately access the contents in the classified secured file. According to one embodiment, a secured file or secured document includes two parts: a header, and an encrypted data portion. The header includes security information that points to or includes access rules, a protection key and a file key. The access rules facilitate restrictive access to the encrypted data portion and essentially determine who the secured document can be accessed. The file key is used to encrypt/decrypt the encrypted data portion and protected by the protection key.Type: GrantFiled: December 9, 2008Date of Patent: January 1, 2013Assignee: Guardian Data Storage LLCInventor: Denis Jacques Paul Garcia