Patents by Inventor Klimenty Vainstein

Klimenty Vainstein has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Publication number: 20120137130
    Abstract: A system and method for providing access management to secured items through use of a plurality of server machines associated with different locations are disclosed. According to one embodiment, a local server can be dynamically reconfigured depending on a user's current location. Upon detecting that a user has moved to a new location, the local server for the new location can be reconfigured to add support for the user, while simultaneously, the local server for the previous location is reconfigured to remove support for the user. As a result, security is enhanced while the access management can be efficiently carried out to ensure that only one access from the user is permitted at any time across an entire organization, regardless of how many locations the organization has or what access privileges the user may be granted.
    Type: Application
    Filed: November 21, 2011
    Publication date: May 31, 2012
    Applicant: Guardian Data Storage, LLC
    Inventors: Klimenty Vainstein, Hal Hildebrand
  • Patent number: 8176334
    Abstract: An improved system and approaches for exchanging secured files (e.g., documents) between internal users of an organization and external users are disclosed. A file security system of the organization operates to protect the files of the organization and thus prevents or limits external users from accessing internal documents. Although the external users are unaffiliated with the organization (i.e., not employees or contractors), the external users often have working relationships with internal users. These working relationships (also referred to herein as partner relationships) often present the need for file (document) exchange. According to one aspect, external users having working relationships with internal users are able to be given limited user privileges within the file security system, such that restricted file (document) exchange is permitted between such internal and external users.
    Type: Grant
    Filed: September 30, 2002
    Date of Patent: May 8, 2012
    Assignee: Guardian Data Storage, LLC
    Inventor: Klimenty Vainstein
  • Patent number: 8127366
    Abstract: Techniques for dynamically altering security criteria used in a file security system are disclosed. The security criteria pertains to keys (or ciphers) used by the file security system to encrypt electronic files to be secured or to decrypt electronic files already secured. The security criteria can, among other things, include keys that are required to gain access to electronic files. Here, the keys can be changed automatically as electronic files transition between different states of a process-driven security policy. The dynamic alteration of security criteria enhances the flexibility and robustness of the security system. In other words, access restrictions on electronic files can be dependent on the state of the process-driven security policy and enforced in conjunction with one or more cryptographic methods.
    Type: Grant
    Filed: September 30, 2003
    Date of Patent: February 28, 2012
    Assignee: Guardian Data Storage, LLC
    Inventors: Klimenty Vainstein, Satyajit Nath, Michael Michio Ouye
  • Patent number: 8065713
    Abstract: A system and method for providing access management to secured items through use of a plurality of server machines associated with different locations are disclosed. According to one embodiment, a local server can be dynamically reconfigured depending on a user's current location. Typically, a local server services only those users that are local to the local server. When a user moves from one location to another location, upon detecting a new location of the user who has moved from a previous location, the local server for the new location can be reconfigured to add support for the user, while at the same time, the local server for the previous location is reconfigured to remove support for the user. As a result, security is enhanced while the access management can be efficiently carried out to ensure that only one access from the user is permitted at any time across an entire organization, regardless of how many locations the organization has or what access privileges the user may be granted.
    Type: Grant
    Filed: February 12, 2002
    Date of Patent: November 22, 2011
    Inventors: Klimenty Vainstein, Hal Hildebrand
  • Patent number: 7921450
    Abstract: Improved system and approaches for centralized storage of access restrictions which are associated with public keys are disclosed. The access restrictions serve to limit access to files secured by a security system. According to one aspect of the present invention, identifiers, or encoded versions thereof, are used as public keys to identify particular access restrictions. The identifiers to the access restrictions are used in a decentralized manner for public keys, while the access restrictions themselves are maintained in a centralized manner. As compared to the access restrictions, the public keys based on identifiers tend to be smaller and more uniform in size. The centralized storage of the access restrictions also facilitates subsequent changes to access restrictions for previously secured files. The improved system and approaches is particularly suitable in an enterprise environment.
    Type: Grant
    Filed: November 15, 2002
    Date of Patent: April 5, 2011
    Inventors: Klimenty Vainstein, Hal S. Hildebrand
  • Patent number: 7913311
    Abstract: Techniques for providing pervasive security to digital assets are disclosed. According to one aspect of the techniques, a server is configured to provide access control (AC) management for a user (e.g., a single user, a group of users, software agents or devices) with a need to access secured data. Within the server module, various access rules for the secured data and/or access privileges for the user can be created, updated, and managed so that the user with the proper access privileges can access the secured documents if granted by the corresponding access rules in the secured data.
    Type: Grant
    Filed: August 10, 2007
    Date of Patent: March 22, 2011
    Inventors: Rossmann Alain, Patrick Zuili, Michael Michio Ouye, Serge Humpich, Chang-Ping Lee, Klimenty Vainstein, Hal Hilderbrand, Denis Jacques Paul Garcia, Senthilvasan Supramaniam, Weiqing Huang, Nicholas Michael Ryan
  • Patent number: 7890990
    Abstract: An improved system and method for providing a security system with the capability to stage a modification to its operation is disclosed. Staging the modification before actually modifying normal operation of the security system allows the impact of the modification on the security system to be examined prior to deployment. If the staging of the modification to the security system is deemed successful, the modification can be fully deployed with reduced risk of unexpected security lapses or other detrimental consequences.
    Type: Grant
    Filed: December 20, 2002
    Date of Patent: February 15, 2011
    Inventors: Klimenty Vainstein, Michael Michio Ouye
  • Patent number: 7783765
    Abstract: A system and method for providing distributed access control are disclosed. A number of local servers are employed to operate largely on behalf of a central server responsible for centralized access control management. Such a distributed fashion ensures the dependability, reliability and scalability of the access control management undertaking by the central server. According to one embodiment, a distributed access control system that restricts access to secured items can include at least a central server having a server module that provides overall access control, and a plurality of local servers. Each of the local servers can include a local module that provides local access control. The access control, performed by the central server or the local servers, operates to permit or deny access requests to the secured items by requestors.
    Type: Grant
    Filed: February 12, 2002
    Date of Patent: August 24, 2010
    Inventors: Hal S. Hildebrand, Klimenty Vainstein
  • Publication number: 20100199088
    Abstract: Techniques for dynamically altering security criteria used in a file security system are disclosed. The security criteria pertains to keys (or ciphers) used by the file security system to encrypt electronic files to be secured or to decrypt electronic files already secured. The security criteria can, among other things, include keys that are required to gain access to electronic files. Here, the keys can be changed automatically as electronic files transition between different states of a process-driven security policy. The dynamic alteration of security criteria enhances the flexibility and robustness of the security system. In other words, access restrictions on electronic files can be dependent on the state of the process-driven security policy.
    Type: Application
    Filed: April 16, 2010
    Publication date: August 5, 2010
    Applicant: Guardian Data Storage, LLC
    Inventors: Satyajit Nath, Klimenty Vainstein, Michael Michio Ouye
  • Patent number: 7729995
    Abstract: Techniques for managing files in a designated location are disclosed. An example of the designated location is a folder, a directory, a repository, a device, or a storage place. A set of access rules is applied to a designated location such that all files in the designated location shall have substantially similar security. As a result, secured files can be easily created and managed with respect to the designated location and users with access privilege to the designated location can access most of the files, in not all, in the designated location.
    Type: Grant
    Filed: July 22, 2002
    Date of Patent: June 1, 2010
    Inventors: Rossmann Alain, Patrick Zuili, Michael Michio Ouye, Serge Humpich, Chang-Ping Lee, Klimenty Vainstein, Hal Hilderbrand, Denis Jacques Paul Garcia, Senthilvasan Supramaniam, Weiqing Huang, Nicholas Michael Ryan
  • Patent number: 7703140
    Abstract: Techniques for dynamically altering security criteria used in a file security system are disclosed. The security criteria pertains to keys (or ciphers) used by the file security system to encrypt electronic files to be secured or to decrypt electronic files already secured. The security criteria can, among other things, include keys that are required to gain access to electronic files. Here, the keys can be changed automatically as electronic files transition between different states of a process-driven security policy. The dynamic alteration of security criteria enhances the flexibility and robustness of the security system. In other words, access restrictions on electronic files can be dependent on the state of the process-driven security policy.
    Type: Grant
    Filed: September 30, 2003
    Date of Patent: April 20, 2010
    Assignee: Guardian Data Storage, LLC
    Inventors: Satyajit Nath, Klimenty Vainstein, Michael Michio Ouye
  • Patent number: 7702909
    Abstract: Improved techniques for validating timestamps used in a client-server environment are disclosed. A client can associate client-provided timestamps with events that occur at the client. The client can then send event information as well as the timestamps to a server. Preferably, the event information and timestamps are sent in a batch pertaining to a plurality of events that have occurred at the client. The server, which has greater time accuracy, can then validate the client-provided timestamps. The server can also modify the client-provided timestamps so as to improve accuracy of the timestamps. Once modified, the timestamps can pertain to a range (e.g., window) of time during which the associated events can be known to have reliably occurred. In one embodiment, the client-server environment is a distributed file security system in which the events and event information pertain to audit files.
    Type: Grant
    Filed: December 22, 2003
    Date of Patent: April 20, 2010
    Inventor: Klimenty Vainstein
  • Publication number: 20090254972
    Abstract: Improved approaches for effectuating changes to security policies in a distributed security system are disclosed. The changes to security policies are distributed to those users (e.g., user and/or computers) in the security system that are affected. The distribution of such changes to security policies can be deferred for those affected users that are not activated (e.g., logged-in or on-line) with the security system.
    Type: Application
    Filed: June 19, 2009
    Publication date: October 8, 2009
    Applicant: Guardian Data Storage, LLC
    Inventors: Weiqing Huang, Senthilvasan Supramaniam, Klimenty Vainstein
  • Patent number: 7565683
    Abstract: Improved approaches for effectuating changes to security policies in a distributed security system are disclosed. The changes to security policies are distributed to those users (e.g., user and/or computers) in the security system that are affected. The distribution of such changes to security policies can be deferred for those affected users that are not activated (e.g., logged-in or on-line) with the security system.
    Type: Grant
    Filed: June 26, 2002
    Date of Patent: July 21, 2009
    Inventors: Weiqing Huang, Senthilvasan Supramaniam, Klimenty Vainstein
  • Patent number: 7562232
    Abstract: Improved approaches for accessing secured digital assets (e.g., secured items) are disclosed. In general, digital assets that have been secured (secured digital assets) can only be accessed by authenticated users with appropriate access rights or privileges. Each secured digital asset is provided with a header portion and a data portion, where the header portion includes a pointer to separately stored security information. The separately stored security information is used to determine whether access to associated data portions of secured digital assets is permitted. These improved approaches can facilitate the sharing of security information by various secured digital assets and thus reduce the overall storage space for the secured digital assets. These improved approaches can also facilitate efficient management of security for digital assets.
    Type: Grant
    Filed: July 25, 2002
    Date of Patent: July 14, 2009
    Inventors: Patrick Zuili, Klimenty Vainstein
  • Publication number: 20090100268
    Abstract: In a system for providing access control management to electronic data, techniques to secure the electronic data and keep the electronic data secured at all times are disclosed. According to one embodiment, a secured file or secured document includes two parts: an attachment, referred to as a header, and an encrypted document or data portion. The header includes security information that points to or includes the access rules and a file key. The access rules facilitate restrictive access to the secured document and essentially determine who/when/how/where the secured document can be accessed. The file key is used to encrypt/decrypt the encrypted data portion. Only those who have the proper access privileges are permitted to retrieve the file key to encrypt/decrypt the encrypted data portion.
    Type: Application
    Filed: March 27, 2008
    Publication date: April 16, 2009
    Applicant: Guardian Data Storage, LLC
    Inventors: Denis Jacques Paul GARCIA, Michael Michio OUYE, Alain ROSSMANN, Steven Toye CROCKER, Eric GILBERTSON, Weiqing HUANG, Serge HUMPICH, Klimenty VAINSTEIN, Nicholas Michael RYAN
  • Patent number: 7478418
    Abstract: Improved approaches for communicating changes to security policies (or rules) in a distributed security system are disclosed. Depending on the status of an affected user in the system, the changes can be delivered to the user if the user is logged in the system or effectuated in a state message in a local server and the state message is delivered to the user next time the user is logged in the system. If a local server is not operative at the time that a change request is received for a user of the local server, the change request is redirected to another local server. The user is directed to the another local server to affect the change request. As a result, various changes are guaranteed to be delivered to the affected users without compromising the network efficiency.
    Type: Grant
    Filed: June 26, 2002
    Date of Patent: January 13, 2009
    Assignee: Guardian Data Storage, LLC
    Inventors: Senthilvasan Supramaniam, Weiqing Huang, Klimenty Vainstein
  • Publication number: 20080034205
    Abstract: Techniques for providing pervasive security to digital assets are disclosed. According to one aspect of the techniques, a server is configured to provide access control (AC) management for a user (e.g., a single user, a group of users, software agents or devices) with a need to access secured data. Within the server module, various access rules for the secured data and/or access privileges for the user can be created, updated, and managed so that the user with the proper access privileges can access the secured documents if granted by the corresponding access rules in the secured data.
    Type: Application
    Filed: August 10, 2007
    Publication date: February 7, 2008
    Applicant: Guardian Data Storage, LLC
    Inventors: Rossmann Alain, Patrick Zuili, Michael Ouye, Serge Humpich, Chang-Ping Lee, Klimenty Vainstein, Hal Hilderbrand, Denis Jacques Garcia, Senthilvasan Supramaniam, Weiqing Huang, Nicholas Ryan
  • Patent number: 7260555
    Abstract: Techniques for providing pervasive security to digital assets are disclosed. According to one aspect of the techniques, a server is configured to provide access control (AC) management for a user (e.g., a single user, a group of users, software agents or devices) with a need to access secured data. Within the server module, various access rules for the secured data and/or access privileges for the user can be created, updated and managed so that the user with the proper access privileges can access the secured documents if granted by the corresponding access rules in the secured data.
    Type: Grant
    Filed: February 12, 2002
    Date of Patent: August 21, 2007
    Assignee: Guardian Data Storage, LLC
    Inventors: Alain Rossmann, Patrick Zuili, Michael Michio Ouya, Serge Humpich, Chang-Ping Lee, Klimenty Vainstein, Hal Hilderbrand, Denis Jacques Paul Garcia, Senthilvasan Supramaniam, Weiqing Huang, Nicholas Michael Ryan
  • Patent number: RE41546
    Abstract: Techniques for reorganizing security levels without implicating accessibility to secured files classified in accordance to one of the security levels are disclosed. In a case of adding a new security level, the controllability or restrictiveness of the new security level is determined with respect to the most restrictive security level or the least security level in a set of existing security levels. A set of proper security parameters are then generated for the new security level and subsequently the existing security levels are reorganized to accommodate the new security level. In a case of removing a security level from the existing security levels, the security parameters for the security level to be deleted are either folded up or down to an immediate next security level, depending on implementation.
    Type: Grant
    Filed: May 2, 2007
    Date of Patent: August 17, 2010
    Inventor: Klimenty Vainstein