Method and system for managing security tiers
Techniques for reorganizing security levels without implicating accessibility to secured files classified in accordance to one of the security levels are disclosed. In a case of adding a new security level, the controllability or restrictiveness of the new security level is determined with respect to the most restrictive security level or the least security level in a set of existing security levels. A set of proper security parameters are then generated for the new security level and subsequently the existing security levels are reorganized to accommodate the new security level. In a case of removing a security level from the existing security levels, the security parameters for the security level to be deleted are either folded up or down to an immediate next security level, depending on implementation. As a result, the security parameters for the immediate next security level are updated to include those for the security level to be deleted such that the secured files classified at the security level to be deleted can still be accessed by those with proper clearance levels.
This application is a continuation-in-part of co-pending U.S. patent application Ser. No. 10/076,254, filed Feb. 12, 2002, that claims the benefits of U.S. provisional application No. 60/339,634 filed Dec. 12, 2001. The application is also related to U.S. patent application Ser. No. 10/159,537 and entitled “Method and Apparatus for Securing Digital Assets”, which is hereby incorporated by reference.
BACKGROUND OF THE INVENTION1. Field of the Invention
The present invention relates to the area of protecting data in an enterprise environment, and more particularly, relates to a method and system for managing security tiers or levels without implicating accessibilities to secured files classified according to a security level.
2. Description of Related Art
The Internet is the fastest growing telecommunications medium in history. This growth and the easy access it affords have significantly enhanced the opportunity to use advanced information technology for both the public and private sectors. It provides unprecedented opportunities for interaction and data sharing among businesses and individuals. However, the advantages provided by the Internet come with a significantly greater element of risk to the confidentiality and integrity of information. The Internet is a widely open, public and international network of interconnected computers and electronic devices. Without proper security means, an unauthorized person or machine may intercept any information traveling across the Internet and even get access to proprietary information stored in computers that interconnect to the Internet, but are otherwise generally inaccessible by the public.
There are many efforts in progress aimed at protecting proprietary information traveling across the Internet and controlling access to computers carrying the proprietary information. Cryptography allows people to carry over the confidence found in the physical world to the electronic world, thus allowing people to do business electronically without worries of deceit and deception. Every day hundreds of thousands of people interact electronically, whether it is through e-mail, e-commerce (business conducted over the Internet), ATM machines, or cellular phones. The perpetual increase of information transmitted electronically has lead to an increase reliance on cryptography.
One of the ongoing efforts in protecting the proprietary information traveling across the Internet is to use one or more cryptographic techniques to secure a private communication session between two communicating computers on the Internet. The cryptographic techniques provides a way to transmit information across an insecure communication channel without disclosing the contents of the information to anyone eavesdropping on the communication channel. Using an encryption process in a cryptographic technique, one party can protect the contents of the data in transit from access by an unauthorized third party yet the intended party can read the data using a corresponding decryption process.
A firewall is another security measure that protects the resources of a private network from users of other networks. However, it has been reported that many unauthorized accesses to proprietary information occur from the inside, as opposed to from the outside. An example of someone gaining unauthorized access from the inside is when restricted or proprietary information is accessed by someone within an organization who is not supposed to do so. Due to the open nature of the Internet, contractual information, customer data, executive communications, product specifications, and a host of other confidential and proprietary intellectual property, remains available and vulnerable to improper access and usage by unauthorized users within or outside a supposedly protected perimeter.
In fact, many businesses and organizations have been looking for effective ways to protect their proprietary information. Typically, businesses and organizations have deployed firewalls, Virtual Private Networks (VPNs), and Intrusion Detection Systems (IDS) to provide protection. Unfortunately, these various security means have been proven insufficient to reliably protect proprietary information residing on private networks. For example, depending on passwords to access sensitive documents from within often causes security breaches when the password of a few characters long is leaked or detected. Therefore, there is a need to provide more effective ways to secure and protect digital assets at all times.
When a security system is employed to secure files, it is sometimes desirable to classify the secured files according to a security level, for example, “top secret”, “secret” or “confidential”. When there is a need to add or delete additional security levels, the secured files originally classified should be still accessible. Thus there is a need for solutions that can manage the security levels dynamically without implicating accessibility to the secured files.
SUMMARY OF INVENTIONThis section is for the purpose of summarizing some aspects of the present invention and to briefly introduce some preferred embodiments. Simplifications or omissions in this section as well as in the abstract may be made to avoid obscuring the purpose therefor. Such simplifications or omissions are not intended to limit the scope of the present invention.
The present invention is related to processes, systems, architectures and software products for providing pervasive security to digital assets at all times and is particularly suitable in an inter/intra enterprise environment. In general, pervasive security means that digital assets are secured at all times and can only be accessed by authenticated users with appropriate access rights or privileges, and proper security clearance in some cases, wherein the digital assets may include, but not be limited to, various types of documents, multimedia files, data, executable code, images and texts. According to one aspect of the present invention, secured files are in a secured form that only those with granted access rights can access. Even with the proper access privilege, when a secured file is classified, at least a security clearance key is needed to ensure those who have the right security clearance can ultimately access the contents in the classified secured file.
According to one aspect of the present invention, a new security level is to be inserted into a set of existing security levels. For example, a security level “secret” is added between the existing security levels “top secret” and “confidential”, resulting in a new set of security levels, “top secret”, “secret” and “confidential”. Without implicating the accessibility to secured files classified at one of the existing security levels, the controllability or restrictiveness of the new security level is determined with respect to the most restrictive security level or the least security level in the existing security levels. A set of proper security parameters are generated for the new security level and subsequently the existing security levels are mapped to accommodate the new security level.
According to another aspect of the present invention, a security level is removed from a set of existing security levels. For example, a security level “secret” is removed from the existing security levels “top secret”, “secret” and “confidential”, resulting in a new set of security levels including only “top secret” and “confidential”. Without implicating the accessibility to secured files classified at one of the existing security levels, the security parameters for the security level to be deleted are either folded up or down to an immediate next security level, depending on implementation. As a result, the security parameters for the immediate next security level are augmented to include those for the security level to be deleted such that the secured files classified at the security level to be deleted can still be accessed by those with proper clearance levels.
Depending on implementation and application, the present invention may be implemented in software, hardware or both in combination, and employed in a client machine or a server machine. According to one embodiment, the present invention is implemented in an executable form loaded in a computing device and activated when the security tiers or levels are changed to provide particular needs of an organization or organizations.
The present invention can be implemented as a method, a system, a process, software medium or other form, each yielding one or more of the following features, benefits and advantages. One of the features, benefits and advantages is the management mechanism of security levels in a security system, the mechanism provides flexibility in reorganizing security levels without implicating accessibility to secured files originally classified. Another one of the features, benefits and advantages is that secured files originally classified at a security level to be deleted can still be accessed by properly folding the security level to a next immediate security level.
Other objects, features, and advantages of the present invention will become apparent upon examining the following detailed description of an embodiment thereof, taken in conjunction with the attached drawings.
These and other features, aspects, and advantages of the present invention will become better understood with regard to the following description, appended claims, and accompanying drawings where:
FIG. 3B and
The present invention pertains to a process, a system, a method and a software product for securing electronic data or digital assets. According to one aspect of the present invention, a new security level is to be inserted into a set of existing security levels. Without implicating the accessibility to secured files classified at one of the existing security levels, the controllability or restrictiveness of the new security level is determined with respect to the most restrictive security level or the least security level in the existing security levels. A set of proper security parameters are generated for the new security level and subsequently the existing security levels are mapped to accommodate the new security level. According to another aspect of the present invention, a security level is removed from a set of existing security levels. The security parameters for the security level to be deleted are either folded up or down to an immediate next security level, depending on implementation. As a result, the security parameters for the immediate next security level are augmented to include those for the security level to be deleted such that the secured files classified at the security level to be deleted can still be accessed by those with proper clearance levels.
There are numerous advantages, benefits, and features in the present invention. One of them is the mechanism contemplated herein capable of providing pervasive security to digital assets sought to be protected at all times. Another one is that the digital assets are presented in such a way that only those with proper access privilege as well as sufficient security clearance level can access information in the digital assets. Other advantages, benefits, and features in the present invention can be readily appreciated by those skilled in the art from the detailed description of the invention provided herein.
In the following description, numerous specific details are set forth in order to provide a thorough understanding of the present invention. However, it will become obvious to those skilled in the art that the present invention may be practiced without these specific details. The description and representation herein are the common means used by those experienced or skilled in the art to most effectively convey the substance of their work to others skilled in the art. In other instances, well-known methods, procedures, components, and circuitry have not been described in detail to avoid unnecessarily obscuring aspects of the present invention.
Reference herein to “one embodiment” or “an embodiment” means that a particular feature, structure, or characteristic described in connection with the embodiment can be included in at least one embodiment of the invention. The appearances of the phrase “in one embodiment” in various places in the specification are not necessarily all referring to the same embodiment, nor are separate or alternative embodiments mutually exclusive of other embodiments. Further, the order of blocks in process flowcharts or diagrams representing one or more embodiments of the invention do not inherently indicate any particular order nor imply any limitations in the invention.
Embodiments of the present invention are discussed herein with reference to
Generally, a content created by a creator for the purpose of an entity is an intellectual property belonging to the creator or the entity. In an enterprise, any kind of information or intellectual property can be content, though it is commonly referred to as “information” instead of “content”. In either case, content or information is independent of its format, it may be in a printout or an electronic document. As used herein, content or information exists in a type of electronic data that is also referred to as a digital asset. A representation of the electronic data may include, but not be limited to, various types of documents, multimedia files, streaming data, dynamic or static data, executable code, images and texts.
To prevent contents in electronic data from an unauthorized access, the electronic data is typically stored in a form that is as close to impossible as possible to read without a priori knowledge. Its purpose is to ensure privacy by keeping the content hidden from anyone for whom it is not intended, even those who have access to the electronic data. Example of a priori knowledge may include, but not be limited to, a password, a secret phase, biometric information or one or more keys.
After the document 100 is created, edited or opened with an application or authoring tool (e.g., Microsoft WORD), upon an activation of a command, such as “Save,” “Save As” or “Close”, or automatic saving invoked by an operating system, the application itself, or an approved application, the created document 100 is caused to undergo a securing process 101. The securing process 101 starts with an encryption process 102, namely the document 100 that has been created or is being written into a store is encrypted by a cipher (e.g., an encryption process) with a file key (i.e., a cipher key). In other words, the encrypted data portion 112 could not be opened without the file key. For the purpose of controlling the access to the contents in the document 100 or the resultant secured file 108, the file key or keys may be the same or different keys for encryption and decryption and are included as part of security information contained in or pointed to by a header 106. The file key or keys, once obtained, can be used to decrypt the encrypted data portion 112 to reveal the contents therein.
To ensure that only authorized users or members of an authorized group can access the secured file 108, a set of access rules 104 (an example is shown in the figure) for the document 100 is received or created and associated with the header 106. In general, the access rules 104 determine or regulate who and/or how the document 100, once secured, can be accessed. In some cases, the access rules 104 also determine or regulate when or where the document 100 can be accessed. In addition, security clearance information 107 is added to the header 106 if the secured file 108 is classified. In general, the security clearance information 107 is used to determine a level of access privilege or security level of a user who is attempting to access the contents in the secured file 108. For example, a secured file may be classified as “Top secret”, “Secret”, “Confidential”, and “Unclassified”.
According to one embodiment, the security clearance information 107 includes another layer of encryption of the file key with another key referred to herein as a clearance key. An authorized user must have a clearance key of proper security level in addition to an authenticated user key and proper access privilege to retrieve the file key. As used herein, a user key or a group key is a cipher key assigned to an authenticated user and may be used to access a secured file or secure a file, or create a secured file. The detail of obtaining such a user key upon a user being authenticated is provided in U.S. patent application Ser. No. 10/074,804.
According to another embodiment, the security clearance information 107 includes a set of special access rules to guard the file key. The retrieval of the file key requires that the user passes an access rule measurement. Since access privilege of a user may be controlled via one or more system parameters (e.g., a policy), the access rule measurement can determine if the user has sufficient access privilege to retrieve the file key in conjunction with the corresponding user key. With the detailed description to follow, those skilled in the art can appreciate that other forms of the security clearance information 107 may be possible. Unless otherwise specified, the following description is based on the security clearance information 107 being another layer of encryption with one or more clearance keys.
In accordance with the security clearance information 107, a user may be assigned a hierarchical security clearance level based on, perhaps, a level of trust assigned to the user. A level of trust implies that one user may be more trusted than another and hence the more trusted user may access more classified files. Depending on implementation, a level of trust may be based on job responsibility of the user or a role of the user in a project or an organization background checks, psychological profiles, or length of service, etc. In any case, a level of trust assigned to the user augments additional aspect to the access privilege of the user such that the user must have proper security clearance to access a classified secured file even if the user is permitted by the access rules to access the file.
As will be further described in detail below, unless the level of security clearance of the user permits, a secured classified file (i.e., the file that is both secured and classified) may not be accessed even if the user has an authenticated user (or group) key and permitted by the access rules in the secured classified file. In one embodiment, the level of security clearance of the user is determined by one or more clearance keys assigned thereto. In general, a clearance key permits a user to access a secured file classified as “top secret”, the same clearance key may permit the user to access all secured files classified less secure, such as “secret” or “confidential”, where it has been assumed that the user has proper access privilege to be granted by the access rules in the file. In one embodiment, a clearance key is further secured by means of secondary authentication, such as re-login, biometric information verification and a second password. In other words, a clearance key may not be automatically released to or activated for a user upon an authenticated login, unless the user provides additional information.
In general, a header is a file structure, preferably small in size, and includes, or perhaps links to, security information about a resultant secured document. Depending on an exact implementation, the security information can be entirely included in a header or pointed to by a pointer that is included in the header. According to one embodiment, the access rules 104, as part of the security information, are included in the header 106. The security information further includes the file key and/or one or more clearance keys, in some cases, an off-line access permit (e.g. in the access rules) should such access be requested by an authorized user. The security information is then encrypted by a cipher (i.e., an en/decryption scheme) with a user key associated with an authorized user to produce encrypted security information 110. The encrypted header 106, if no other information is added thereto, is attached to or integrated with the encrypted data portion 112 to generate the resultant secured file 108. In a preferred embodiment, the header is placed at the beginning of the encrypted document (data portion) to facilitate an early detection of the secured nature of a secured file. One of the advantages of such placement is to enable an access application (i.e., an authoring or viewing tool) to immediately activate a document securing module (to be described where it deems appropriate) to decrypt the header if permitted. Nevertheless, there is no restriction as to where the encrypted header 106 is integrated with the encrypted data portion 112.
It is understood that a cipher may be implemented based on one of many available encryption/decryption schemes. Encryption and decryption generally require the use of some secret information, referred to as a key. For some encryption mechanisms, the same key is used for both encryption and decryption; for other mechanisms, the keys used for encryption and decryption are different. In any case, data can be encrypted with a key according to a predetermined cipher (i.e., encryption/decryption) scheme. Examples of such schemes may include, but not be limited to, Data Encryption Standard algorithm (DES), Blowfish block cipher and Twofish cipher. Therefore, the operations of the present invention are not limited to a choice of those commonly-used encryption/decryption schemes. Any cipher scheme that is effective and reliable may be used. Hence, the details of a particular scheme are not further discussed herein so as to avoid obscuring aspects of the present invention.
In essence, the secured document 108 includes two parts, the encrypted data portion 112 (i.e., encrypted version of the document itself) and the header 110 that may point to or include security information for the secured document 108. To access the contents in the encrypted data portion 112, one needs to obtain the file key to decrypt the encrypted data portion 112. To obtain the file key, one needs to be authenticated to get a user or group key and pass an access test in which at least the access rules in the security information are measured against the user's access privilege (i.e., access rights). If the secured file is classified, it further requires a security level clearance on the user. In general, the security clearance level of the user must be high enough before the file key can be retrieved. Alternatively, part of the access rules may be left non-encrypted for users authorized or non-authorized alike to view embedded access permissions of a secured file in a display application or markup language interpreter (e.g., a browser).
At 222, the process 220 awaits a request for a clearance key. It is described that a secured file can be classified or unclassified. When it is determined that a user needs to access a secured file that is classified at a security level, such request is provided to activate the process 220. In general, the request pertains to a specific user or some members in a group. At 224, a corresponding account for the user is retrieved, provided there is the account for the user. If the account is not available, then the account shall be opened accordingly. Alternatively, the process 220 may be part of the process of opening an appropriate account for a user who has the need-to-know basis to access secured files at certain security or confidential level(s). Depending on implementation, the corresponding account information may include a username or identifier, membership information, designated access privilege, and a corresponding user key (which sometimes is a pair of a private key and a public key). At 226, a security level for the user is determined, which is usually done by the necessity. For example, an executive of an enterprise may be assigned the highest security clearance level and a front desk receptionist may be assigned the lowest security clearance level. Once the security level is determined, a clearance key is generated at 228.
Referring now to
Returning to
Clearance keys provide flexibilities for a security system to control access by authorized users to secured files that are classified accordingly. However, when levels of the security are fixed, the flexibilities are limited. As one of the features in the present invention, the levels of security can be added or adjusted up or down in a security system without compromising the security of the secured files that have been previously classified.
For simplified illustration purpose, the first access relationship is shown in the figures and the following description is based on the first access relationship. Those skilled in the art can understand the implementation of the second access relationship given the detailed description herein. When an additional security level 304 is added between the security levels 1 and 2, the groups and corresponding keys have to be reassigned without affecting the accessibility to other secured files originally classified. According to one embodiment, the security level 1 is the most restrictive level. Since the added level 304 is less restrictive than the security level 1 but more restrictive than level 2, as shown in
To maintain the accessibility of the originally authorized groups, the security levels are renumbered or remapped. If the original access relationship is SF ∀ (G2, level 2, CK2), there is now SF ∀ (G3, level 3, CK2), namely the original security level 2 is mapped to as security level 3.
FIG. 3B and
SF ∀ (G1, level 1, CK1);
SF ∀ (G2, level 2, CK2);
SF ∀ (G3, level 3, CK3);
are now correspondingly mapped to:
SF ∀ (G1, level 1, CK1, G2, level 2, CK2);
SF ∀ (G3, level 3, CK3).
In other words, those secured files classified at security level 2 can still be accessed by those with proper access privilege.
One the other hand,
SF ∀ (G1, level 1, CK1);
SF ∀ (G2, level 2, CK2);
SF ∀ (G3, level 3, CK3);
are now correspondingly mapped to:
SF ∀ (G1, level 1, CK1);
SF ∀ (G3, level 3, CK3, G2, level 2, CK2).
In other words, those secured files classified at security level 2 can still be accessed by those with proper access privilege.
At 402, the process 400 awaits a request to insert a new security level into N existing security levels. For example, a system was configured to manage secured files classified respectively in accordance with one of N security levels. In other words, there are N security levels in the system. For some reason, the system needs to be configured to manage N+1 security levels, namely a security level is to be added into the N security levels. Upon receiving a request to insert the new security level, the process 400 determines how restrictive the new security level is with respect to the N security level at 404. It is assumed that the 1 st security level in the N security levels is most restrictive while the Nth security level is least restrictive. The relative restrictiveness of the new security level is a relative position in the stack of the N security levels, indicating how less or more restrictive with respect to the 1 st security level or the Nth security level.
At 406, a set of security parameters is generated for the new security level. The security parameters include at least a clearance key and a relative security level (e.g., a tier rank). The clearance key may be respectively generated in accordance with
At 408, the new security level is now created in the original N security levels, resulting N+1 security levels. Without implicating the accessibility to secured files classified at other security levels, the security levels below the new security level are mapped accordingly. For example, an ith security level in the original N security levels now becomes an (i+1) security level and the corresponding security parameters are also shifted accordingly. In another perspective, SF ∀ (Gi, level i, CKi) is now SF ∀ (G(i+1), level (i+1), CKi). At 410, a new set of security levels is created, which does not implicate the accessibility to secured files originally classified and the originally authenticated users are still able to access the secured files they are entitled to.
According to one embodiment, when an authorized user logins into the system, with the login information in reference to a group, the user is granted at least two keys (a corresponding clearance key and a user key) such that the user can access secured files classified at the granted security level or any levels below this security level. According to another embodiment, when an authorized user logins into the system, with the login information in reference to a group, the user is granted all keys pairs the user is entitled to such that the user can access secured files classified at this security level or any levels below this security level. It should be noted that “granting” herein does not necessarily means only that the user receives the keys from the system. Depending on implementation, one or more of the keys or part or whole of the keys may be stored in a local or remote machine and caused to be activated for use only after the user is authenticated.
At 422, the process 420 awaits a request to delete a security level out of N existing security levels. For example, a system was configured to manage secured files classified respectively in accordance with one of N security levels. In other words, there are N security levels in the system. For some reason, the system needs to be configured to manage N−1 security levels, namely one of the N security levels is to be deleted. Upon receiving the request to delete, for example, an ith security level, the process 420 determines at 424 whether the ith security level is the most restrictive. It is assumed that the 1st security level in the N security levels is most restrictive while the Nth security level is least restrictive. Accordingly, the process 420 determines at 424 whether the security level to be removed is the 1st security level. If it is indeed the 1st security level, the request is denied.
It should be noted that 424 is not a limitation in the present invention and it can be folded down to a next immediate level. According to one embodiment, it is designed to suit in a more practical situation. In general, it is just not desirable to have a most restrictive security level to be deleted. In some other case, it is also not desirable to have a least restrictive security level to be deleted as well. Optionally, another checking may be employed in the process 420 to determine at 424 whether the security level to be removed is the Nth security level.
Depending on implementation, at 426, the security level to be deleted is to be folded up or down to a next immediate security level. For example, an ith security level to be deleted can be merged with (i−1)th security level or (i+1)th security level. By merging the ith security level with its next immediate security level, it is possible to access those secured files classified at the ith security level even if this level is deleted.
To access those secured files classified at the ith security level, the security parameters, such as the keys and the group designations shall be retained. As a result, at 428, the security parameters for the ith security level are transferred or updated accordingly. In general, for the case of folding up, the security parameters for the ith security level are merged with those for the (i−1)th security level, for the case of folding down, the security parameters for the ith security level are merged with those for the (i+1)th security level. At 430, the security levels are reordered, for example from security levels 1 to N to 1 to (N−1).
At 502, an identifier of the security level above the one being dropped is located, namely the identifier of the (i−1)th security level. According to the table 510, the identifier of the 3rd security level is FF5 (i.e., currentID=FF5). Given the two identifiers FF5 and C07, at 504, these two identifiers are entered in a mapping table at 504.
At 506, the mapping table 512 is updated. There is no operation since there are any entries previously in the table 512. At 508, the user who is previously authorized to access secured files classified at CD7 is updated. According to one embodiment, a notification is sent to the user or users who may have been affected by dropping CD7 to cause the original clearance key (i.e., CK4) to be updated or exchanged with another clearance key (e.g., CD3 for FF5). According to another embodiment, when a secured file classified at CD7 is accessed, the original clearance key is used to access the file. At the time, the file is stored, saved or written back to a storage space, an updated clearance key (i.e., the key for FF5) is effectuated in accordance with CurrentID. In any case, the updating at 508 can be configured to be carried out transparently.
Next, it is assumed that another security level, Level 3, is to be dropped. Accordingly, at 502, the identifier (A92) of the security level above Level 3 is located. At 504, these two identifiers are entered, namely deletedID=FF5 and currentD=A92. At 506, the table 512 needs to be updated. Since there is are entries from a previous deletion of one security level, these entries are preferably updated, thus the CurrentID is assigned to be A92 as well as shown in FIG. 5C. The affected user or users are updated at 508 so that these users can still access the secured files classified at FF5.
There are numerous features, advantages and benefits in the present invention. One of them is the mechanism provided to regroup security levels per a specific requirement without implicating the accessibility to secured files classified in accordance with the existing security levels. Another one of them is that a security level can be removed from a set of existing security levels while the security parameters for the security level to be deleted are either folded up or down to an immediate next security level. As a result, the security parameters for the immediate next security level are augmented to include those for the security level to be deleted such that the secured files classified at the security level to be deleted can still be accessed by those with proper clearance levels. Other features, advantages and benefits may be appreciated by those skilled in the art in the foregoing descriptions.
The present invention has been described in sufficient details with a certain degree of particularity. It is understood to those skilled in the art that the present disclosure of embodiments has been made by way of examples only and that numerous changes in the arrangement and combination of parts may be resorted without departing from the spirit and scope of the invention as claimed. Accordingly, the scope of the present invention is defined by the appended claims rather than the foregoing description of embodiments.
Claims
1. In a system for providing restrictive access to contents in secured files, each of the secured files classified in accordance with one of N security levels, a A method for reorganizing the N security levels without implicating accessibilities to the secured files, each of the secured files classified in accordance with one of the N security levels, the method comprising:
- determining, using a computing device, a new security level with respect to the N security levels, wherein a 1st security level is most restrictive and an Nth security level is least restrictive in among the N security levels;
- generating, using the computing device, security parameters accordingly for the new security level, the new security level being ith less restrictive with respect to the 1st security level; and
- mapping, using the computing device, an ith security level in the N security levels to an (i+1)th security level in the N security levels to accommodate the new security level such that there are now (N+1) security levels in the system,
- wherein each of the secured files includes an encrypted data portion and a security portion that controls restrictive access to the encrypted data portion, the security portion including a file key encrypted by at least a first key and a second key and further protected by a set of rules, and
- wherein both of the first key and the second key must be obtained by a user whose access privilege is satisfied by the rules before the contents of the each of the secured files can be accessed.
2. The method of claim 1, wherein the security parameters includes at least a clearance key and one or more of the parameters pertain to a designated group of users authorized to access the secured files classified at the new security level.
3. The method of claim 2, wherein the clearance key is associated with the designated group of users, and together with a user key associated with each of the users, allows access to files secured at the ith security level can now be accessed.
4. The method of claim 2, wherein, when if a user authorized to access secured files classified at the new security level logins logs into the system, the user is granted the clearance key, together with a user key authorized authorizing the user to access the secured files, those and secured files classified at the new security level can now be accessed by the users.
5. The method of claim 4, wherein, the clearance key is a private key in a pair of a public key and the private key, those and the secured files are classified at the new security level with the public key.
6. The method of claim 4, wherein, if the user is authorized at to access the ith security level in the original N security levels, the user is now granted a second user key and a second clearance key such that the contents in the secured files classified at the (i+1)th security level and below can be now accessed by the user.
7. The method of claim 6 1, wherein the first key determines if the user is authorized to access the secured files classified at one of the N security levels or one of the (N+1) security levels, and the second key is in accordance with the one of the N security levels or the one of the (N+1) security levels.
8. In a system for providing restrictive access to contents in secured files, at least some of the secured files classified in accordance with one of N security levels, a A method for reorganizing the N security levels without implicating accessibilities to the secured files, at least some of the secured files classified in accordance with one of the N security levels, the method comprising:
- upon receiving a request to remove an ith security level out of the N security levels, determining, using a computing device, if an (i−1)th security level is a 1st security level or if an (i+1)th security level is an Nth security levels, wherein the 1st security level is most restrictive and the Nth security level is least restrictive in among the N security levels;
- when if the (i−1)th security level is not the 1st security level and the (i+1)th security level is not the Nth security levels, merging, using the computing device, the ith security level with either the (i−1)th security level or the (i+1)th security level such that there are now (N−1) security levels in the system,
- wherein each of the secured files includes an encrypted data portion and a security portion that controls restrictive access to the encrypted data portion, the security portion including a file key encrypted by at least a first key and a second key and further protected by a set of rules, and wherein both of the first key and the second key must be obtained by a user whose access privilege is satisfied by the rules before the contents of the each of the secured files can be accessed.
9. The method of claim 8, wherein users authorized to access secured files classified at the ith security level can now access secured files classified at the (i−1)th security level if the ith security level is has been merged with the (i−1)th security level.
10. The method of claim 8, wherein users authorized to access secured files classified at the ith security level can now access secured files classified at the (i+1)th security level if the ith security level is has been merged with the (i+1)th security level.
11. The method of claim 8, wherein at least two keys are needed to access secured files classified at the ith security level, and after the ith security level is has been merged with the (i−1)th or (i+1)th security level, the at lest two keys are incorporated into the (i−1)th or (i+1)th security level as such that users authorized to access the secured files classified at the ith security level can still access the secured files.
12. The method of claim 11, wherein, at the same time, the users can access secured files classified at the (i−1)th or (i+1)th security level.
13. The method of claim 11, wherein the at least two keys include a first key associated with a designated group of users and a second key being a clearance key in accordance with the ith security level.
14. The method of claim 13, wherein, when if the user logins logs into the system, the user is granted the at least two keys.
15. The method of claim 8, further comprising:
- when if the (i−1)th security level is the 1st security level, denying the request to remove the ith security level out of the N security levels; or
- always folding down the ith security level with (i−1)th security level.
16. The method of claim 8 further comprising:
- when if the (i−1)th security level is the N security level, denying the request to remove the ith security level out of the N security levels; or always folding up the ith security level with (i−1)th security level.
17. In a A system for providing restrictive access to contents in secured files, each of the secured files classified in accordance with one of N security levels, the system comprising:
- a first machine loaded with a software module to reorganize the N security levels without implicating accessibilities to the secured files, wherein the 1st security level is most restrictive and the Nth security level is least restrictive in the N security levels, when and wherein, if the software module is executed, the first machine performs operations of: if a request of for deleting an ith security level out of the N security levels is received, determining if an (i−1)th security level is a 1 st security level or if an (i+1)th security level is an Nth security levels, wherein the 1st security level is most restrictive and the Nth security level is least restrictive in the N security levels; and when if the (i−1)th security level is not the 1st security level and the (i+1)th security level is not the Nth security levels, merging the ith security level with either the (i−1)th security level or the (i+1)th security level such that there are now (N−1) security levels in the system; and if a request of adding a new security level into the N security is received, determining a new security level with respect to the N security levels, wherein a 1 st security level is most restrictive and an Nth security level is least restrictive in the N security levels; generating security parameters accordingly for the new security level, the new security level being ith less restrictive with respect to the 1st security level; and mapping an ith security level in the N security levels to an (i+1)th security level in the N security levels to accommodate the new security level such that there are now (N+1) security levels in the system; and
- a second machine, coupled to the first machine over a network, associated with a user that is granted with at least two keys to access one of the secured files classified at one of the N security levels,
- wherein each of the secured files includes an encrypted data portion and a security portion that controls restrictive access to the encrypted data portion, the security portion including a file key encrypted by at least a first key and a second key and further protected by a set of rules, and
- wherein both of the first key and the second key must be obtained by a user whose access privilege is satisfied by the rules before the contents of the each of the secured files can be accessed.
18. The system of claim 17, wherein one of the two keys granted to the user is a clearance key in accordance with the one of the N security levels.
19. The system of claim 18, wherein the two keys granted to the user are folded to either the (i−1)th security level or the (i+1)th security level, when if the user is authorized to access secured files classified at the ith security level.
20. A tangible computer-readable storage medium having stored thereon instructions that, if executed by a computing device, cause the computing device to perform a method comprising:
- determining a new security level with respect to the N security levels, wherein a 1st security level is most restrictive and an Nth security level is least restrictive among the N security levels;
- generating security parameters accordingly for the new security level, the new security level being ith less restrictive with respect to the 1st security level; and
- mapping an ith security level in the N security levels to an (i+1)th security level in the N security levels to accommodate the new security level such that there are (N+1) security levels in the system,
- wherein each of the secured files includes an encrypted data portion and a security portion that controls restrictive access to the encrypted data portion, the security portion including a file key encrypted by at least a first key and a second key and further protected by a set of rules, and
- wherein both of the first key and the second key must be obtained by a user whose access privilege is satisfied by the rules before the contents of the each of the secured files can be accessed.
21. The computer-readable storage medium according to claim 20, wherein the security parameters include at least a clearance key and one or more of the parameters pertain to a designated group of users authorized to access the secured files classified at the new security level.
22. The computer-readable storage medium according to claim 21, wherein the clearance key is associated with the designated group of users, and together with a user key associated with each of the users, allows access to files secured at the ith security level.
23. The computer-readable storage medium according to claim 21, wherein, if a user authorized to access secured files classified at the new security level logs into the system, the user is granted the clearance key, together with a user key authorizing the user to access the secured files, and secured files classified at the new security level can be accessed by the user.
24. The computer-readable storage medium according to claim 23, wherein the clearance key is a private key in a pair of a public key and the private key, and the secured files are classified at the new security level with the public key.
25. The computer-readable storage medium according to claim 23, wherein, if the user is authorized to access the ith security level in the N security levels, the user is granted a second user key and a second clearance key such that the contents in the secured files classified at the (i+1)th security level and below can be accessed by the user.
26. The computer-readable storage medium according to claim 25, wherein the first key determines if the user is authorized to access the secured files classified at one of the N security levels or one of the (N+1) security levels, and the second key is in accordance with the one of the N security levels or the one of the (N+1) security levels.
27. A tangible computer-readable storage medium having stored thereon instructions that, if executed by a computing device, cause the computing device to perform a method comprising:
- upon receiving a request to remove an ith security level out of the N security levels, determining if an (i−1)th security level is a 1st security level or if an (i+1)th security level is an Nth security level, wherein the 1st security level is most restrictive and the Nth security level is least restrictive among the N security levels;
- if the (i−1)th security level is not the 1st security level and the (i+1)th security level is not the Nth security level, merging the ith security level with either the (i−1)th security level or the (i+1)th security level such that there are (N−1) security levels in the system,
- wherein each of the secured files includes an encrypted data portion and a security portion that controls restrictive access to the encrypted data portion, the security portion including a file key encrypted by at least a first key and a second key and further protected by a set of rules, and
- wherein both of the first key and the second key must be obtained by a user whose access privilege is satisfied by the rules before the contents of each of the secured files can be accessed.
28. The computer-readable storage medium according to claim 27, wherein users authorized to access secured files classified at the ith security level can access secured files classified at the (i−1)th security level if the ith security level has been merged with the (i−1)th security level.
29. The computer-readable storage medium according to claim 27, wherein users authorized to access secured files classified at the ith security level can access secured files classified at the (i+1)th security level if the ith security level has been merged with the (i+1)th security level.
30. The computer-readable storage medium according to claim 27, wherein at least two keys are needed to access secured files classified at the ith security level, and after the ith security level has been merged with the (i−1)th or (i+1)th security level, the at lest two keys are incorporated into the (i−1)th or (i+1)th security level such that users authorized to access the secured files classified at the ith security level can access the secured files.
31. The computer-readable storage medium according to claim 30, wherein the users can access secured files classified at the (i−1)th or (i+1)th security level.
32. The computer-readable storage medium according to claim 30, wherein the at least two keys include a first key associated with a designated group of users and a second key being a clearance key in accordance with the ith security level.
33. The computer-readable storage medium according to claim 32, wherein, if the user logs into the system, the user is granted the at least two keys.
34. The computer-readable storage medium according to claim 27, further comprising computer code for: if the (i−1)th security level is the 1st security level, denying the request to remove the ith security level out of the N security levels; or always folding down the ith security level with (i−1)th security level.
35. The computer-readable storage medium according to claim 27 further comprising computer code for: if the (i−1)th security level is the N security level, denying the request to remove the ith security level out of the N security levels; or always folding up the ith security level with (i−1)th security level.
4203166 | May 1980 | Ehrsam et al. |
4734568 | March 29, 1988 | Watanabe |
4757533 | July 12, 1988 | Allen et al. |
4796220 | January 3, 1989 | Wolfe |
4799258 | January 17, 1989 | Davies |
4827508 | May 2, 1989 | Shear |
4888800 | December 19, 1989 | Marshall et al. |
4972472 | November 20, 1990 | Brown et al. |
5032979 | July 16, 1991 | Hecht et al. |
5052040 | September 24, 1991 | Preston et al. |
5058164 | October 15, 1991 | Elmer et al. |
5144660 | September 1, 1992 | Rose |
5204897 | April 20, 1993 | Wyman |
5220657 | June 15, 1993 | Bly et al. |
5235641 | August 10, 1993 | Nozawa et al. |
5247575 | September 21, 1993 | Sprague et al. |
5276735 | January 4, 1994 | Boebert et al. |
5301247 | April 5, 1994 | Rasmussen et al. |
5319705 | June 7, 1994 | Halter et al. |
5369702 | November 29, 1994 | Shanton |
5375169 | December 20, 1994 | Seheidt et al. |
5404404 | April 4, 1995 | Novorita |
5406628 | April 11, 1995 | Beller et al. |
5414852 | May 9, 1995 | Kramer et al. |
5495533 | February 27, 1996 | Linehan et al. |
5499297 | March 12, 1996 | Boebert |
5502766 | March 26, 1996 | Boebert et al. |
5535375 | July 9, 1996 | Eshel et al. |
5557765 | September 17, 1996 | Lipner et al. |
5570108 | October 29, 1996 | McLaughlin et al. |
5584023 | December 10, 1996 | Hsu |
5600722 | February 4, 1997 | Yamaguchi et al. |
5606663 | February 25, 1997 | Kadooka |
5655119 | August 5, 1997 | Davy |
5661806 | August 26, 1997 | Nevoux et al. |
5671412 | September 23, 1997 | Christiano |
5673316 | September 30, 1997 | Auerbach et al. |
5677953 | October 14, 1997 | Dolphin |
5680452 | October 21, 1997 | Shanton |
5684987 | November 4, 1997 | Mamiya et al. |
5689718 | November 18, 1997 | Sakurai et al. |
5699428 | December 16, 1997 | McDonnal et al. |
5708709 | January 13, 1998 | Rose |
5715403 | February 3, 1998 | Stefik |
5717755 | February 10, 1998 | Shanton |
5720033 | February 17, 1998 | Deo |
5729734 | March 17, 1998 | Parker et al. |
5732265 | March 24, 1998 | Dewitt et al. |
5745573 | April 28, 1998 | Lipner et al. |
5748736 | May 5, 1998 | Mittra |
5751287 | May 12, 1998 | Hahn et al. |
5757920 | May 26, 1998 | Misra et al. |
5765152 | June 9, 1998 | Erickson |
5778065 | July 7, 1998 | Hauser et al. |
5787169 | July 28, 1998 | Eldridge et al. |
5787173 | July 28, 1998 | Seheidt et al. |
5787175 | July 28, 1998 | Carter |
5790789 | August 4, 1998 | Suarez |
5790790 | August 4, 1998 | Smith et al. |
5813009 | September 22, 1998 | Johnson et al. |
5821933 | October 13, 1998 | Keller et al. |
5825876 | October 20, 1998 | Peterson |
5835592 | November 10, 1998 | Chang et al. |
5835601 | November 10, 1998 | Shimbo et al. |
5857189 | January 5, 1999 | Riddle |
5862325 | January 19, 1999 | Reed et al. |
5870468 | February 9, 1999 | Harrison |
5870477 | February 9, 1999 | Sasaki et al. |
5881287 | March 9, 1999 | Mast |
5892900 | April 6, 1999 | Ginter et al. |
5893084 | April 6, 1999 | Morgan et al. |
5898781 | April 27, 1999 | Shanton |
5922073 | July 13, 1999 | Shimada |
5923754 | July 13, 1999 | Angelo et al. |
5933498 | August 3, 1999 | Schnek et al. |
5944794 | August 31, 1999 | Okamoto et al. |
5953419 | September 14, 1999 | Lohstroh et al. |
5968177 | October 19, 1999 | Batten-Carew et al. |
5970502 | October 19, 1999 | Salkewicz et al. |
5987440 | November 16, 1999 | O'Neil et al. |
5991879 | November 23, 1999 | Still |
5999907 | December 7, 1999 | Donner |
6014730 | January 11, 2000 | Ohtsu |
6023506 | February 8, 2000 | Ote et al. |
6032216 | February 29, 2000 | Schmuck et al. |
6038322 | March 14, 2000 | Harkins |
6044155 | March 28, 2000 | Thomlinson et al. |
6055314 | April 25, 2000 | Spies et al. |
6058424 | May 2, 2000 | Dixon et al. |
6061790 | May 9, 2000 | Bodnar |
6069957 | May 30, 2000 | Richards |
6085323 | July 4, 2000 | Shimizu et al. |
6088717 | July 11, 2000 | Reed et al. |
6088805 | July 11, 2000 | Davis et al. |
6098056 | August 1, 2000 | Rusnak et al. |
6101507 | August 8, 2000 | Cane et al. |
6105131 | August 15, 2000 | Carroll |
6122630 | September 19, 2000 | Strickler et al. |
6134327 | October 17, 2000 | Van Oorschot |
6134658 | October 17, 2000 | Multerer et al. |
6134660 | October 17, 2000 | Boneh et al. |
6134664 | October 17, 2000 | Walker |
6141754 | October 31, 2000 | Choy |
6145084 | November 7, 2000 | Zuili |
6158010 | December 5, 2000 | Moriconi et al. |
6161139 | December 12, 2000 | Win et al. |
6182142 | January 30, 2001 | Win et al. |
6185684 | February 6, 2001 | Pravetz et al. |
6192408 | February 20, 2001 | Vahalia et al. |
6205549 | March 20, 2001 | Pravetz et al. |
6212561 | April 3, 2001 | Sitaraman et al. |
6223285 | April 24, 2001 | Komuro et al. |
6226618 | May 1, 2001 | Downs et al. |
6226745 | May 1, 2001 | Wiederhold et al. |
6240188 | May 29, 2001 | Dondeti et al. |
6249873 | June 19, 2001 | Richard et al. |
6253193 | June 26, 2001 | Ginter et al. |
6260040 | July 10, 2001 | Kauffman et al. |
6260141 | July 10, 2001 | Park |
6263348 | July 17, 2001 | Kathrow et al. |
6272631 | August 7, 2001 | Thomlinson et al. |
6272632 | August 7, 2001 | Carmen et al. |
6282649 | August 28, 2001 | Lambert et al. |
6289450 | September 11, 2001 | Pensak et al. |
6292895 | September 18, 2001 | Baltzley |
6292899 | September 18, 2001 | McBride |
6295361 | September 25, 2001 | Kadansky et al. |
6301614 | October 9, 2001 | Najork et al. |
6308256 | October 23, 2001 | Folmsbee |
6308273 | October 23, 2001 | Goertzel et al. |
6314409 | November 6, 2001 | Schnek et al. |
6317777 | November 13, 2001 | Skarbo et al. |
6332025 | December 18, 2001 | Takahashi et al. |
6336114 | January 1, 2002 | Garrison |
6339423 | January 15, 2002 | Sampson et al. |
6339825 | January 15, 2002 | Pensak et al. |
6341164 | January 22, 2002 | Dilkie et al. |
6343316 | January 29, 2002 | Sakata |
6347374 | February 12, 2002 | Drake et al. |
6349337 | February 19, 2002 | Parsons et al. |
6351813 | February 26, 2002 | Mooney et al. |
6356903 | March 12, 2002 | Baxter et al. |
6356941 | March 12, 2002 | Cohen |
6357010 | March 12, 2002 | Viets et al. |
6363480 | March 26, 2002 | Perlman |
6370249 | April 9, 2002 | Van Oorschot |
6381698 | April 30, 2002 | Devanbu et al. |
6389433 | May 14, 2002 | Bolosky et al. |
6389538 | May 14, 2002 | Gruse et al. |
6393420 | May 21, 2002 | Peters |
6405315 | June 11, 2002 | Burns et al. |
6421714 | July 16, 2002 | Rai et al. |
6442688 | August 27, 2002 | Moses et al. |
6442695 | August 27, 2002 | Dutcher et al. |
6446090 | September 3, 2002 | Hart |
6449721 | September 10, 2002 | Pensak et al. |
6453353 | September 17, 2002 | Win et al. |
6466932 | October 15, 2002 | Dennis et al. |
6477544 | November 5, 2002 | Bolosky et al. |
6490680 | December 3, 2002 | Scheidt et al. |
6505300 | January 7, 2003 | Chan et al. |
6510349 | January 21, 2003 | Schnek et al. |
6519700 | February 11, 2003 | Ram et al. |
6529956 | March 4, 2003 | Smith et al. |
6530020 | March 4, 2003 | Aoki |
6530024 | March 4, 2003 | Proctor |
6542608 | April 1, 2003 | Scheidt et al. |
6549623 | April 15, 2003 | Scheidt et al. |
6550011 | April 15, 2003 | Sims |
6557039 | April 29, 2003 | Leong et al. |
6567914 | May 20, 2003 | Just et al. |
6571291 | May 27, 2003 | Chow |
6584466 | June 24, 2003 | Serbinis et al. |
6587946 | July 1, 2003 | Jakobsson |
6588673 | July 8, 2003 | Chan et al. |
6594662 | July 15, 2003 | Sieffert et al. |
6598161 | July 22, 2003 | Kluttz et al. |
6603857 | August 5, 2003 | Batten-Carew et al. |
6608636 | August 19, 2003 | Roseman |
6611599 | August 26, 2003 | Natarajan |
6611846 | August 26, 2003 | Stoodley |
6615349 | September 2, 2003 | Hair |
6615350 | September 2, 2003 | Schell et al. |
6625650 | September 23, 2003 | Stelliga |
6629243 | September 30, 2003 | Kleinman et al. |
6633311 | October 14, 2003 | Douvikas et al. |
6640307 | October 28, 2003 | Viets et al. |
6646515 | November 11, 2003 | Jun et al. |
6647388 | November 11, 2003 | Numao et al. |
6678835 | January 13, 2004 | Shah et al. |
6687822 | February 3, 2004 | Jakobsson |
6711683 | March 23, 2004 | Laczko et al. |
6718361 | April 6, 2004 | Basani et al. |
6735701 | May 11, 2004 | Jacobson |
6738908 | May 18, 2004 | Bonn et al. |
6775779 | August 10, 2004 | England et al. |
6782403 | August 24, 2004 | Kino et al. |
6801999 | October 5, 2004 | Venkatesan et al. |
6807534 | October 19, 2004 | Erickson |
6807636 | October 19, 2004 | Hartman et al. |
6810389 | October 26, 2004 | Meyer |
6810479 | October 26, 2004 | Barlow et al. |
6816871 | November 9, 2004 | Lee |
6826698 | November 30, 2004 | Minkin et al. |
6834333 | December 21, 2004 | Yoshino et al. |
6834341 | December 21, 2004 | Bahl et al. |
6845452 | January 18, 2005 | Roddy et al. |
6851050 | February 1, 2005 | Singhal et al. |
6865555 | March 8, 2005 | Novak |
6874139 | March 29, 2005 | Krueger et al. |
6877136 | April 5, 2005 | Bess et al. |
6889210 | May 3, 2005 | Vainstein |
6891953 | May 10, 2005 | DeMello et al. |
6892201 | May 10, 2005 | Brown et al. |
6892306 | May 10, 2005 | En-Seung et al. |
6907034 | June 14, 2005 | Begis |
6909708 | June 21, 2005 | Krishnaswamy et al. |
6915434 | July 5, 2005 | Kuroda et al. |
6920558 | July 19, 2005 | Sames et al. |
6931450 | August 16, 2005 | Howard et al. |
6931530 | August 16, 2005 | Pham et al. |
6931597 | August 16, 2005 | Prakash |
6938042 | August 30, 2005 | Aboulhosn et al. |
6941355 | September 6, 2005 | Donaghey et al. |
6941456 | September 6, 2005 | Wilson |
6941472 | September 6, 2005 | Moriconi et al. |
6944183 | September 13, 2005 | Iyer et al. |
6947556 | September 20, 2005 | Matyas, Jr. et al. |
6950818 | September 27, 2005 | Dennis et al. |
6950936 | September 27, 2005 | Subramaniam et al. |
6950941 | September 27, 2005 | Lee et al. |
6950943 | September 27, 2005 | Bacha et al. |
6952780 | October 4, 2005 | Olsen et al. |
6957261 | October 18, 2005 | Lortz |
6959308 | October 25, 2005 | Gramsamer et al. |
6961849 | November 1, 2005 | Davis et al. |
6968060 | November 22, 2005 | Pinkas |
6971018 | November 29, 2005 | Witt et al. |
6978376 | December 20, 2005 | Giroux et al. |
6978377 | December 20, 2005 | Asano et al. |
6988133 | January 17, 2006 | Zavalkovsky et al. |
6988199 | January 17, 2006 | Toh et al. |
6993135 | January 31, 2006 | Ishibashi |
6996718 | February 7, 2006 | Henry et al. |
7003117 | February 21, 2006 | Kacker et al. |
7003560 | February 21, 2006 | Mullen et al. |
7003661 | February 21, 2006 | Beattie et al. |
7013332 | March 14, 2006 | Friedel et al. |
7013485 | March 14, 2006 | Brown et al. |
7020645 | March 28, 2006 | Bisbee et al. |
7024427 | April 4, 2006 | Bobbitt et al. |
7035854 | April 25, 2006 | Hsiao et al. |
7035910 | April 25, 2006 | Dutta et al. |
7046807 | May 16, 2006 | Hirano et al. |
7051213 | May 23, 2006 | Kobayashi et al. |
7058696 | June 6, 2006 | Phillips et al. |
7058978 | June 6, 2006 | Feuerstein et al. |
7073063 | July 4, 2006 | Peinado |
7073073 | July 4, 2006 | Nonaka et al. |
7076067 | July 11, 2006 | Raike et al. |
7076312 | July 11, 2006 | Law et al. |
7076469 | July 11, 2006 | Schreiber et al. |
7076633 | July 11, 2006 | Tormasov et al. |
7080077 | July 18, 2006 | Ramamurthy et al. |
7095853 | August 22, 2006 | Morishita |
7096266 | August 22, 2006 | Lewin et al. |
7099926 | August 29, 2006 | Ims et al. |
7107269 | September 12, 2006 | Arlein et al. |
7107416 | September 12, 2006 | Stuart et al. |
7117322 | October 3, 2006 | Hochberg et al. |
7120635 | October 10, 2006 | Bhide et al. |
7120757 | October 10, 2006 | Tsuge |
7124164 | October 17, 2006 | Chemtob |
7130964 | October 31, 2006 | Ims et al. |
7131071 | October 31, 2006 | Gune et al. |
7134041 | November 7, 2006 | Murray et al. |
7136903 | November 14, 2006 | Phillips et al. |
7145898 | December 5, 2006 | Elliott |
7146388 | December 5, 2006 | Stakutis et al. |
7146498 | December 5, 2006 | Takechi et al. |
7159036 | January 2, 2007 | Hinchliffe et al. |
7171557 | January 30, 2007 | Kallahalla et al. |
7174563 | February 6, 2007 | Brownlie et al. |
7177427 | February 13, 2007 | Komuro et al. |
7178033 | February 13, 2007 | Garcia |
7181017 | February 20, 2007 | Nagel et al. |
7185364 | February 27, 2007 | Knouse et al. |
7187033 | March 6, 2007 | Pendharkar |
7188181 | March 6, 2007 | Squier et al. |
7194764 | March 20, 2007 | Martherus et al. |
7200747 | April 3, 2007 | Riedel et al. |
7203317 | April 10, 2007 | Kallahalla et al. |
7203968 | April 10, 2007 | Asano et al. |
7219230 | May 15, 2007 | Riedel et al. |
7224795 | May 29, 2007 | Takada et al. |
7225256 | May 29, 2007 | Villavicencio |
7227953 | June 5, 2007 | Shida |
7233948 | June 19, 2007 | Shamoon et al. |
7237002 | June 26, 2007 | Estrada et al. |
7249044 | July 24, 2007 | Kumar et al. |
7260555 | August 21, 2007 | Rossmann et al. |
7265764 | September 4, 2007 | Alben et al. |
7266684 | September 4, 2007 | Jancula |
7280658 | October 9, 2007 | Amini et al. |
7287055 | October 23, 2007 | Smith et al. |
7290148 | October 30, 2007 | Tozawa et al. |
7308702 | December 11, 2007 | Thomsen et al. |
7313824 | December 25, 2007 | Bala et al. |
7319752 | January 15, 2008 | Asano et al. |
7340600 | March 4, 2008 | Corella |
7362868 | April 22, 2008 | Madoukh et al. |
7380120 | May 27, 2008 | Garcia |
7383586 | June 3, 2008 | Cross et al. |
7386529 | June 10, 2008 | Kiessig et al. |
20010011254 | August 2, 2001 | Clark |
20010021926 | September 13, 2001 | Schnek et al. |
20010032181 | October 18, 2001 | Jakstadt et al. |
20010034839 | October 25, 2001 | Karjoth et al. |
20010044903 | November 22, 2001 | Yamamoto et al. |
20010056550 | December 27, 2001 | Lee |
20020010679 | January 24, 2002 | Felsher |
20020016922 | February 7, 2002 | Richards et al. |
20020031230 | March 14, 2002 | Sweet et al. |
20020035624 | March 21, 2002 | Kim |
20020046350 | April 18, 2002 | Lordemann et al. |
20020050098 | May 2, 2002 | Chan |
20020056042 | May 9, 2002 | Van Der Kaay et al. |
20020062240 | May 23, 2002 | Morinville |
20020062245 | May 23, 2002 | Niu et al. |
20020069077 | June 6, 2002 | Brophy et al. |
20020069272 | June 6, 2002 | Kim et al. |
20020069363 | June 6, 2002 | Winburn |
20020073320 | June 13, 2002 | Rinkevich et al. |
20020077986 | June 20, 2002 | Kobata et al. |
20020077988 | June 20, 2002 | Sasaki et al. |
20020087479 | July 4, 2002 | Malcolm |
20020099947 | July 25, 2002 | Evans |
20020124180 | September 5, 2002 | Hagman |
20020129235 | September 12, 2002 | Okamoto et al. |
20020133699 | September 19, 2002 | Pueschel |
20020138762 | September 26, 2002 | Horne |
20020143710 | October 3, 2002 | Liu |
20020143906 | October 3, 2002 | Tormasov et al. |
20020156726 | October 24, 2002 | Kleckner et al. |
20020157016 | October 24, 2002 | Russell et al. |
20020169963 | November 14, 2002 | Seder et al. |
20020169965 | November 14, 2002 | Hale et al. |
20020172367 | November 21, 2002 | Mulder et al. |
20020174109 | November 21, 2002 | Chandy et al. |
20020176572 | November 28, 2002 | Ananth |
20020178271 | November 28, 2002 | Graham et al. |
20020194484 | December 19, 2002 | Bolosky et al. |
20020198798 | December 26, 2002 | Ludwig et al. |
20030009685 | January 9, 2003 | Choo et al. |
20030014391 | January 16, 2003 | Evans et al. |
20030023559 | January 30, 2003 | Choi et al. |
20030028610 | February 6, 2003 | Pearson |
20030033528 | February 13, 2003 | Ozog et al. |
20030037133 | February 20, 2003 | Owens |
20030037237 | February 20, 2003 | Abgrall et al. |
20030037253 | February 20, 2003 | Blank et al. |
20030046238 | March 6, 2003 | Nonaka et al. |
20030051039 | March 13, 2003 | Brown et al. |
20030056139 | March 20, 2003 | Murray et al. |
20030074580 | April 17, 2003 | Knouse et al. |
20030078959 | April 24, 2003 | Yeung et al. |
20030079175 | April 24, 2003 | Limantsev |
20030081784 | May 1, 2003 | Kallahalla et al. |
20030081787 | May 1, 2003 | Kallahalla et al. |
20030088517 | May 8, 2003 | Medoff |
20030088783 | May 8, 2003 | DiPierro |
20030101072 | May 29, 2003 | Dick et al. |
20030110169 | June 12, 2003 | Zuili |
20030110266 | June 12, 2003 | Rollins et al. |
20030110397 | June 12, 2003 | Supramaniam |
20030115146 | June 19, 2003 | Lee et al. |
20030115570 | June 19, 2003 | Bisceglia |
20030120601 | June 26, 2003 | Ouye |
20030120684 | June 26, 2003 | Zuili et al. |
20030126434 | July 3, 2003 | Lim et al. |
20030154381 | August 14, 2003 | Ouye |
20030159066 | August 21, 2003 | Staw et al. |
20030172280 | September 11, 2003 | Scheidt et al. |
20030177070 | September 18, 2003 | Viswanth et al. |
20030177378 | September 18, 2003 | Wittkotter |
20030182579 | September 25, 2003 | Leporini et al. |
20030196096 | October 16, 2003 | Sutton |
20030197729 | October 23, 2003 | Denoue et al. |
20030200202 | October 23, 2003 | Hsiano et al. |
20030217264 | November 20, 2003 | Martin et al. |
20030217281 | November 20, 2003 | Ryan |
20030217333 | November 20, 2003 | Smith et al. |
20030226013 | December 4, 2003 | Dutertre |
20030233650 | December 18, 2003 | Zaner et al. |
20040022390 | February 5, 2004 | McDonald et al. |
20040025037 | February 5, 2004 | Hair |
20040039781 | February 26, 2004 | LaVallee et al. |
20040064710 | April 1, 2004 | Vainstein |
20040068524 | April 8, 2004 | Aboulhosn et al. |
20040068664 | April 8, 2004 | Nachenberg et al. |
20040073660 | April 15, 2004 | Toomey |
20040073718 | April 15, 2004 | Johannessen et al. |
20040088548 | May 6, 2004 | Smetters et al. |
20040098580 | May 20, 2004 | DeTreville |
20040103202 | May 27, 2004 | Hildenbrand et al. |
20040103280 | May 27, 2004 | Balfanz et al. |
20040133544 | July 8, 2004 | Kiessig et al. |
20040158586 | August 12, 2004 | Tsai |
20040193602 | September 30, 2004 | Liu et al. |
20040193905 | September 30, 2004 | Lirov et al. |
20040193912 | September 30, 2004 | Li et al. |
20040199514 | October 7, 2004 | Rosenblatt et al. |
20040215956 | October 28, 2004 | Venkatachary et al. |
20040215962 | October 28, 2004 | Douceur et al. |
20040243853 | December 2, 2004 | Swander et al. |
20050021467 | January 27, 2005 | Franzdonk |
20050021629 | January 27, 2005 | Cannata et al. |
20050028006 | February 3, 2005 | Leser et al. |
20050039034 | February 17, 2005 | Doyle et al. |
20050071275 | March 31, 2005 | Vainstein et al. |
20050071657 | March 31, 2005 | Ryan |
20050071658 | March 31, 2005 | Nath et al. |
20050081029 | April 14, 2005 | Thornton et al. |
20050086531 | April 21, 2005 | Kenrich |
20050091484 | April 28, 2005 | Thornton et al. |
20050120199 | June 2, 2005 | Carter |
20050138371 | June 23, 2005 | Supramaniam |
20050138383 | June 23, 2005 | Vainstein |
20050177716 | August 11, 2005 | Ginter et al. |
20050177858 | August 11, 2005 | Ueda |
20050198326 | September 8, 2005 | Schlimmer et al. |
20050223242 | October 6, 2005 | Nath |
20050223414 | October 6, 2005 | Kenrich et al. |
20050235154 | October 20, 2005 | Serret-Avila |
20050256909 | November 17, 2005 | Aboulhosn et al. |
20050273600 | December 8, 2005 | Seeman |
20050283610 | December 22, 2005 | Serret-Avila et al. |
20050288961 | December 29, 2005 | Tabrizi |
20060005021 | January 5, 2006 | Torrubia-Saez |
20060075465 | April 6, 2006 | Ramanathan et al. |
20060093150 | May 4, 2006 | Reddy et al. |
20060168147 | July 27, 2006 | Inoue et al. |
20060230437 | October 12, 2006 | Boyer et al. |
20070006214 | January 4, 2007 | Dubal et al. |
20070067837 | March 22, 2007 | Schuster |
0 647 253 | September 1995 | EP |
0 672 991 | September 1995 | EP |
0 809 170 | November 1997 | EP |
0 913 966 | May 1999 | EP |
0 913 967 | May 1999 | EP |
0 950 941 | October 1999 | EP |
0 950 941 | October 1999 | EP |
1 107504 | June 2001 | EP |
1 107 504 | June 2001 | EP |
1 130 492 | September 2001 | EP |
1 154 348 | November 2001 | EP |
1324565 | July 2003 | EP |
2 328 047 | February 1999 | GB |
2001-036517 | February 2001 | JP |
02001036517 | February 2001 | JP |
2006244044 | September 2006 | JP |
WO 96/41288 | December 1996 | WO |
WO 01/61438 | August 2001 | WO |
WO 01/63387 | August 2001 | WO |
WO 01/63387 | August 2001 | WO |
WO 01/77783 | October 2001 | WO |
WO 01/78285 | October 2001 | WO |
WO 01/84271 | November 2001 | WO |
- Search Report, completion date Apr. 14, 2005, for European Patent Application No. EP 02 25 8533, 2 pages.
- Search Report, completion date Mar. 16, 2005, for European Patent Application No. EP 02 25 8534, 2 pages.
- Search Report, completion date Mar. 2, 2005, for European Patent Application No. EP 02 25 8535, 2 pages.
- Search Report, completion date Mar. 3, 2005, for European Patent Application No. EP 02 25 8537, 2 pages.
- Search Report, completion date May 12, 2005, for European Patent Application No. EP 02 25 8539, 2 pages.
- Search Report, completion date Jul. 6, 2005, for European Patent Application No. EP 02 25 8529, 4 pages.
- Search Report, completion date Oct. 8, 2003, for European Patent Application No. EP 02 25 8536, 2 pages.
- Search Report, completion date May 8, 2003, for European Patent Application No. EP 02 25 8540, 2 pages.
- U.S. Appl. No. 10/259,075, entitled “Effectuating Access Policy Changes to Designated Places for Secured Files,” inventor Crocker, Sep. 27, 2002, 60 pgs.
- U.S. Appl. No. 10/286,575, entitled “Method and Architecture for Providing Acess to Secured Data from Non-Secured Clients,” inventor Vainstein, Nov. 1, 2002, 46 pgs.
- U.S. Appl. No. 10/295,363, entitled “Security System Using Indirect Key Generation from Access Rules and Methods Therefor,” inventor Vainstein, Nov. 15, 2002, 70 pgs.
- U.S. Appl. No. 11/889,310, entitled “Methods and Systems for Providing Access Control to Electronic Data, ” inventor Rossmann, Aug. 10, 2007, 90 pgs.
- Adobe Acrobat 5.0 Classroom in a Book, Adobe Press, Jun. 26, 2001, pp. 1-4.
- Adobe Acrobat Security Settings, Acrobat 7.0, Nov. 15, 2004, pp. 1-4.
- “Security Options”. Dec. 20, 2001. DC & Co. pp. 1-2.
- Microsoft Press Computer Dictionary, 1997, Microsoft Press, Third Edition, p. 426.
- Search Report, completion date May 8, 2003, for European Patent Application No. EP 02 25 8530, 2 pages.
- Search Report, completion date Oct. 2, 2003, for European Patent Application No. EP 02 25 8531, 2 pages.
- U.S. Appl. No. 10/074,194, entitled “Methods for identifying compunds that inhibit or reduce PTP1B expressions” inventor Rondinone, Feb. 12, 2002, 69 pgs.
- U.S. Appl. No. 10/074,804, entitled “Secured Data Format for Access Control,” inventor Garcia, Feb. 12, 2002, 108 pgs.
- U.S. Appl. No. 10/075,194, entitled “System and Method for Providing Multi-location Access Management to Secured Items,” inventor Vainstein et al., Feb. 12, 2002, 110 pgs.
- U.S. Appl. No. 10/074,996, entitled “Method and Apparatus for Securing Electronic Data,” inventor Lee et al., Feb. 12, 2002, 111 pgs.
- U.S. Appl. No. 10/074,825, entitled “Method and Apparatus for Accessing Secured Electronic Data Off-line, ” inventor Lee et al., Feb. 12, 2002, 108 pgs.
- U.S. Appl. No. 10/105,532, entitled “System and Method for Providing Different Levels of Key Security for Controlling Access to Secured Items,” inventor Hildebrand et al., Mar. 20, 2002, 86 pgs.
- U.S. Appl. No. 10/186,203, entitled “Method and System for Implementing Changes to Security Policies in a Distributed Security System,” inventor Huang, Jun. 26, 2002, 65 pgs.
- U.S. Appl. No. 10/201,756, entitled “Managing Secured Files in Designated Locations,” inventor Alain, Jul. 22, 2002, 121 pgs.
- U.S. Appl. No. 10/206,737, entitled “Method and System for Updating Keys in a Distributed Security System,” inventor Hildebrand, Jul. 26, 2002, 60 pgs.
- U.S. Appl. No. 10/246,079, entitled “Security System for Generating Keys from Access rules in a Decentralized Manner and Methods Therefor,” inventor Hildebrand, Sep. 17, 2002, 78 pgs.
- A Real-Time Push-Pull Communications Model for Distributed Real-Time and Multimedia Systems, Jan. 1999, School of Computer Sciences Carnegie Mellon University, Kanaka Juvva, Raj Rajkurmar.
- U.S. Appl. No. 10/889,685, entitled “Method and Apparatus for Controlling the Speed Ranges of a Machine” inventor Thomas, Jul. 13, 2004, 18 pgs.
- U.S. Appl. No. 10/028,397, entitled “Method and system for resisting use of a clipboard application,” inventor Zuili, Dec. 21, 2001, 38 pgs.
- U.S. Appl. No. 10/368,277, entitled “Method and apparatus for uniquely identifying files,” inventor Ouye, Feb. 18, 2003, 25 pgs.
- U.S. Appl. No. 10/327,320, entitled “Security system with staging capabilities” inventor Vainstein, Dec. 20, 2002, 39 pgs.
- U.S. Appl. No. 10/286,524, entitled “Security system that uses indirect password-based encryption, ” inventor Gutnik, Nov. 1, 2002, 38 pgs.
- U.S. Appl. No. 10/242,185, entitled “Method and system for protecting encrypted files transmitted over a network ” inventor Ryan, Sep. 11, 2002, 23 pgs.
- U.S. Appl. No. 10/642,041, entitled “Method and system for fault-tolerant transfer of files across a network” inventor Kenrich, Aug. 15, 2003, 32 pgs.
- U.S. Appl. No. 10/610,832, entitled “Method and system for enabling users of a group shared across multiple security systems to access secured files” inventor Ryan, Jun. 30, 2003, 33 pgs.
- U.S. Appl. No. 10/448,806, entitled “Method and System for Using Remote Headers to Secure Electronic Files” inventor Ryan, May 30, 2003, 35 pgs.
- “Windows 2000 EFS” in the Apr. 1999 issue of Windows NT magazine.
- Microsoft Windows 200 server. Windows 2000 Group Policy White Paper, 2000.
- Symantec. Norton Antivirus Corporate Edition Implementation Guide, 1999.
- Crocker, Steven Toye, “Multi-level cryptographic transformations for securing digital assets,” U.S. Appl. No. 10/404,566,, filed Mar. 31, 2003.
- Crocker, Steven Toye, “Effectuating access policy changes to designated places for secured files,” U.S. Appl. No. 10/259,075, filed Sep. 27, 2002.
- Kenrich, Michael Frederick, “Multi-Level File Digest”, U.S. Appl. No. 10/894,493, filed Jul. 19, 2004.
- Kinghorn, Gary Mark, “Method and system for protecting electronic data in enterprise environment,” U.S. Appl. No. 10/159,220, filed May 31, 2002.
- Nath, Satyajit, “Method and system for securing digital assets using content type designations,” U.S. Appl. No. 10/405,587, filed Apr. 1, 2003.
- Prakash, Nalini J., “Method and apparatus for securiting/unsecuring files crawling,” U.S. Appl. No. 10/325,102, filed Dec. 20, 2002.
- Rossmann, Alain, “Hybrid systems for securing digital assets,” U.S Appl. No. 10/325,013, filed Dec. 20, 2002.
- Expiration Mechanism for Chipcards, IBM Technical Disclosure Bulletin, Oct. 1, 2001, UK.
- McDaniel et al. “Antigone: A Flexible Framework for Secure Group Communication,” Proceedings of the 8th USENIX Security Symposium, Aug. 23, 1999.
- Stallings, William, “Cryptography and Network Security: Principles and Practice” 1999, pp. 333-337, Second Edition, Prentice Hall, Upper Saddle River, New Jersey.
- “Affect,” The American Hertage Dictionary of the English Language, Fourth Edition, Houghton Mifflin Company, 2002. Retrieved May 4, 2006 from http://dictionary.reference.com/search?q=affect.
- “Inside Encryping file system,” Part 1, from MSDN Oct. 2001, version, exact publication date is unknown but believed prior to Dec. 12, 2001.
- “Inside Encryping file system,” Part 2, from MSDN Oct. 2001 version, exact publication date is unknown but believed prior to Dec. 12, 2001.
- “Security with Encryping File System,” from MSDN Oct. 2001 version, exact publication date is unknown but believed prior to Dec. 12, 2001.
- “How EFS work,” from MSDN Oct. 2001 version, exact publication date is unknown but believed prior to Dec. 12, 2001.
- “Encryping File System,” from MSDN Oct. 2001 version, exact publication date is unknown but believed prior to Dec. 12, 2001.
- “Features of EFS” from MSDN Oct. 2001 version, exact publication date is unknown but believed prior to Dec. 12, 2001.
- Examination Report, completion date Jun. 18, 2008, for European Patent Application No. EP 02 258 532.7-1244, 6 pgs.
- Office Action, dated May 10, 2005, for European Patent Application No. 02258532.7, 5 pgs.
- Office Action, dated Dec. 5, 2006, for European Patent Application No. 02258532.7, 5 pgs.
- Boneh et al., “Hierarchical Identity Based Encryption with Constant Size Ciphertext,” Advances in Cryptology—EUROCRYPT 2005, vol. 3493, Jun. 20, 2005, pp. 440-456.
- Boneh et al., “IBE Secure E-Mail,” Stanford University, Apr. 8, 2002.
- IBM Technical Disclosure bulletin; Oct. 2001 UK; Expiration mechanism for chipcards.
Type: Grant
Filed: May 2, 2007
Date of Patent: Aug 17, 2010
Inventor: Klimenty Vainstein (San Francisco, CA)
Primary Examiner: Pierre E Elisca
Attorney: Sterne, Kessler, Goldstein & Fox PLLC
Application Number: 11/797,367
International Classification: G06F 21/00 (20060101);