Computer method and apparatus for securely managing data objects in a distributed context
Abstract
In a network of intermittently-connected computers, a method and apparatus for maintaining and managing control over data objects authored, accessed, and altered by users in dynamic, distributed, and collaborative contexts. The invention method and apparatus attach to each data object an identification of a respective control policy. Each control policy comprises at least an indication of a subset of the users who may access the data object, an indication of the privileges granted to each subset of users able to access the data object, and an indication of a subset of users who may define or edit the control policy. The invention method and apparatus separate the management of the control policies of data objects from the creation and use of the data objects. The invention method and apparatus automate common policy changes, distribution of policy changes to the enforcement agents, and propagation of control policies to derivative works.
Claims
exact text as granted — not AI-modified1 . A computer method of protecting data objects, said method comprising the steps of:
encrypting a data object with a content encryption key; and encrypting the content encryption key with a key encryption key of a control policy associated with the data object.
2 . The method of protecting data objects of claim 1 , further comprising:
recording a control policy tag corresponding to the data object.
3 . The method of protecting data objects of claim 2 , further comprising:
storing the encrypted content encryption key in the control policy tag.
4 . The method of protecting data objects of claim 3 , further comprising:
decrypting the content encryption key stored in the control policy tag with a cached key encryption key; and decrypting the data object with the decrypted content encryption key.
5 . The method of protecting data objects of claim 2 , wherein the control policy tag is attached to the data object.
6 . The method of protecting data objects of claim 2 , wherein the data object is read-only.
7 . The method of protecting data objects of claim 2 , wherein the control policy tag is constructed on a control policy server.
8 . The method of protecting data objects of claim 2 , wherein the control policy tag is constructed on a client.
9 . The method of protecting data objects of claim 2 , wherein the key encryption key of a control policy has an associated validity period.
10 . The method of protecting data objects of claim 9 , further comprising:
automatically replacing an expired key encryption key of a control policy.
11 . The method of protecting data objects of claim 10 , wherein automatically replacing an expired key encryption key of a control policy further comprises:
selecting a proper key from a set of decryption keys comprising at least one of: a next future key, a current key, a recently expired key, and an old key received from a control policy server.
12 . The method of protecting data objects of claim 2 , further comprising:
storing a second copy of the content key encrypted with a second encryption key in the control policy tag.
13 . The method of protecting data objects claim 12 , wherein the second encryption key is a control policy server key encryption key.
14 . The method of protecting data objects of claim 12 , further comprising:
providing access to a data object with an expired key encryption key of the control policy using the control policy server key encryption key.
15 . The method of protecting data objects of claim 2 , further comprising:
protecting integrity of the control policy tag against tampering.
16 . The method of protecting data objects of claim 15 , wherein the step of protecting the integrity of the control policy tag against tampering further comprises using a secure hash over control policy tag fields.
17 . The method of protecting data objects of claim 2 , further comprising:
checking a control policy server for modifications to the control policy associated with the data object.
18 . The method of protecting data objects of claim 17 wherein the control policy tag comprises a uniform resource locator of a control policy server and a control policy locator.
19 . The method of protecting data objects of claim 17 , further comprising:
revoking a user's access to the data object upon detection of the changes to the control policy that prevent that user from further access to the data object.
20 . The method of protecting data objects of claim 1 , further comprising the step of:
storing the key encryption key of the control policy on a control policy server.
21 . The method of protecting data objects of claim 20 , wherein the control policy comprises at least an indication of a set of users who may access the data object, an indication of privileges granted to each user of the set, and an indication of a set of users who may define or edit the control policy, the method further comprising the steps of:
retrieving a decryption key for the key encryption key of the control policy and the indication of privileges for a user by the user if the user is indicated in the control policy to be in a set of users who may access the data object.
22 . The method of protecting data objects of claim 21 , wherein retrieving the key encryption key of a control policy further comprises determining if a user is authenticated.
23 . The method of protecting data objects of claim 21 , further comprising:
storing an indication of a duration of time for which the user may access the data object; and revoking a user's access to the data object upon expiration of the duration of time.
24 . The method of protecting data objects of claim 23 , further comprising:
decrypting the data object; and allowing the user to access the data object.
25 . The method of protecting data objects of claim 23 , further comprising:
destroying the key encryption key of the control policy upon expiration of the duration of time.
26 . The method of protecting data objects of claim 1 further comprising:
changing the content encryption key whenever the data object is modified.
27 . The method of protecting data objects of claim 2 further comprising:
automatically replacing an expired control policy tag.
28 . The method of protecting data objects of claim 27 , wherein the control policy tag comprises at least one of: a length field and a version field.
29 . The method of protecting data objects of claim 28 , wherein replacing the expired control policy tag further comprises:
sending the control policy tag to a control policy server if a control policy version does not match a current version.Join the waitlist — get patent alerts
Track US2005008163A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.