发明名称 Protecting information using policies and encryption
摘要 A technique and system protects documents at rest and in motion using declarative policies and encryption. Encryption in the system is provided transparently and can work in conjunction with policy enforcers installed at a system. A system can protect information or documents from: (i) insider theft; (ii) ensure confidentiality; and (iii) prevent data loss, while enabling collaboration both inside and outside of a company.
申请公布号 US8843734(B2) 申请公布日期 2014.09.23
申请号 US201213439827 申请日期 2012.04.04
申请人 NextLabs, Inc. 发明人 Lim Keng
分类号 G06F21/00;H04L12/58;G06F21/60;H04L9/00;H04L29/06 主分类号 G06F21/00
代理机构 Aka Chan LLP 代理人 Aka Chan LLP
主权项 1. A method comprising: providing a document management system managing a plurality of documents wherein the document management system comprises clients and servers; at a first client, executing a first policy enforcer program; at the first client, trapping by the first policy enforcer program a request by an e-mail application to send an e-mail with a document attachment, managed by the document management system, to a second client; at the first policy enforcer program, evaluating at least one policy associated with the document attachment; as a result of the evaluating, determining that the send request is allowed, but before allowing the e-mail application to send the document attachment, encrypting the document attachment; allowing the e-mail application to send the encrypted document attachment to the second client; sending a notification from a second policy enforcer regarding an attempt at the second client to open the encrypted document; determining the attempt at the second client is allowed according to a first policy; at the second client, determining that the encrypted document is encrypted; providing an encryption module executing at the second client; with the second policy enforcer program, requesting a key that will allow decryption of the encrypted document; passing the key to the encryption module; and at the encryption module, using the key to unencrypt the encrypted document attachment and obtaining the unencrypted document attachment.
地址 San Mateo CA US