Methods to dynamically establish overall national security or sensitivity classification for information contained in electronic documents; to provide control for electronic document/information access and cross domain document movement; to establish virtual security perimeters within or among computer networks for electronic documents/information; to enforce physical security perimeters for electronic documents between or among networks by means of a perimeter breach alert system
Abstract
The invention is an a document classification and marking engine/method that functions in a real-time compatible mode with off-the-shelf word processors, e-mail programs and presentation or other document development software applications. The software engine is used for the security classification of sensitive or national security classified information in electronic format and is enhanced by methods and processes that ensure that the software classification engine considers all document informational elements regardless of attributes assigned to the text that may hide text from the user. The software engine provides a complete and reliable document classification determination interface method based on user selections and uniquely codes the full text classification determination in a persistent manner within the electronic shell of the document in real-time and dynamically displays the text based full classification determination in the banner of the host document development application. The unique codes of the full classification embedded in the electronic shell of the document enable effective and reliable software processes and methods that establish controls for access, movement, storage etc. for electronic documents, as well as virtual electronic security perimeters, on a computer, networks of computers and/or among computer networks and domains of networks. The full or complete and persistent classification codes embedded in the document shell also enables reliable software processes and methods that immediately warn or alert security personnel of a beach of a physical security perimeter between or among computers networks or domains of networks established to protect the information contained in electronic document format.
Claims
exact text as granted — not AI-modified1 . A computer system comprising a method and system in real-time, by means of a user interface or desk-top tool functioning in conjunction with and within a host document development software application, to assure that users of the document development application assess and make classification determinations on all possible informational content of an electronic document regardless of the attributes (visible, hidden, etc) assigned to the informational portions of the electronic document by the host document development software or user's (past or present) of the document development software, or the location of the information within the total electronic, digital, computer, or machine representation of the document.
2 . The method and system of claim 1 further comprising a method and system to monitor in real-time user changes in the text/informational content of a document via the host document development software application to assure that added information, portions and/or changes to portions or information are identified and presented to the document user/classifier in real-time, for the purpose of assessing and properly classifying or maintaining the proper classification of the full or complete information of an electronic document, and the posting in local and/or network databases the document changes and any corresponding or resultant user classification events.
3 . The method and system of claim 2 further comprising of a method and system to dynamically provide real-time, constant, visible feedback to the developer/classifier of electronic documents, or subsequent users of an electronic document, of the full text based classification determination, or classification mark, for all of the informational content of the complete electronic document, within the banner display scheme of the host document development software application.
4 . The method and system of claim 3 further comprising a method and system to dynamically, in real-time, assess and display within the host document development software application the proper classification determination, or classification mark, in a text based format in accordance with the classification rules and regulations of an organization, for subset electronic, informational views or displays of an electronic document, and potentially printed hard copy subsets of the full informational content of an electronic document, within the current informational subset view or display of the document in the host application, while persistently maintaining the full classification determination for all of the information contained in the document in the banner of the document development software.
5 . The method and system of claim 4 further comprising of a method and system to dynamically post in real-time a unique, machine readable code that represents the full or complete text based classification determination of all the information contained in an electronic document into the electronic shell of an electronic document.
6 . The method and system of claim 5 further comprising of a system and method to ensure that the codes representing the total text based classification determination of all of the informational content of an electronic document are persistently embedded into the electronic shell of an electronic document and cannot be changed outside of the host document development software without detection.
7 . The method and system of claim 6 further comprising a system and method to dynamically, in real-time, post and record the full or complete classification determination for all of the information in an electronic document, to a local and/or network databases, to log current document classification status, and pertinent document information as well as assigning a unique identification code to each document for the purpose of positively tracking document changes and access and assuring the persistent aspect of the embedded full classification and document identification codes embedded in the electronic shell of electronic documents by the invention's methods.
8 . The method and system of claim 7 further comprising a system and method to monitor in real-time, and identify the removal of, or change to, the full classification code imbedded by the invention into the shell of an electronic document, by means outside of the authorized host document development software for the electronic document, and warning/alerting in real-time of the removal or change to the embedded full classification code, as well as subsequent, immediate re-posting to the electronic shell of the document the proper classification code for the document from a database and logging the event in local and/or network databases for the purpose of assuring the protection of the information contained in the electronic document and the reliability of security controls for the document effected and based on the embedded full classification code in the shell of an electronic document.
9 . The method and system of claim 8 further comprising a system and method to establish and maintain virtual security perimeters in real-time within networks or domains of networks authorized to manage various levels of national security classified or sensitive information, by means of monitoring and assessing the full or complete classification code imbedded into the electronic shell of a document or within storage media for electronic documents, against a controlling database of matrixes of preset conditions, precipitated by an operating system event or call (copy, move, print, send, rename, delete, etc), or a similar software application activity event within a computer, network of computers, or domains of networks, within the physical security perimeter of such networks, for the purpose of determining if the full classification code for the document's information allows the operating system or application event to occur, as well as the logging and recording of successful event activity or attempted/denied event activity in a local and/or network databases for security system oversight and management.
10 . The method and system of claim 9 further comprising a system and method to continuously monitor in real-time computers outside of the physical security perimeter of a certain sensitivity or classification level of a computer, network of computers or domain of networks or otherwise unauthorized to receive or store predetermined levels of classified or sensitive information, for full classification codes embedded into the shells of electronic, or on storage media for electronic documents, for the purpose of positive and immediate identification of breaches of physical security perimeters and the real-time notification of such security perimeter breaches to predetermined security or management personnel and/or the real-time initiation of computer, network or domain active measures to prevent the further dissemination of the information in accordance with preset matrixes in a controlling database, without jeopardizing or providing undue insight to the sensitivity or classification of the organization's classification criteria used to assign classifications to documents and information.Join the waitlist — get patent alerts
Track US2010186091A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.