US2014237233A1PendingUtilityA1

Method and apparatus for providing content

Assignee: ABSIO CORPPriority: May 20, 2010Filed: Apr 29, 2014Published: Aug 21, 2014
Est. expiryMay 20, 2030(~3.8 yrs left)· nominal 20-yr term from priority
H04L 2209/60H04L 9/0894H04L 2209/26G06F 21/30G06Q 2220/10H04L 63/045H04L 63/06H04L 9/0825G06F 2211/008G06F 12/14H04L 9/0822G06F 21/60H04L 9/14H04L 9/30G06F 21/62G06F 21/1086
39
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Methods and systems for enabling content to be securely and conveniently distributed to authorized users are provided. More particularly, content is maintained in encrypted form on sending and receiving devices, and during transport. In addition, policies related to the use of, access to, and distribution of content can be enforced. Features are also provided for controlling the release of information related to users. The distribution and control of contents can be performed in association with a client application that presents content and that manages keys.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method for providing content, comprising:
 using a client application, decrypting a document package containing encrypted first content, a first content key, and at least first information related to the first content by applying a private key;   using the client application, decrypting the encrypted first content obtained from the document package by applying the first content key;   using the client application, providing access to the first content;   discontinuing providing access to the first content; and   overwriting memory containing the first content to remove any unencrypted portion of the first content from the memory.   
     
     
         2 . The method of  claim 1 , further comprising:
 overwriting memory containing the first content key.   
     
     
         3 . The method of  claim 2 , further comprising:
 receiving a command to discontinue access to the first content without saving the first content, wherein discontinuing providing access to the first content is performed in response to the command, and wherein no copy of the first content is maintained on a first device on which the client application that provided access to the first content is running.   
     
     
         4 . The method of  claim 2 , further comprising:
 receiving a command to store the first content;   requesting the first content key by the client application from a content key ring;   applying by the client application the first content key to the first content to encrypt the first content in memory;   saving the encrypted first content in an object store.   
     
     
         5 . The method of  claim 4 , wherein the first content key is obtained from the content key ring in encrypted form. 
     
     
         6 . The method of  claim 5 , further comprising:
 applying by the client application a private key to the encrypted first content key in order to access the first content key.   
     
     
         7 . The method of  claim 1 , further comprising:
 after using the unencrypted first content decryption key to decrypt the encrypted first content, overwriting the unencrypted first content key in memory.   
     
     
         8 . The method of  claim 1 , wherein providing access to the first content includes displaying the first content to a user. 
     
     
         9 . The method of  claim 1 , further comprising:
 while access is provided to the first content, creating modified first content;   requesting a second content key by the client application;   applying the second content key by the client application to the modified first content to encrypted the modified first content in memory;   saving the encrypted modified first content in an object store.   
     
     
         10 . The method of  claim 9 , further comprising:
 in response to requesting a second content key:
 selecting an encryption algorithm; 
 generating the second content key using the selected encryption algorithm; 
 testing a strength of the second content key, wherein the second content key is applied to the modified first content if the testing results in approval of the second content key. 
   
     
     
         11 . The method of  claim 10 , further comprising:
 placing the second content key in a key ring;   overwriting the second content key in memory.   
     
     
         12 . A system for distributing content, comprising:
 a first device;   a first client application running on the first device;   first data storage associated with the first device;   a first document stored as an encrypted first document in an object store on the first data storage of the first device;   first encrypted information related to the first encrypted document stored in the object store on the first data storage of the first device;   an encrypted first content key for decrypting the first encrypted document stored as part of a first content key ring on the first data storage of the first device,   wherein a first system key is required to be applied by the first client application to decrypt the encrypted first content key and to thereby access the first content key,   wherein the first client application enables the first content key to be used to decrypt the first encrypted document,   wherein the first content key for decrypting the first encrypted document stored as part of the first content key ring cannot be directly accessed by a user of the first device,   wherein the first client application applies the first content key to decrypt the first encrypted document and to provide access to the first document to a user, and   wherein following the decryption of the first encrypted document the decrypted first content key is overwritten in memory.   
     
     
         13 . The system of  claim 12 , further comprising:
 a display associated with the first device, wherein providing access to the first document includes presenting the first client application presenting the first document on the display.   
     
     
         14 . The system of  claim 13 , wherein the first document is only stored on the first data storage as the first encrypted document. 
     
     
         15 . A method for distributing content, comprising:
 receiving a first data wrapper containing first encrypted content at a first computer, a first content key, and at least first information related to the first encrypted content;   applying using first computer programming running on the first computer a first user key to the first data wrapper, wherein the first encrypted content is removed from the first data wrapper and stored in an object store in encrypted form, wherein the first content key is stored in a key ring in encrypted form as an encrypted first content key, and wherein the information related to the first encrypted content is stored in the object store in encrypted form;   applying using the first computer programming running on the first computer a first system key to the encrypted first content key to thereby obtain the first content key;   applying using the first computer programming running on the first computer the first content key to the first encrypted content, wherein the first encrypted content is decrypted to obtain first content;   accessing using the first computer programming the first content, wherein actions a user takes with respect to the first content are limited according to permissions associated with the first decrypted content; and   overwriting the first content in memory.   
     
     
         16 . The method of  claim 15 , further comprising:
 in response to an instruction to save the first content, encrypting the first content and saving the encrypted first content to the object store.   
     
     
         17 . The method of  claim 15 , wherein the first computer programming includes a first client application, and wherein the first client application controls access to the first decrypted document. 
     
     
         18 . The method of  claim 15 , wherein accessing the first decrypted document includes at least one of: viewing of the first decrypted document, forwarding of the first decrypted document, modifying the first decrypted document, excerpting from the decrypted document. 
     
     
         19 . The method of  claim 15 , wherein the first data wrapper additionally includes document metadata, wherein at least some of the document metadata is accessible subsequent to applying a first permission key to the wrapper, and prior to applying the first content key to the wrapper contents. 
     
     
         20 . The method of  claim 15 , further comprising:
 receiving the first content key at the recipient computer, wherein the first content key is received by the recipient computer when the first data wrapper is received by the recipient computer.

Join the waitlist — get patent alerts

Track US2014237233A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.