File sharing and policy control based on file link mechanism

US10834060B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10834060-B2
Application numberUS-201816185885-A
CountryUS
Kind codeB2
Filing dateNov 9, 2018
Priority dateApr 11, 2017
Publication dateNov 10, 2020
Grant dateNov 10, 2020

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A method, a computing system and a computer program product are provided. A link for use by a user to access a file is created. Content of the file is encrypted using a common key. The common key is encrypted using a public key of the user and is registered in the link. Access rights regarding the file are set for the user and registered in the link. The link includes information for use by the user to access the file when the access rights indicate that the user is authorized to access the file.

First claim

Opening claim text (preview).

The invention claimed is: 1. A machine-implemented method for accessing a file, the method comprising: creating, by a computing device, a plurality of links to a file, each of the plurality of links being for use by a respective user of a plurality of users to access the file; encrypting, by the computing device, content of the file by using a common key; encrypting, by the computing device, the common key using a respective public key of each respective user to produce a respective encrypted common key for the each respective users; registering, by the computing device, the respective encrypted common key for the each respective user in a respective link of the plurality of links; setting, by the computing device, respective access rights regarding the file for the each respective user; registering, by the computing device, the respective access rights for the each respective user in the respective link of the plurality of links; and permitting access to the content of the file for a respective user only when a request to access the file is received including a private key of the respective user, and the access rights registered in one of the plurality of created links for use by the respective user indicating that the respective user is authorized to access the file. 2. The machine-implemented method of claim 1 , further comprising: performing key management of private keys of the plurality of users in collaboration with an external key management service. 3. The machine-implemented method of claim 1 , further comprising: obtaining encryption information included in the one of the plurality of created links to the file; determining whether the respective user is authorized to decrypt the content of the file based on the encryption information; and decrypting the content of the file, when the respective user is determined to be authorized to decrypt the content of the file, to produce a decrypted content of the file, wherein the permitting access to the content of the file includes allowing access to the decrypted content of the file when the respective user is determined to be authorized to decrypt the content of the file. 4. The machine-implemented method of claim 3 , wherein the decrypting of the content of the file further comprises: obtaining an encrypted common key via key information included in the one of the plurality of created links to the file, decrypting the encrypted common key with the private key of the respective user to produce the common key, and decrypting the content of the file using the common key. 5. A computing system comprising: at least one processor; and at least one memory connected to the at least one processor, wherein the at least one processor is configured to perform: creating a plurality of links to a file, each of the plurality of links being for use by a respective user of a plurality of users to access the file; encrypting content of the file by using a common key; encrypting the common key using a respective public key of each respective user to produce a respective encrypted common key for the each respective user; registering the respective encrypted common key for the each respective user in a respective link of the plurality of links; setting respective access rights regarding the file for the each respective user; registering the respective access rights for the each respective user in the respective link of the plurality of links; and permitting access to the content of the file for a respective user only when a request to access the file is received including a private key of the respective user, and the access rights registered in one of the plurality of created links for use by the respective user indicating that the respective user is authorized to access the file. 6. The computing system of claim 5 , wherein the at least one processor is further configured to perform: performing key management of private keys of the plurality of users in collaboration with an external key management service. 7. The computing system of claim 5 , wherein the at least one processor is further configured to perform: obtaining encryption information included in the one of the plurality of created links to the file; determining whether the respective user is authorized to decrypt the content of the file based on the encryption information; and decrypting the content of the file, when the respective user is determined to be authorized to decrypt the content of the file, to produce a decrypted content of the file, wherein the permitting access to the content of the file includes allowing access to the decrypted content of the file when the respective user is determined to be authorized to decrypt the content of the file. 8. The computing system of claim 7 , wherein the decrypting of the content of the file further comprises: obtaining an encrypted common key via key information included in the one of the plurality of created links to the file, decrypting the encrypted common key with the private key of the respective user to produce the common key, and decrypting the content of the file using the common key. 9. A computer program product comprising: at least one computer readable storage medium having computer readable program code embodied therewith for execution on at least one processor, the computer readable program code being configured to be executed by the at least one processor to perform: creating a plurality of links to a file, each of the plurality of links being for use by a respective user of a plurality of users to access the file; encrypting content of the file by using a common key; encrypting the common key using a respective public key of each respective user to produce a respective encrypted common key for the each respective user; registering the respective encrypted common key for the each respective user in a respective link of the plurality of links; setting respective access rights regarding the file for the each respective user; registering the respective access rights for the each respective user in the respective link of the plurality of links; and permitting access to the content of the file for a respective user only when a request to access the file is received including a private key of the respective user, and the access rights registered in one of the plurality of created links for use by the respective user indicating that the respective user is authorized to access the file. 10. The computer program product of claim 9 , wherein the computer readable program code is further configured to be executed by the at least one processor to perform: performing key management of private keys of the plurality of users in collaboration with an external key management service. 11. The computer program product of claim 9 , wherein the computer readable program code is further configured to be executed by the at least one processor to perform: obtaining encryption information included in the one of the plurality of created links to the file; determining whether the respective user is authorized to decrypt the content of the file based on the encryption information; and decrypting the content of the file, when the respective user is determined to be authorized to decrypt the content of the file, to produce a decrypted content of the file, wherein the permitting access to the content of the file includes allowing access to the decrypted content of the file when the respective user is determined to be authorized to decrypt the content of the file. 12. The computer program product of claim 11 , wherein the decrypting of the content of the file further comprises:

Assignees

Inventors

Classifications

  • H04L63/061Primary

    for key exchange, e.g. in peer-to-peer networks (cryptographic mechanisms or cryptographic arrangements for key agreement H04L9/0838) · CPC title

  • to a single file or object, e.g. in a secure envelope, encrypted and accessed using a key, or with access control rules appended to the object itself · CPC title

  • wherein the sending and receiving network entities apply asymmetric encryption, i.e. different keys for encryption and decryption (cryptographic mechanisms or cryptographic arrangements for public-key encryption H04L9/30) · CPC title

  • wherein the sending and receiving network entities apply hybrid encryption, i.e. combination of symmetric and asymmetric encryption (cryptographic mechanisms or cryptographic arrangements using a plurality of keys or algorithms H04L9/14) · CPC title

  • Support for shared access to files; File sharing support · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10834060B2 cover?
A method, a computing system and a computer program product are provided. A link for use by a user to access a file is created. Content of the file is encrypted using a common key. The common key is encrypted using a public key of the user and is registered in the link. Access rights regarding the file are set for the user and registered in the link. The link includes information for use by the…
Who is the assignee on this patent?
IBM
What technology area does this patent fall under?
Primary CPC classification H04L63/061. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Nov 10 2020 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 2 related publications on this page (citations in our corpus or others sharing the same primary CPC).