1. Field of the Invention
This invention relates to providing secure electronic archiving of customer data over a network. In addition, this invention relates to processing requests for the access of the electronic information to a customer or a third party specified by the customer.
2. Background of the Invention
Current electronic archive systems provide for the long-term storage of electronic files. Typically such systems require specialized software and/or are incorporated in document management software packages, such as DocuXplorer by Archive Power Systems, Inc. One known system for providing archival and retrieval of electronic messages, such as emails and their attachments, is ZANTAZ, by Zantaz, Inc. What is needed is a secure archive system for archival and retrieval of customer data files by incorporating secure customer identification through the use of digital certificates, and by utilizing electronic postmarks (“EPMs”) to store customer data and to facilitate tracking of customer data. What is also needed is a secure archive system that is independent of customer hardware and software platforms.
The present invention provides an archive system that customers may access through a browser over a network using secure communication transmissions, and using electronic postmarks (“EPMs”) to facilitate tracking of customer data. An EPM is a time-stamped and cryptographically sealed digital hash that accompanies an electronic message, to detect modification of the latter. The EPM for a message may include a time and date stamp indicating when the EPM was generated. The contents of an EPM are digitally “sealed” by the addition of a digital signature. An exemplary EPM is described in U.S. Ser. No. 09/675,677, filed Sep. 29, 2000, by Leo J. Campbell et al. and titled “Systems and Methods for Authenticating an Electronic Message,” the disclosure of which is expressly incorporated herein by reference to its entirety. In addition, an embodiment of the invention provides an archive system that is independent of customer hardware and software platforms.
More specifically, and in accordance with an embodiment of the invention, systems and methods are disclosed for providing customer accessible archiving of electronic files. Such systems and methods provide for establishing an account for a customer; receiving from the customer a storage request for archiving, wherein the storage request includes the electronic file and customer identification information; creating a storage EPM corresponding to the storage request; and storing the electronic file together with the storage EPM.
In accordance with another embodiment of the invention, systems and methods are disclosed for providing a customer access to the electronic files in an archive, wherein the electronic file is stored with a storage EPM. Such systems and methods receive an access request from the customer for the electronic file, wherein the access request includes the customer identification information and information identifying the electronic file in the archive; verify that the customer may access the electronic file based on the customer identification information and the information identifying the electronic file in the archive; retrieve the stored electronic file from the archive; and provide the retrieved electronic file to the customer.
In accordance with yet another embodiment of the invention, systems and methods are disclosed for providing access to an electronic file in an archive to a third party, wherein the electronic file is stored with a storage EPM. Such systems and methods provide for receiving from a customer a link request to permit access of the electronic file by the third party, wherein the link request includes information identifying the electronic file in the archive, customer identification information including the customer's digital certificate, and the third party's digital certificate; authenticating the customer based on the customer identification information; linking the customer's digital certificate to the third party's digital certificate, when the customer has been authenticated; receiving an access request from the third party, wherein the access request includes identification information about the third party and the information identifying the electronic file in the archive; verifying that the third party may access the electronic file based on identification information about the third party; retrieving the electronic file from the archive; and providing the retrieved electronic file to the third party.
It is to be understood that both the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the invention, as claimed.
The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments of the invention and together with the description, serve to explain the principles of the invention.
Reference will now be made in detail to the exemplary embodiments consistent with the invention, examples of which are illustrated in the accompanying drawings. Wherever possible, the same reference numbers will be used throughout the drawings to refer to the same or like parts.
Operation of archive system 101 is generally controlled and coordinated by operating system 280. Operating system 280 controls allocation of system resources and performs tasks, such as memory management, process scheduling, networking, and services, among other things.
Secondary storage 230 may include a computer-readable medium, such as a hard disk drive and a compact disc (“CD”) drive or a read/write CD drive. From the CD drive or the read/write CD drive, software and data may be loaded onto the disk drive, which may then be copied into memory 220. Similarly, software and data in memory 220 may be copied onto the hard disk drive, which may then be loaded onto a read/write CD drive.
Network interface component 240 may include hardware and software for sending and receiving data over network 110 (see FIG. 1). Archive system 101 may communicate with one or more customer systems 120 over network 110 through network interface component 240.
Input/Output interface component 250 may include one or more of, a keyboard, a pointing device, a voice recognition device, a keypad, display unit, or a printing device. Archive database 260 may include one or more databases and/or data files for the storage of data relating to customers 120. Authorization database 270 may include one or more databases and/or data files for storing information about customer archival transactions.
With reference to
A digital certificate may be used to uniquely identify a customer and to provide authorization to a customer for access of electronic information, such as an archived electronic file. An exemplary digital certificate of authority is described in U.S. Ser. No. 09/809,325, filed Mar. 16, 2001, by Leo J. Campbell et al. and titled “Methods and Systems for Proofing Identities Using a Certificate Authority,” the entire disclosure of which is expressly incorporated herein by reference. For example, the USPS provides a public key infrastructure, which includes, among other things, the generation of digital certificates.
Returning to
As shown in
Thereafter, as shown in
Archive administrator component 275 then verifies whether customer 120 is allowed to access the archived electronic file, using information in authorization database 270, customer identification information, and information identifying the archived electronic file (stage 430). If customer 120 is not allowed access to the archived electronic file (“No”), archive administrator component 275 may send an appropriate message to customer 120 and terminates the transaction (stage 490). Otherwise (“Yes”), archive administrator component 275 retrieves a copy of the archived electronic file from archive database 260 (stage 440). More specifically, archive administrator component 275 retrieves the storage EPM 370 from archive database 260 based on the customer identification information and the information identifying the archived electronic file. Next, archive administrator component 275 retrieves the archived electronic file from the hash of data 374 in the storage EPM 370.
In addition, archive administrator component 275 creates an access EPM and applies it to the archived electronic file by generating a record for the transaction in a transaction log 265 in the archive database 260 (stage 450). An access EPM includes the time and date on which the access request was processed by the archive system 101.
Thereafter, archive administrator component 275 provides customer 120 access to the electronic file by sending the copy of the electronic file to customer 120 over network 110 (stage 460). Alternatively, archive administrator component 275 may send the electronic file to a file server, and send the location of the electronic file at the file server to customer 120. In addition, archive administrator component 275 may bill customer 120 for access of the archived electronic file (stage 470). Customer 120 may make changes to the electronic file, and may request the revised electronic file be archived by archive system 101.
As shown in
Archive administrator component 275 verifies that customer 120 is allowed to access the archived electronic file, using information in authorization database 270 and the customer identification information (stage 517). If customer 120 is not allowed access to the archived electronic file (“No”), archive administrator component 275 sends an appropriate message to customer 120 and terminates the transaction (stage 590). Otherwise (“Yes”), archive administrator component 275 links the customer's digital certificate to the third party's digital certificate for access to the archived electronic file (stage 520). In addition, archive administrator component 275 creates a link EPM and applies it to the archived electronic file by generating a record for the transaction in transaction log 265 in archive database 260. A link EPM may include the time and date on which the customer's digital certificate was electronically linked to the third party's digital certificate, information about the third party's digital certificate, and an index link to the storage EPM that includes the electronic file.
Thereafter, the third party may submit to the archive system 101 over network 110 an access request for the archived electronic file, the access request including information identifying the archived electronic file, and identification information about the third party, such as the third party's digital certificate and optionally a name and password (stage 525). The information identifying the archived electronic file may include, for example, a filename for the electronic file. Archive administrator component 275 creates an access request EPM and applies it to the access request by generating a record for the transaction in transaction log 265 in archive database 260 (stage 530). The access request EPM may be used to track access requests for the archived electronic file. An access request EPM may include the time and date of the access request and identification information about the third party, allowing archive system 101 to keep track of access request transactions.
Archive administrator component 275 verifies that the third party is allowed to access the archived electronic file (stage 535). Archive administrator component 275 may determine whether the third party is allowed access to the archived electronic file based on information in the authorization database 270 and the identification information about the third party (stage 540). If the third party is not allowed access to the electronic file (“No”), archive administrator component 275 sends an appropriate message to the third party and terminates the transaction (stage 590). Otherwise (“Yes”), archive administrator component 275 retrieves a copy of the archived electronic file from archive database 260 (stage 550). More specifically, archive administrator component 275 retrieves the storage EPM 370 from archive database 260 based on the third party identification information and the information identifying the archived electronic file. Next, archive administrator component 275 retrieves the archived electronic file from the hash of data 374 in the storage EPM 370.
In addition, archive administrator component 275 creates an access EPM and applies it to the archived electronic file by generating a record for the transaction in transaction log 265 in archive database 260 (stage 560). An access EPM includes the time and date on which the access request was processed by the archive system 101, allowing archive system 101 to keep track of information about the access of the archived electronic file.
Thereafter, archive administrator component 275 allows the third party to access the electronic file by sending the copy of the electronic file to the third party over network 110 (stage 570). Alternatively, archive administrator component 275 may send the electronic file to a file server, and send the location of the electronic file at the file server to the third party. In addition, archive administrator component 275 may bill customer 120 for access of the electronic file (stage 580). The third party may make changes to the electronic file, and customer 120 may request the revised electronic file be archived by archive system 101.
Other embodiments of the invention will be apparent to those skilled in the art from consideration of the specification and practice of the invention disclosed herein. It is intended that the specification and examples be considered as exemplary only, with a true scope and spirit of the invention being indicated by the following claims.
This application claims priority from U.S. Provisional Application Ser. No. 60/231,337, filed Sep. 8, 2000, by Leo J. Campbell and titled SYSTEMS AND METHODS FOR PROVIDING ELECTRONIC ARCHIVING, the disclosure of which is expressly incorporated herein by reference.
| Filing Document | Filing Date | Country | Kind | 371c Date |
|---|---|---|---|---|
| PCT/US01/27690 | 9/7/2001 | WO | 00 | 2/24/2003 |
| Publishing Document | Publishing Date | Country | Kind |
|---|---|---|---|
| WO02/21315 | 3/14/2002 | WO | A |
| Number | Name | Date | Kind |
|---|---|---|---|
| 5857188 | Douglas | Jan 1999 | A |
| 5878233 | Schloss | Mar 1999 | A |
| 6064995 | Sansone et al. | May 2000 | A |
| 6219669 | Haff et al. | Apr 2001 | B1 |
| 6442571 | Haff et al. | Aug 2002 | B1 |
| Number | Date | Country | |
|---|---|---|---|
| 20040128316 A1 | Jul 2004 | US |
| Number | Date | Country | |
|---|---|---|---|
| 60231337 | Sep 2000 | US |