US9148283B1
патент
An encrypted resource is stored in association with an access controllist. A request to retrieve the resource is received. The wrapped key and the authentication credentials are sent, from the application server system, to a key server system. An unencrypted version of the resource encryption key is received from the key server system if the key server system determines that the authentication credentials correspond to a user in the group of users identified by the group identifier. The stored encrypted resource is decrypted using the received unencrypted version of the resource encryption key to gener ate an unencrypted version of the resource. The unencrypted version of the resource is sent, from the application server system, to the client application. 15 Claims, 9 Drawing Sheets
Притязаний: 11. Знаков текста: 99 096.