Computer-implemented method, computer program, and computer system
The method addresses the inflexibility of existing access control by using machine learning to detect document layout and apply dynamic access policies, enabling efficient and cost-effective access management to document components based on layout similarity.
Patent Information
- Application Number
- JP2021195948
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2020-12-02
- Filing Date
- 2021-12-02
- Publication Date
- 2025-10-09
- Estimated Expiration
- 2041-12-02
AI Technical Summary
Existing document access control mechanisms lack the ability to enforce different levels of access control for different sections of a document, preventing dynamic application of access policies based on document layout, and require manual encryption for all users, which is inefficient and inflexible.
A computer-implemented method that detects document layout using machine learning, defines access policies based on layout and user identification, authorizes access requests, and retrieves document components dynamically, allowing fine-grained access control based on document similarity.
Enables dynamic, granular access control to different document components for various users, improving productivity by allowing access policies to be applied flexibly across similar documents without modifying the original documents, and reducing costs through subsidized access to specific sections.
Smart Images

Figure 0007751940000001 
Figure 0007751940000002 
Figure 0007751940000003
Abstract
Description
[Technical Field]
[0001] The present disclosure relates generally to the field of document access control, and more particularly to providing document access control based on document component layout. [Background technology]
[0002] In the fields of physical and information security, access control is the selective restriction of access to a location or other resource, while access management describes the process. The act of accessing can mean consuming, entering, or using. Granting access to a resource is called authorization. Locks and login credentials can be considered two similar mechanisms of access control. Document access management allows document administrators to control which documents user groups can view or modify. This is useful when users want to manage access to a specific set of documents and do not want to create a complete disruption to coding, messaging, and administration by creating a new project.
[0003] Existing document access control mechanisms rely on full encryption or sub-section encryption by the document owner to enable different levels of access for different users. This requires the document owner to properly encrypt every document in the database for all other users, which cannot be dynamically updated to suit a large number of users. Currently, there is no option to enforce different levels of access control for different sections of a document, so that an access policy can be dynamically applied to other documents in the repository with a particular layout. For example, existing technology does not allow a user to specify that another user can access only the tables of a particular type of document, but not the body.
[0004] For example, Kanai (US Patent Application Publication No. 2006 / 0265599) discloses an access control device for controlling access to a predetermined resource, which includes: a first entity attempting to access the predetermined resource; entity relationship definition information defining a predetermined relationship between the first entity and a second entity; indirect access control information defining an access right to the predetermined resource based on the predetermined relationship; and an indirect access right determination unit detecting a second entity having a predetermined relationship with the first entity based on the entity relationship definition information, and determining the access right of the first entity based on the predetermined relationship with the detected second entity and the indirect access control information.
[0005] In another example, Neylan et al. (U.S. Patent Application Publication No. 2019 / 0129968) discloses a system for dynamically displaying specific sections of a file depending on user identification information. The system uses access control data to allow a creator to create a file, share it with several consumers, and allow each recipient to view a customized set of sections of the file depending on the permissions associated with each recipient. The file can be in any format, such as a word processing document, a presentation document, a media file, or any other file with several sections. A section of a file can be any distinct unit of data, such as a page, slide, tab, worksheet, video segment, audio segment, etc. Permissions can be based on the user's permission level, work history, skill level, organizational role, title, etc. The system can also prevent access to certain sections of a file depending on the permissions associated with the consumer.
[0006] In yet another example, Mohammad et al. (U.S. Patent Application Publication No. 2020 / 0044843) disclose a method for regulating document access that includes providing users with a set of access keys, each key in the set providing different user access privileges for components of a compound document, selecting multiple nodes in a distributed storage system, and distributing data representing N fragments of encrypted or unencrypted versions of the set of access keys or at least one of the individual keys, symmetric keys, or both, or a combination thereof. [Prior art documents] [Patent documents]
[0007] [Patent Document 1] US Patent Application Publication No. 2006 / 0265599 [Patent Document 2] US Patent Application Publication No. 2019 / 0129968 [Patent Document 3] US Patent Application Publication No. 2020 / 0044843 Summary of the Invention [Problem to be solved by the invention]
[0008] The present invention overcomes certain shortcomings of the prior art and provides further advantages by providing a technique for real-time opportunity discovery for improving productivity of a production process. Advantageously, a processor detects a layout of a document, the layout comprising one or more components of the document. The processor defines an access policy for accessing the one or more components based on the layout. The processor authorizes a request for access to the one or more components based on the access policy and the layout. The processor searches for and retrieves the one or more components based on the access policy and the authorized request. [Means for solving the problem]
[0009] In one or more embodiments, a computer-implemented method for detecting the layout of a document is provided. The layout may include one or more components of the document. In one example, the components may be figures, tables, sections, or other subsections of the document. The document may be searched and retrieved from a document repository. The document may be a digital document, such as a scanned document or other digitally formatted document. Advantageously, the document may be analyzed using machine learning techniques. The layout may be detected using machine learning techniques. The document may be indexed based on the detected layout and components. Advantageously, the document may be in a structured format. In another example, the document may be in an unstructured format.
[0010] In one or more embodiments, a computer-implemented method is provided for defining an access policy for accessing one or more components based on a layout. Advantageously, this computer-implemented method can provide access to components with different layouts based on the user and the task. This computer-implemented method can define access control based on the layout and one or more components. Advantageously, this computer-implemented method can create an access policy based on the layout, the components, and user identification. This computer-implemented method can also define access levels based on the layout and the components. Advantageously, this computer-implemented method can dynamically change the access level based on the layout. For example, this computer-implemented method can advantageously select one or more components (e.g., a table, a figure, a paragraph describing the table, and a specific document section) by annotating the document. This computer-implemented method can also select users and specify whether a particular user can access any of the components. Advantageously, this computer-implemented method can dynamically change a user's access level based on the document layout. Advantageously, this computer-implemented method can also apply dynamic, fine-grained access control to different layout components of a document to different users with different access levels based on document layout similarity.
[0011] In one or more embodiments, a computer-implemented method is provided for authorizing a request to access a component of a document based on an access policy and the layout of the document. The request can be validated based on the access policy. Advantageously, the computer-implemented method can provide access to the component based on the validated request from the user. Advantageously, the computer-implemented method can identify the specific component to which the user may request access.
[0012] In one or more embodiments, a computer-implemented method is provided for searching and retrieving a document based on an access policy in response to a document access request. Advantageously, the computer-implemented method can search for and retrieve authorized components of the document based on the access policy. Certain components of the document can be rendered unreadable based on access control details. In another example, the unreadable components can be stripped using "empty" content. The computer-implemented method can also encrypt the unreadable components for the request. The computer-implemented method can obscure certain components sufficiently to render them unreadable based on the request. The computer-implemented method may provide access to a document with certain components and sections rendered unreadable. The computer-implemented method can extract only the authorized sections. Advantageously, the computer-implemented method can display sections of the document (e.g., tables, figures) based on the user's access level by consulting an index. The computer-implemented method can also be provided to output one or more components based on a validated request. The computer-implemented method can also be provided to determine layout similarity between the document and other documents, such as documents in a document repository, based on a predefined similarity threshold. The computer-implemented method may also provide for dynamically applying the access policy to other documents.
[0013] In another aspect, a computer program product is provided that includes one or more computer-readable storage media and program instructions collectively stored on the one or more computer-readable storage media. Advantageously, the program instructions detect a layout of a document, the layout including one or more components of the document. The program instructions define an access policy for accessing the one or more components based on the layout. The program instructions authorize requests for access to the one or more components based on the access policy and the layout. The program instructions search for and retrieve the one or more components based on the access policy and the authorized requests.
[0014] In yet another aspect, a computer system is provided that includes one or more computer processors, one or more computer-readable storage media, and program instructions stored on the one or more computer-readable storage media for execution by at least one of the one or more computer processors. Advantageously, the program instructions detect a layout of a document, the layout including one or more components of the document. The program instructions define an access policy for accessing the one or more components based on the layout. The program instructions authorize requests for access to the one or more components based on the access policy and the layout. The program instructions search for and retrieve the one or more components based on the access policy and the authorized request.
[0015] Other features and advantages are realized through the teachings of the present invention. Additional embodiments and aspects of the invention are described in detail herein and are considered a part of the claimed invention. [Brief explanation of the drawings]
[0016] [Figure 1]FIG. 1 is a functional block diagram illustrating a document access control environment according to one embodiment of the present disclosure. [Figure 2] 2 is a flowchart illustrating operational steps of a document access control module 110 in the computing device of FIG. 1 according to one embodiment of the present disclosure. [Figure 3] FIG. 2 illustrates an example access policy expressed in JavaScript Object Notation (JSON) that may be applied in a document access control module within the computing device of FIG. 1 , in accordance with one embodiment of the present disclosure. [Figure 4] FIG. 2 is a block diagram illustrating components of the computing device of FIG. 1 in accordance with one embodiment of the present disclosure. DETAILED DESCRIPTION OF THE INVENTION
[0017] The present disclosure is directed to systems and methods for providing document access control based on document component layout.
[0018] Embodiments of the present disclosure recognize that different levels of access control are needed for different sections of a document so that access policies can be dynamically applied to other documents in a document repository that have a specific similar layout. Embodiments of the present disclosure disclose controlling access to specific sections of a document. Embodiments of the present disclosure disclose managing access to sections within a document. Embodiments of the present disclosure disclose providing access to different layout components based on the user and the task.
[0019] Embodiments of the present disclosure disclose applying dynamic, granular access control to different layout components of a document to different users with different access levels based on the document's layout similarity. For example, embodiments of the present disclosure disclose allowing User A to grant User B access to only tables across all similar documents (e.g., publications, memos, resumes) in a database, and such access policies can be dynamically updated as needed without modifying the documents. Embodiments of the present disclosure disclose dynamically assigning access across specific types of documents (based on layout) to different user groups without modifying the documents. Embodiments of the present disclosure disclose enabling document owners to dynamically assign access to multiple documents based on layout identification without modifying the original documents and without having to assign access to all documents in a very large document database with millions of documents. Embodiments of the present disclosure disclose allowing a user to access a specific category (e.g., a table listing amounts) but not the entities associated with the contract / warranty category within the document. Embodiments of the present disclosure disclose enabling subscription to document sections (e.g., specific sections such as tables, figures, or results) at a subsidized cost rather than the regular cost of article access. Embodiments of the present disclosure disclose enabling users to specify document access levels based on the document's layout and components. Embodiments of the present disclosure disclose enabling users to dynamically change a user's access level based on the document layout. Embodiments of the present disclosure disclose document access control based on document component layout. Embodiments of the present disclosure disclose applying dynamic, fine-grained access control to different layout components of a document to different users with different access levels based on the similarity of the document layout.Embodiments of the present disclosure disclose specifying document access levels based on document layout and components. Embodiments of the present disclosure disclose dynamically defining access control based on user type and task type. Embodiments of the present disclosure disclose extracting document layout components based on access control.
[0020] The present disclosure will now be described in detail with reference to the drawings, in which: Figure 1 is a functional block diagram illustrating a document access control environment, generally designated 100, according to one embodiment of the present disclosure.
[0021] In the illustrated embodiment, document access control environment 100 includes computing device 102, document 104, document repository 106, and network 108. In the illustrated embodiment, document 104 is external to computing device 102 and document repository 106 and is accessed via a communications network, such as network 108. However, in other embodiments, document 104 may be stored in document repository 106. In some embodiments, document 104 may be located on computing device 102. In some embodiments, document 104 may be accessed directly by computing device 102. In the illustrated embodiment, document repository 106 is external to computing device 102 and is accessed via a communications network, such as network 108. However, in other embodiments, document repository 106 may be located on computing device 102. In some embodiments, document repository 106 may be accessed directly by computing device 102.
[0022] In one or more embodiments, the document repository 106 may be a database that stores digital documents, such as scanned documents and other digital documents. The document repository 106 may store structured and unstructured documents. The document repository 106 may be accessed by a particular user. The document 104 may be stored in the document repository 106. The document 104 may be accessed and retrieved through a search in the document repository 106. The document 104 may include a layout 116. The layout 116 may include one or more components 118a-118n. For example, the components 118a-118n may be subsections of the document 104. In one embodiment, the components 118a-118n may be figures, tables, sections, or other subsections of the document. The document 104 may be indexed based on the layout 116 and the components 118a-118n. In one embodiment, the document 104 may be in a structured format. In another embodiment, the document 104 may be in an unstructured format.
[0023] In various embodiments of the present disclosure, the computing device 102 may be a laptop computer, a tablet computer, a netbook computer, a personal computer (PC), a desktop computer, a mobile phone, a smartphone, a smart watch, a wearable computing device, a personal digital assistant (PDA), or a server. In another embodiment, the computing device 102 represents a computing system that uses clustered computers and components to function as a single pool of seamless resources. In other embodiments, the computing device 102 may represent a server computing system that uses multiple computers as a server system, such as in a cloud computing environment. In general, the computing device 102 may be any computing device or combination of devices that can access the document access control module 110 and the network 108 and that is capable of processing program instructions and executing the document access control module 110 in accordance with one embodiment of the present disclosure. The computing device 102 may include internal and external hardware components, as shown and described in further detail with respect to FIG. 4.
[0024] Also, in the illustrated embodiment, computing device 102 includes document access control module 110. In the illustrated embodiment, document access control module 110 is located on computing device 102. However, in other embodiments, document access control module 110 may be external and accessed via a communications network, such as network 108. The communications network may be, for example, a local area network (LAN), a wide area network (WAN) such as the Internet, or a combination of the two, and may include wired, wireless, fiber optic, or any other connection known in the art. In general, the communications network may be any combination of connections and protocols that will support communication between computing device 102 and document access control module 110 in accordance with any desired embodiment of the present disclosure.
[0025] In one or more embodiments, the document access control module 110 is configured to detect the layout 116 of the document 104. The layout 116 may include one or more components 118a-118n of the document 104. For example, the components 118a-118n may be subsections of the document 104. In one embodiment, the components 118a-118n may be figures, tables, sections, or other subsections of the document. The document access control module 110 may receive the document 104 from the document repository 106. The document repository 106 may store digital documents, such as scanned documents or other digital documents. The document 104 may be a digital document from the document repository 106. The document access control module 110 may analyze the document 104 using machine learning techniques. The document access control module 110 may detect the layout 116 of the document 104 using machine learning techniques. In one embodiment, the document access control module 110 may detect the layout 116 and components 118a-118n (e.g., tables) using an evaluation metric called tree edit distance similarity (TEDS), which captures the performance of table structure recognition and cell content recognition. The document access control module 110 may use TEDS to better capture multi-hop cell mismatches and optical character recognition errors. The document access control module 110 may use TEDS to inspect the recognition results at a global tree structure level. The document access control module 110 may index the document 104 based on the detected layout 116 and components 118a-118n. In one embodiment, the document 104 may be in a structured format. In another embodiment, the document 104 may be in an unstructured format.For example, the document access control module 110 can automatically create a large set of annotated documents (e.g., Portable Document Format (PDF) documents) based on a set of unlabeled documents (e.g., PDF documents) and a corresponding set of structured documents, such as Extensible Markup Language (XML) files. Each pair of PDF and XML documents can represent the same general information in a different format, with PDF being a format designed for ease of use by human readers and XML being a structured format that includes labels identifying various components 118a-118n (e.g., paragraphs, images, tables, etc.) of the document 104. The document access control module 110 can automatically label each annotated document so that the various components 118a-118n (e.g., sentences, paragraphs, titles, images, tables, headers, footers, etc.) of the layout 116 can be accurately identified and labeled. The resulting large set of annotated PDF documents can then be used as training data to effectively train a machine learning model to analyze new documents and identify and extract layout elements from the new documents, e.g., the document 104. The document access control module 110 may use this training data to identify and extract the layout 116 and components 118a-118n. The document access control module 110 may use a deep neural network to analyze the layout 116 of the document 104. In one embodiment, the document access control module 110 can label a large number of documents (e.g., PDF documents) that initially do not have any specified descriptions or labels by parsing the PDF and then matching unlabeled portions of the parsed PDF with labeled portions of an XML document.While this disclosure generally uses PDF documents and XML documents as examples of unstructured and structured documents that the disclosed systems use to automatically generate training data, it is contemplated that various embodiments of the invention may substituted other suitable types of unstructured and / or structured documents. For example, other types of unstructured documents may include scanned documents and plain text (where characters and symbols can be spatially arranged in a human-perceivable manner to create tables, lists, and simple images), and other types of structured documents may include Markdown, JSON, word processing documents, and HyperText Markup Language (HTML).
[0026] In one or more embodiments, the document access control module 110 is configured to define access policies for accessing one or more components 118a-118n based on the layout 116. The document access control module 110 may provide access to different layout components 118a-118n based on the user and the task. The document access control module 110 may define access controls based on the layout 116 and one or more components 118a-118n. The document access control module 110 may create an access policy based on the layout 116, one or more components 118a-118n, and user identification information. The document access control module 110 may define access levels based on the layout 116 and one or more components 118a-118n. The document access control module 110 may dynamically change the access levels based on the layout 116. For example, the document access control module 110 may select one or more components 118a-118n (e.g., a table, a figure, a paragraph describing the table, and a particular document section) by annotating a sample document (e.g., document 104) representing a document with a particular layout (e.g., layout 116). The document access control module 110 may select a user and specify whether the particular user can access any of the components 118a-118n of documents in a document database (e.g., document repository 106) that have a layout similar to layout 116. The document access control module 110 may have the option to set an expiration date for accessing any of the components 118a-118n. The document access control module 110 may select access control based on the user's current task.The document access control module 110 may identify that a user needs access to a particular section of the document 104 (eg, any of one or more components 118a-118n).
[0027] The document access control module 110 may define control access only to a particular component 118a-118n (e.g., component 118a) but not to other components 118a-118n (e.g., component 118n). In one embodiment, the document access control module 110 may define a particular section (e.g., a table listing amounts) but not the contract / guarantee-related entities in the example financial document. The document access control module 110 may enable subscription to document sections (e.g., specific sections such as tables, figures, or results) at a subsidized fee rather than the regular cost of article access. The document access control module 110 may allow users to specify document access levels based on the layout 116 and components 118a-118n of the document 104. The document access control module 110 may allow users to dynamically change their access levels based on the document layout 116. The document access control module 110 may apply dynamic and fine-grained access control to different layout components 118a-118n of the document 104 to different users at different access levels based on document layout similarity. In one embodiment, the document access control module 110 may determine document layout similarity using a pre-trained language model, such as bidirectional encoder representations from transformers (BERT), a neural network-based technique for natural language processing pre-training. The document access control module 110 may also use an automated evaluation metric for text generation, such as a BERT score. The document access control module 110 may calculate a similarity score for each token in the candidate sentence with each token in the reference sentence.The document access control module 110 may calculate token similarity using context embeddings. The document access control module 110 may achieve better correlation with human judges and stronger model selection performance. The document access control module 110 may calculate the similarity between two sentences as the sum of cosine similarities between token embeddings. The document access control module 110 may dynamically define access controls based on user type and task type. The document access control module 110 may extract document layout components 118a-118n based on the access controls. The document access control module 110 may specify user access levels by specifying the layout 116 and components 118a-118n of the document 104 and the respective users.
[0028] The document access control module 110 may provide different levels of access control for different components 118a-118n (e.g., different sections) of the document 104, such that access policies can be dynamically applied to other documents in the document repository 106 that have a specific similar layout to the document 104. The document access control module 110 may apply dynamic, fine-grained access control to different layout components of a document to different users with different access levels based on document layout similarity. For example, the document access control module 110 may allow user A to grant user B access to only tables of all similar documents (e.g., publications, memos, resumes) in the document repository 106, where such access policies can be dynamically updated as needed. The document access control module 110 may provide access control for components 118a-118n (e.g., specific sections) of the document 104. The document access control module 110 may also provide access management for individual sections of the document 104. The document access control module 110 may manage access control for individual sections within the document 104. The document access control module 110 may manage access control using the document 104, which may be in a structured or unstructured format.
[0029] In one or more embodiments, the document access control module 110 is configured to authorize access requests to components 118a-118n based on the access policy of the document 104 and the layout 116. The document access control module 110 may validate the request based on the access policy. The document access control module 110 may grant access to one or more components 118a-118n based on the validated request from the user. The document access control module 110 may identify a particular component (e.g., any of components 118a-118n) to which the user may request access.
[0030] In one or more embodiments, the document access control module 110 may be configured to search for and retrieve the document 104 based on an access policy for a request to access the document 104. The document access control module 110 may search for and retrieve authorized components 118a-118n of the document 104 based on the access policy. The document access control module 110 may render sections of the document 104 (e.g., certain components 118a-118n) unreadable based on the access control details. In another example, the document access control module 110 may remove empty content for unreadable components. The document access control module 110 may encrypt unreadable components for a request. The document access control module 110 may obscure components sufficiently to render certain components unreadable based on the request. The document access control module 110 may grant access to the document 104 with certain components and sections unreadable. The document access control module 110 may extract only the authorized sections. The document access control module 110 may display document sections (e.g., tables, figures) based on the user's access level by consulting an index. The document access control module 110 may output one or more components 118a-118n based on the validated request. The document access control module 110 may display the components 118a-118n based on the access level. The document access control module 110 may determine layout similarity between the document 104 and other documents, such as documents in the document repository 106, based on a predefined similarity threshold.In one embodiment, the document access control module 110 may determine document layout similarity using a pre-trained language model, such as BERT, a neural network-based technique for natural language processing pre-training. The document access control module 110 may use an automated evaluation metric for text generation, such as a BERT score. The document access control module 110 may calculate a similarity score for each token in a candidate sentence with each token in a reference sentence. The document access control module 110 may calculate token similarity using contextual embeddings. The document access control module 110 may achieve better correlation with human judgement and stronger model selection performance. The document access control module 110 may calculate the similarity between two sentences as the sum of cosine similarities between token embeddings. The document access control module 110 may dynamically apply access policies to other documents. The document access control module 110 may search for and retrieve components of other documents based on the access policies of documents 104 with similar layouts.
[0031] In the illustrated embodiment, the document access control module 110 includes an access policy module 112 and a document search module 114. In one or more embodiments, the access policy module 112 is configured to define an access policy for accessing one or more components 118a-118n based on the layout 116. The access policy module 112 may grant access to different layout components 118a-118n based on the user and the activity. The access policy module 112 may define access control based on the layout 116 and the one or more components 118a-118n. The access policy module 112 may create an access policy based on the layout 116, the one or more components 118a-118n, and user identification information. The access policy module 112 may define an access level based on the layout 116 and the one or more components 118a-118n. The access policy module 112 may dynamically change the access level based on the layout 116. For example, the access policy module 112 may select one or more components 118a-118n (e.g., a table, a figure, a paragraph describing the table, and a specific document section) by annotating the document 104. The access policy module 112 may select a user and specify whether a particular user can access any of the components 118a-118n. The access policy module 112 may have the option to set an expiration date for accessing any of the components 118a-118n. The access policy module 112 may select access controls based on the user's immediate task. The access policy module 112 may identify that a user needs access to a specific section of the document 104 (e.g., any of one or more components 118a-118n).
[0032] The access policy module 112 may define control access only to certain components 118a-118n (e.g., component 118a) and not to other components 118a-118n (e.g., component 118n). In one embodiment, the access policy module 112 may define a particular section (e.g., a table containing amounts) but not the contract / guarantee-related entities in an example financial document. The access policy module 112 may enable subscription to document sections (e.g., specific sections such as tables, figures, or results) at a subsidized fee rather than the regular cost of access to the article. The access policy module 112 may allow users to specify document access levels based on the layout 116 and components 118a-118n of the document 104. The access policy module 112 may allow users to dynamically change their access levels based on the document layout 116. The access policy module 112 may apply dynamic, fine-grained access control to different layout components 118a-118n of the document 104 to different users at different access levels based on document layout similarity. The access policy module 112 may dynamically define access control based on user type and task type. The access policy module 112 may extract the document layout components 118a-118n based on the access control. The access policy module 112 may specify a user's access level by specifying the layout 116 and components 118a-118n of the document 104 and the respective users.The access policy module 112 may provide different levels of access control for different components 118a-118n (e.g., different sections) of the document 104, such that the access policy can be dynamically applied to other documents in the document repository 106 that have a specific similar layout to the document 104. The access policy module 112 may apply dynamic, fine-grained access control to different layout components of the document to different users at different access levels based on document layout similarity. For example, the access policy module 112 may allow user A to grant user B access to only tables of all similar documents (e.g., publications, memos, resumes) in the document repository 106, where such access policies can be dynamically updated as needed. The access policy module 112 may provide access control for components 118a-118n (e.g., specific sections) of the document 104. The access policy module 112 may provide access management for individual sections of the document 104. The access policy module 112 may manage access control for individual sections within the document 104. The access policy module 112 may manage access control using the document 104, which may be in a structured or unstructured format.
[0033] In one or more embodiments, the document search module 114 is configured to search for and retrieve the document 104 based on an access policy for a request to access the document 104. The document search module 114 may search for and retrieve authorized components 118a-118n of the document 104 based on the access policy. The document search module 114 may render sections of the document 104 (e.g., certain components 118a-118n) unreadable based on the access control details. In another example, the document search module 114 may remove empty content for unreadable components. The document search module 114 may encrypt unreadable components for the request. The document search module 114 may obscure components sufficiently to render certain components unreadable based on the request. The document search module 114 may grant access to the document 104 with certain components and sections unreadable. The document search module 114 may extract only the authorized sections. The document retrieval module 114 may display document sections (e.g., tables, figures) based on the user's access level by consulting an index. The document retrieval module 114 may output one or more components 118a-118n based on a validated request. The document retrieval module 114 may display the components 118a-118n based on the access level. The document retrieval module 114 may determine layout similarity between the document 104 and other documents, such as documents in the document repository 106, based on a predefined similarity threshold. The document retrieval module 114 may dynamically apply access policies to other documents. The document retrieval module 114 may search for and retrieve components of other documents based on the access policy of the document 104 that have a similar layout.
[0034] FIG. 2 is a flowchart 200 illustrating the operational steps of the document access control module 110 according to one embodiment of the present disclosure.
[0035] The document access control module 110 operates to detect the layout 116 of the document 104. The layout 116 may include one or more components 118a-118n of the document 104. The document access control module 110 also operates to define access policies for accessing the one or more components 118a-118n based on the layout 116. The document access control module 110 operates to authorize requests to access the components 118a-118 based on the access policies and the layout 116 of the document 104. The document access control module 110 operates to search for and retrieve the document 104 based on the access policies of the document 104 for requests from a user.
[0036] In step 202, the document access control module 110 detects the layout 116 of the document 104. The layout 116 may include one or more components 118a-118n of the document 104. For example, the components 118a-118n may be subsections of the document 104. In one embodiment, the components 118a-118n may be figures, tables, sections, or other subsections of the document. The document access control module 110 may receive the document 104 from the document repository 106. The document repository 106 may store digital documents, such as scanned documents or documents in other digital formats. The document 104 may be a digital document from the document repository 106. The document access control module 110 may analyze the document 104 using machine learning techniques. The document access control module 110 may detect the layout 116 of the document 104 using machine learning techniques. In one embodiment, the document access control module 110 may detect the layout 116 and components 118a-118n (e.g., tables) using a rating indicator (TEDS) that captures the performance of table structure recognition and cell content recognition. The document access control module 110 may use TEDS to better capture multi-hop cell misalignment and optical character recognition errors. The document access control module 110 may use TEDS to inspect the recognition results at a global tree structure level. The document access control module 110 may index the document 104 based on the detected layout 116 and components 118a-118n. In one embodiment, the document 104 may be in a structured format. In another embodiment, the document 104 may be in an unstructured format.For example, the document access control module 110 can automatically create a large set of annotated documents (e.g., PDF documents) based on a set of unlabeled documents (e.g., PDF documents) and a corresponding set of structured documents, such as XML files. Each pair of PDF and XML documents can represent the same general information in a different format, with PDF being a format designed for ease of use by human readers and XML being a structured format that includes labels identifying various components 118a-118n (e.g., paragraphs, images, tables, etc.) of the document 104. The document access control module 110 can automatically label each annotated document so that the various components 118a-118n (e.g., sentences, paragraphs, titles, images, tables, headers, footers, etc.) of the layout 116 can be accurately identified and labeled. The resulting large set of annotated PDF documents can then be used as training data to effectively train a machine learning model to analyze new documents and identify and extract layout elements from the new documents, e.g., the document 104. The document access control module 110 may use this training data to identify and extract the layout 116 and components 118a-118n. The document access control module 110 may use a deep neural network to analyze the layout 116 of the document 104. In one embodiment, the document access control module 110 can label a large number of documents (e.g., PDF documents) that initially do not have any specified descriptions or labels by parsing the PDF and then matching unlabeled portions of the parsed PDF with labeled portions of an XML document.While this disclosure generally uses PDF documents and XML documents as examples of unstructured and structured documents that the disclosed system uses to automatically generate training data, it is contemplated that any other suitable types of unstructured and / or structured documents may be substituted in various embodiments of the invention. For example, other types of unstructured documents may include scanned documents and plain text (where characters and symbols can be spatially arranged in a human-perceivable manner to create tables, lists, and simple images), and other types of structured documents may include Markdown, JSON, word processing documents, and HTML.
[0037] In step 204, the document access control module 110 defines an access policy for accessing one or more components 118a-118n based on the layout 116. The document access control module 110 may grant access to different layout components 118a-118n based on the user and the task. The document access control module 110 may define access control based on the layout 116 and one or more components 118a-118n. The document access control module 110 may create an access policy based on the layout 116, one or more components 118a-118n, and user identification information. The document access control module 110 may define an access level based on the layout 116 and one or more components 118a-118n. The document access control module 110 may dynamically change the access level based on the layout 116. For example, the document access control module 110 may select one or more components 118a-118n (e.g., a table, a figure, a paragraph describing the table, and a particular document section) by annotating a sample document (e.g., document 104) representing a document with a particular layout (e.g., layout 116). The document access control module 110 may select a user and specify whether the particular user can access any of the components 118a-118n of documents in a document database (e.g., document repository 106) that have a layout similar to layout 116. The document access control module 110 may have the option to set an expiration date for accessing any of the components 118a-118n. The document access control module 110 may select access control based on the user's current task.The document access control module 110 may identify that a user needs access to a particular section of the document 104 (eg, any of one or more components 118a-118n).
[0038] The document access control module 110 may define control access only to a particular component 118a-118n (e.g., component 118a) but not to other components 118a-118n (e.g., component 118n). In one embodiment, the document access control module 110 may define a particular section (e.g., a table listing amounts) but not the contract / guarantee-related entities in the example financial document. The document access control module 110 may enable subscription to document sections (e.g., specific sections such as tables, figures, or results) at a subsidized fee rather than the regular cost of article access. The document access control module 110 may allow users to specify document access levels based on the layout 116 and components 118a-118n of the document 104. The document access control module 110 may allow users to dynamically change their access levels based on the document layout 116. The document access control module 110 may apply dynamic and fine-grained access control to different layout components 118a-118n of the document 104 for different users at different access levels based on document layout similarity. In one embodiment, the document access control module 110 may determine document layout similarity using a pre-trained language model, such as BERT, a neural network-based technique for natural language processing pre-training. The document access control module 110 may use an automated evaluation metric for text generation, such as the BERT score. The document access control module 110 may calculate a similarity score for each token in the candidate sentence with each token in the reference sentence. The document access control module 110 may calculate token similarity using context embedding. The document access control module 110 may achieve better correlation with human judges and stronger model selection performance.The document access control module 110 may calculate the similarity between two sentences as the sum of cosine similarities between their token embeddings. The document access control module 110 may dynamically define access controls based on user type and task type. The document access control module 110 may extract document layout components 118a-118n based on the access controls. The document access control module 110 may specify a user's access level by specifying the layout 116 and components 118a-118n of the document 104 and the respective users.
[0039] The document access control module 110 may provide different levels of access control for different components 118a-118n (e.g., different sections) of the document 104, such that access policies can be dynamically applied to other documents in the document repository 106 that have a specific similar layout to the document 104. The document access control module 110 may apply dynamic, fine-grained access control to different layout components of a document to different users with different access levels based on document layout similarity. For example, the document access control module 110 may allow user A to grant user B access to only tables of all similar documents (e.g., publications, memos, resumes) in the document repository 106, where such access policies can be dynamically updated as needed. The document access control module 110 may provide access control for components 118a-118n (e.g., specific sections) of the document 104. The document access control module 110 may also provide access management for individual sections of the document 104. The document access control module 110 may manage access control for individual sections within the document 104. The document access control module 110 may manage access control using the document 104, which may be in a structured or unstructured format.
[0040] In step 206, the document access control module 110 authorizes the request for access to the components 118a-118n based on the access policy of the document 104 and the layout 116. The document access control module 110 may validate the request based on the access policy. The document access control module 110 may grant access to one or more components 118a-118n based on the validated request from the user. The document access control module 110 may identify the particular component (e.g., any of the components 118a-118n) to which the user may request access.
[0041] In step 208, the document access control module 110 searches for and retrieves the document 104 based on the access policy of the document 104 for the user request. The document access control module 110 may search for and retrieve the authorized components 118a-118n of the document 104 based on the access policy for the request. The document access control module 110 may render sections of the document 104 (e.g., certain components 118a-118n) unreadable based on the access control details. In another embodiment, the document access control module 110 may remove the content of the unreadable components using "empty." The document access control module 110 may encrypt the unreadable components for the request. The document access control module 110 may obscure the components sufficiently to render certain components unreadable based on the request. The document access control module 110 may grant access to the document 104 with the specified components and sections unreadable. The document access control module 110 may extract only the authorized sections. The document access control module 110 may display document sections (e.g., tables, figures) based on the user's access level by consulting an index. The document access control module 110 may output one or more components 118a-118n based on the validated request. The document access control module 110 may display the components 118a-118n based on the access level. The document access control module 110 may determine layout similarity between the document 104 and other documents, such as documents in the document repository 106, based on a predefined similarity threshold. In one embodiment, the document access control module 110 may determine document layout similarity using a pre-trained language model, such as BERT, a neural network-based technique for natural language processing pre-training.The document access control module 110 may use an automatic evaluation metric for text generation, such as a BERT score. The document access control module 110 may calculate a similarity score for each token in a candidate sentence with each token in a reference sentence. The document access control module 110 may use contextual embeddings to calculate token similarity. The document access control module 110 may achieve better correlation with human judgment and stronger model selection performance. The document access control module 110 may calculate the similarity between two sentences as the sum of cosine similarities between token embeddings. The document access control module 110 may dynamically apply access policies to other documents. The document access control module 110 may search for and retrieve components of other documents based on the access policies of documents 104 with similar layouts.
[0042] FIG. 3 illustrates an example access policy expressed in JSON that is applied in the document access control module 110 according to one embodiment of the present disclosure.
[0043] In the example of FIG. 3, the document access control module 110 defines the access policy in JSON based on the layout 116, the components 118, and the user identification information 302. In other embodiments, the document access control module 110 may define the access policy in other suitable files or programming formats. In this example, the components 118 are defined to include, for example, a table 118a and a section 118b. The document access control module 110 defines the access policy to include controlled access 304. In this example, controlled access 304 is set to "X," representing no access. The document access control module 110 may also define an expiration date 306 option.
[0044] 4 illustrates a block diagram 400 of components of a computing device 102 in accordance with one exemplary embodiment of the present disclosure. It is understood that FIG. 4 is merely provided as an example of one implementation and does not imply any limitation with respect to the environment in which different embodiments may be implemented. Many modifications to the depicted environment may be made.
[0045] The computing device 102 may include a communications fabric 402 that provides communication between the cache 416, the memory 406, the persistent storage 408, the communications unit 410, and the input / output (I / O) interface 412. The communications fabric 402 may be implemented using any architecture designed to pass data and / or control information between a processor (such as a microprocessor, communications and network processor), system memory, peripheral devices, and any other hardware components in a system. For example, the communications fabric 402 may be implemented using one or more buses or crossbar switches.
[0046] Memory 406 and persistent storage 408 are computer-readable storage media. In this embodiment, memory 406 includes random access memory (RAM). In general, memory 406 may include any suitable volatile or non-volatile computer-readable storage medium. Cache 416 is a high-speed memory that improves performance of computer processor 404 by retaining recently accessed data and data near the recently accessed data from memory 406.
[0047] The document access control module 110 may be stored in persistent storage 408 and memory 406 for execution by one or more of the respective computer processors 404 via cache 416. In one embodiment, persistent storage 408 includes a magnetic hard disk drive. Alternatively, or in addition to a magnetic hard disk drive, persistent storage 408 may include a solid-state hard drive, a semiconductor storage device, a read-only memory (ROM), an erasable programmable read-only memory (EPROM), a flash memory, or any other computer-readable storage medium capable of storing program instructions or digital information.
[0048] The media used by persistent storage 408 may be removable. For example, a removable hard drive may be used for persistent storage 408. Other examples include optical disks, magnetic disks, thumb drives, and smart cards that are inserted into a drive for transfer to another computer-readable storage medium that is also part of persistent storage 408.
[0049] The communications unit 410, in these examples, provides for communication with other data processing systems or devices. In these examples, the communications unit 410 includes one or more network interface cards. The communications unit 410 may provide communication using either or both physical and wireless communications links. The document access control module 110 may be downloaded to the persistent storage 408 via the communications unit 410.
[0050] The I / O interface 412 allows for the input and output of data to and from other devices connectable to the computing device 102. For example, the I / O interface 412 may provide a connection to an external device 418, such as a keyboard, keypad, touch screen, or any other suitable input device or combination thereof. The external device 418 may also include portable computer-readable storage media, such as thumb drives, portable optical or magnetic disks, and memory cards. Software and data used to implement embodiments of the present invention, such as the document access control module 110, may be stored on such portable computer-readable storage media and loaded into the persistent storage 408 via the I / O interface 412. The I / O interface 412 also connects to a display 420.
[0051] Display 420 provides a mechanism for displaying data to a user and may be, for example, a computer monitor.
[0052] The programs described herein are identified based on the applications for which they are implemented in particular embodiments of the invention, but it should be understood that any particular program nomenclature herein is used merely as a matter of convenience, and therefore the present invention should not be limited to use with only any particular application identified and / or suggested by such nomenclature.
[0053] The present invention may be a system, method, or computer program product, or combination thereof, at any possible level of technical detail of integration. The computer program product may include a computer-readable storage medium (or media) having computer-readable program instructions stored thereon for causing a processor to implement aspects of the present invention.
[0054] A computer-readable storage medium may be a tangible device capable of retaining and storing instructions for use by an instruction execution device. A computer-readable storage medium may be, for example, but not limited to, an electronic storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination thereof. A non-exhaustive list of more specific examples of computer-readable storage media may include: a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), a static random access memory (SRAM), a portable compact disk read-only memory (CD-ROM), a digital versatile disk (DVD), a memory stick, a floppy disk, a mechanically encoded device such as a punch card or a ridge structure in a groove in which instructions are recorded, and any suitable combination thereof. As used herein, computer-readable storage media should not be construed as transitory signals per se, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through a waveguide or other transmission medium (e.g., light pulses through fiber optic cable), or electrical signals transmitted over electrical wires.
[0055] The computer-readable program instructions described herein can be downloaded from a computer-readable storage medium to each computing / processing device or to an external computer or storage device over a network, such as the Internet, a local area network, a wide area network, or a wireless network, or a combination thereof. The network may include copper transmission cables, optical fiber transmissions, wireless transmissions, routers, firewalls, switches, gateway computers, or edge servers, or a combination thereof. A network adapter card or network interface in each computing / processing device receives the computer-readable program instructions from the network and forwards the computer-readable program instructions to a computer-readable storage medium within the respective computing / processing device for storage.
[0056] Computer-readable program instructions for carrying out the operations of the present invention may be source or object code written in any combination of one or more programming languages, including assembler instructions, instruction set architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, state setting data, configuration data for integrated circuits, or procedural programming languages such as object-oriented programming languages such as Python, C++, and the "C" programming language, or similar programming languages. The computer-readable program instructions may execute entirely on the user's computer, partially on the user's computer as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the latter case, the remote computer may be connected to the user's computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection may be to an external computer (e.g., via the Internet using an Internet Service Provider). In some embodiments, electronic circuitry including, for example, a programmable logic circuit, a field programmable gate array (FPGA), or a programmable logic array (PLA), may execute computer-readable program instructions to perform aspects of the invention by personalizing the electronic circuitry using state information of the computer-readable program instructions.
[0057] Aspects of the present invention are described with reference to flowchart illustrations and / or block diagrams that illustrate methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer-readable program instructions.
[0058] These computer-readable program instructions can be supplied to a processor of a computer or other programmable data processing apparatus, thereby implementing a machine in which the instructions, executed by the processor of the computer or other programmable data processing apparatus, form means for implementing the functions / acts specified in a block or blocks of the flowcharts and / or block diagrams. These computer-readable program instructions can also be stored on a computer-readable storage medium that can instruct a computer, programmable data processing apparatus, or other device, or combination thereof, to function in a particular manner. Thus, a computer-readable storage medium having instructions stored thereon includes an article of manufacture containing instructions that implement aspects of the functions / acts specified in a block or blocks of the flowcharts and / or block diagrams.
[0059] The computer-readable program instructions may also be loaded into a computer, other programmable data processing apparatus, or other device to cause a sequence of operational steps to be performed on the computer, other programmable apparatus, or other device to realize a computer-implemented process, whereby the instructions executed on the computer, other programmable apparatus, or other device implement the function(s) / act(s) specified in a block or blocks of the flowchart and / or block diagram.
[0060] The flowcharts and block diagrams in the figures illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of instructions, including one or more executable instructions for implementing the specified logical function(s). In some alternative implementations, the functions noted in the blocks may occur out of the order noted in the figures. For example, two blocks shown in succession may actually be performed as a single step, in parallel, substantially in parallel, partially, or fully overlapping in time, or the blocks may even be performed in reverse order, depending on the functionality involved. It will also be understood that each block of the block diagrams and / or flowchart diagrams, and combinations of blocks in the block diagrams and / or flowchart diagrams, may be implemented by a dedicated hardware-based system that performs the specified functions or operations, or may embody a combination of dedicated hardware and computer instructions.
[0061] The description of various embodiments of the present invention has been provided for illustrative purposes and is not intended to be exhaustive or limited to the disclosed embodiments. Many modifications and variations will be apparent to those skilled in the art without departing from the scope and spirit of the present invention. The terms used herein have been selected to best explain the principles of the embodiments, practical applications, or technical improvements over commercially available technologies, or to enable those skilled in the art to understand the embodiments disclosed herein.
[0062] Although specific embodiments of the present invention have been described, those skilled in the art will recognize that there are other embodiments that are equivalent to the described embodiments. Accordingly, the present invention should not be limited by the specific exemplary embodiments, but rather should be limited only by the scope of the appended claims. [Explanation of symbols]
[0063] 100 Document Access Control Environment 102 Computing Devices 106 Document Repository 108 Network 110 Document Access Control Module 112 Access Policy Module 114 Document Search Module 116 Layout 118a Components 118b Components 118n Components 400 Block Diagram 402 Communication Fabric 404 processor 406 memory 408 Persistent Storage 410 Communication Unit 412 I / O interface 416 Cache 418 External Devices 420 Display
Claims
1. determining, by one or more processors, a first layout of a first document, the first layout including one or more components of the first document; defining, by one or more processors, access policies that grant user access to component types for the one or more components, the access policies being dynamically applied to documents whose layouts match within a predefined layout similarity threshold; determining, by one or more processors, that a second document has a second layout that matches the first layout within the predefined layout similarity threshold; receiving a request from the user to access the second document; and in response to receiving the request, by one or more processors, granting the user access to components in the second document based on the access policy and the second layout, the components being of the component type; A computer-implemented method comprising:
2. The computer-implemented method of claim 1 , wherein the access policy is stored external to the first document and the second document.
3. The computer-implemented method of claim 1 or 2, wherein defining the access policy includes defining an access level.
4. 4. The computer-implemented method of claim 3, further comprising dynamically changing, by one or more processors, the access levels to the first document and the second document.
5. The computer-implemented method of claim 3 or 4, further comprising presenting the component in the second document to the user.
6. searching, by one or more processors, for retrieving the components of the second document based on the access policy; The computer-implemented method of claim 1 , further comprising:
7. The computer-implemented method of claim 1 , wherein the one or more components are selected from the group consisting of a table, a figure, and a section.
8. The processor determining a first layout of a first document, the first layout including one or more components of the first document; defining an access policy that grants user access to a component type for the one or more components, the access policy being dynamically applied to documents whose layouts match within a predefined layout similarity threshold; determining that a second document has a second layout that matches the first layout within the predefined layout similarity threshold; receiving a request from the user to access the second document; in response to receiving the request, granting the user access to components in the second document based on the access policy and the second layout, the components being of the component type; and A computer program that causes a number of steps to be performed, including:
9. 9. The computer program product of claim 8, wherein the access policy is stored externally to the first document and the second document.
10. 10. The computer program product according to claim 8, wherein the step of defining an access policy includes the step of defining an access level.
11. the processor, 11. The computer program product of claim 10, further comprising dynamically changing the access levels to the first document and the second document.
12. the processor, 12. The computer program product of claim 10, further comprising the step of presenting the component in the second document to the user.
13. the processor, searching and retrieving the components of the second document based on the access policy; 13. The computer program product of claim 8, further comprising:
14. 14. The computer program product of claim 8, wherein the one or more components are selected from the group consisting of a table, a figure, and a section.
15. 1. A computer system comprising one or more computer processors, one or more computer readable storage media, and program instructions stored on the one or more computer readable storage media for execution by at least one of the one or more computer processors of a plurality of procedures, the plurality of procedures comprising: determining a first layout of a first document, the first layout including one or more components of the first document; defining an access policy that grants user access to a component type for the one or more components, the access policy being dynamically applied to documents whose layouts match within a predefined layout similarity threshold; determining that a second document has a second layout that matches the first layout within the predefined layout similarity threshold; receiving a request from the user to access the second document; in response to receiving the request, granting the user access to components in the second document based on the access policy and the second layout, the components being of the component type; and 1. A computer system comprising:
16. 16. The computer system of claim 15, wherein the access policy is stored external to the first document and the second document.
17. 17. The computer system according to claim 15, wherein the step of defining an access policy includes the step of defining an access level.
18. 20. The computer system of claim 17, further comprising program instructions stored on the one or more computer-readable storage media for execution by at least one of the one or more computer processors to cause the computer system to perform a procedure for dynamically changing the access levels to the first document and the second document.
19. 19. The computer system of claim 17 or 18, further comprising program instructions stored on the one or more computer-readable storage media for execution by at least one of the one or more computer processors to further cause the computer system to perform a step of presenting the component in the second document to the user.
20. 20. The computer system of claim 15, further comprising program instructions stored on the one or more computer-readable storage media for execution by at least one of the one or more computer processors to perform a procedure for searching and retrieving the components of the second document based on the access policy.
Citation Information
Patent Citations
Information management system, information management apparatus, information management method, program, and recording medium
JP2006243819A
Document management apparatus, document management method, and document management program
JP2010072690A
Access control apparatus, access control method, access control program, recording medium, access control data, and relation description data
US20060265599A1
Dynamic display of file sections based on user identities
US20190129968A1
Regulating document access
US20200044843A1