Behavioral Models for Document Access Control Across Sharing Platforms

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data protection methods across sharing platforms are inadequate in preventing unintentional sharing of sensitive information and detecting malicious intent in document distribution.

Innovation Solution

A method that involves correlating sequences of words in documents with language signals to generate document tags, associating these tags with documents, and enforcing data access policies based on identity characteristics and behavioral models to restrict access when thresholds are exceeded.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data access policies are manually configured and reviewed, then policy accuracy and security are improved, but operational complexity and time consumption increase

Engineering Contradiction:
Improvedata access policy accuracyVSAvoidpolicy management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system automatically generates data access policies by analyzing document metadata, user profiles, and organizational hierarchies without requiring manual policy creation. The policy engine self-adjusts access rights based on real-time data about users and documents, eliminating the need for manual policy configuration while maintaining high accuracy.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system dynamically changes access policy parameters based on real-time data such as user roles, document sensitivity levels, and organizational structure. Instead of static manual policies, the system continuously adjusts access parameters like permission levels, sharing restrictions, and visibility settings based on current organizational state.

Inventive Principle:
Principle #35Parameter changes

2Productivity

If automated policy generation is implemented, then operational efficiency is improved, but policy precision and customization may deteriorate

Engineering Contradiction:
Improvepolicy generation efficiencyVSAvoidaccess policy customization
Core Design Contradiction:
ProductivityVSManufacturing precision

Solution Approach 1:

The system applies different levels of automation based on local requirements. High-level automation generates general access policies, while specific local needs can trigger manual review or customization. The policy engine allows organizations to maintain high automation efficiency while preserving the ability to customize policies for specific sensitive documents or user groups when needed.

Inventive Principle:
Principle #3Local quality

3Object-affected harmful factors

If comprehensive data protection measures are implemented, then data security is improved, but system complexity and implementation difficulty increase

Engineering Contradiction:
Improvedata leakage preventionVSAvoidsystem implementation complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The system uses a universal policy engine that handles multiple data protection functions through a single integrated platform. It simultaneously manages access control, data classification, sharing restrictions, and compliance monitoring using the same core technology, reducing implementation complexity compared to multiple separate security systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system performs preliminary data classification and sensitivity analysis automatically when documents are created or uploaded. By pre-tagging documents with security attributes and pre-configuring user profiles with access rights, the system reduces the complexity of ongoing security management and enables comprehensive protection without requiring complex real-time intervention.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12373585B2Method for data protection across sharing platforms
Publication Date: 2025.07.29 ARMORBLOX INC
  • US12373585B2 patent drawing
  • US12373585B2 patent drawing
  • US12373585B2 patent drawing

AI summary

A method includes: accessing a corpus of messages previously sent from a user account; correlating sequences of words, in the corpus of messages, with behavior signals; aggregating the behavior signals into a behavioral model representing combinations of behavior signals characteristic of behavior in messages sent from the user account; later, accessing a message outbound from the user account to a recipient account, the message including a document associated with a document tag; correlating sequences of words, in the message, with behavior signals; retrieving a data access policy including a threshold at which access to a document associated with the document tag is restricted; and in response to detecting a difference between the behavioral signals from the message and the behavioral model exceeding the threshold, restricting access, by the recipient account, to the document in the message.