Cloaked Data Objects in Electronic Content Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current electronic content management systems (ECM) restrict access to data objects, preventing users from learning about the existence and relationships of inaccessible objects, which can lead to inaccurate decision-making in design changes and resource estimation.
Innovation Solution
Implementing 'cloaked' data objects in ECM systems, where users can access information about the existence and relationships of inaccessible data objects without revealing their substantive content, allowing transparent processing by client applications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the ECM system returns no data objects when a user lacks read-access privileges, then access control security is maintained, but the user cannot learn about the existence or relationships of inaccessible data objects
Solution Approach 1:
The data object information is segmented into two distinct parts: (1) structural/relational metadata that is visible to all users, and (2) substantive content that remains restricted. The system displays cloaked data objects that show hierarchical relationships, parent-child connections, and structural context without revealing the actual content, thereby maintaining security while providing existence information.
Solution Approach 2:
The system introduces an intermediary representation called a 'cloaked data object' that acts as a mediator between the user and the actual restricted data. This cloaked object presents a simplified view showing only structural relationships and existence information, while the substantive content remains protected. The cloaked object serves as a safe intermediary that satisfies the user's need for contextual information without compromising security.
2Loss of information
If the ECM system provides broad read-access to all data objects, then users can evaluate design changes and resource usage accurately, but proprietary information and sensitive data become vulnerable to unauthorized disclosure
Solution Approach 1:
The system applies different quality levels of information disclosure to different aspects of data objects. Structural metadata, hierarchical relationships, and contextual information are made visible with high quality (full access), while substantive content remains restricted with low quality (cloaked). This local differentiation allows users to assess relationships and existence without accessing sensitive proprietary information.
Solution Approach 2:
The system provides partial access to data object information by displaying only the portion needed for relationship assessment (structural metadata and hierarchical context) while withholding the excessive portion (substantive proprietary content). This partial action approach gives users sufficient information to evaluate design changes and resource usage without providing more access than necessary.
3Object-affected harmful factors
If the ECM system completely restricts access to data objects without read privileges, then proprietary information is protected, but designers cannot assess the impact of design changes or estimate resource costs
Solution Approach 1:
The system performs preliminary action by pre-displaying cloaked data objects that show structural relationships and existence information before any access control violation occurs. Users can immediately assess the scope of data objects, hierarchical relationships, and potential impact areas without needing to request or gain special access permissions. This preliminary provision of structural information eliminates delays in decision-making while maintaining security.
Data Source
AI summary
Embodiments of the invention provide for “cloaked” data objects in an electronic content management system. A “cloaked” data object is one that is inaccessible and unreadable by a user, but one which the user is permitted to know exists. The cloaked object may allow the user to know the scope of use of an object, without revealing the substantive content of the data object. A client application may process the cloaked object in a manner that is no different than manner in which the client processes an uncloaked version of the same data object.


