Composite Access Control for Multi-Document Media

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems fail to create composite management rules for a single medium that do not violate the individual management rules of multiple documents stored within, leading to inadequate management of electronic data with diverse validity terms, access controls, and storage policies.

Innovation Solution

A composite medium management system and apparatus that includes an information management server and client apparatus, capable of communicating to create composite access control policies that do not violate the management rules of each document, by evaluating and combining policy files and user information to determine valid storage and access conditions for a single medium.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If multiple documents with different management rules are stored in a single medium, then storage efficiency is improved, but creating composite management rules that do not violate individual document rules becomes complex and difficult

Engineering Contradiction:
Improvenumber of documents stored in single mediumVSAvoidcomplexity of creating composite management rules
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The patent segments management rules into hierarchical levels: document-level rules (term of validity, takeout range, authority to view) and medium-level rules. The composite medium management rule generation unit processes individual document rules separately and combines them systematically, rather than attempting to create composite rules monolithically, thereby reducing complexity while enabling storage of multiple documents with different rules in a single medium.

Inventive Principle:
Principle #1Segmentation

2Reliability

If conventional access control techniques are applied to individual documents, then document-level security is maintained, but composite management rules for the medium cannot be created

Engineering Contradiction:
Improvedocument-level security complianceVSAvoidability to create composite medium management rules
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent merges document-level access control with medium-level management by introducing a composite medium management rule generation unit that systematically combines individual document rules (term of validity, takeout range, authority to view) into composite medium rules. This merging enables both document-level security compliance and medium-level management capability to coexist, allowing the system to generate composite rules that respect individual document constraints while providing unified medium management.

Inventive Principle:
Principle #5Merging (Combining)

3Adaptability or versatility

If documents with different terms of validity are stored together, then storage versatility is improved, but determining a unified term of validity for the medium becomes difficult

Engineering Contradiction:
Improveability to store documents with different validity termsVSAvoiddifficulty of determining unified medium validity term
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic rule generation where the composite medium management rules are not static but are generated adaptively based on the specific combination of documents stored. The composite medium management rule generation unit dynamically determines unified terms of validity by processing the validity terms of individual documents, allowing the system to accommodate documents with different validity periods while automatically establishing appropriate medium-level constraints that reflect the actual document portfolio.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10185716B2Composite medium management system, information management server apparatus, composite access control creation apparatus, and program
Publication Date: 2019.01.22 TOSHIBA DIGITAL SOLUTIONS CORP
  • US10185716B2 patent drawing
  • US10185716B2 patent drawing
  • US10185716B2 patent drawing

AI summary

Upon receiving a medium storage request from a client apparatus, an information management server apparatus according to an embodiment evaluates, based on at least one policy file read out based on at least one parent management ID in the medium storage request and user information in the medium storage request, whether medium storage responding to the medium storage request is possible. Upon evaluating that the medium storage is possible, the information management server apparatus creates composite access control which do not violate any management rules included in the at least one policy file.