Composite Document Distribution Version Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In collaborative document workflows across multiple users and locations, ensuring secure access and protection of documents with varying sensitivity levels is challenging, especially when documents are shared through non-secure channels, and maintaining security during transit and storage in less secure environments is difficult.
Innovation Solution
A system and method for creating a distribution version of a composite document with embedded access control, allowing only authorized users to access specific parts, using encryption and digital signatures, and ensuring secure delivery and re-importation into a secure environment, utilizing a .pex composite document format and in-memory processing to manage access rights transiently.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If documents are shared through non-secure channels for collaborative workflows, then accessibility and ease of operation are improved, but security and protection of documents deteriorate
Solution Approach 1:
The patent creates a distribution version that is a copy of the master copy, specifically designed for secure sharing through non-secure channels. This distribution version includes embedded access control information and encryption keys, allowing users to access documents without compromising the master copy's security while enabling ease of operation through direct sharing capabilities.
Solution Approach 2:
The patent introduces an intermediary layer between the master copy and end users. The distribution version acts as this intermediary, containing encrypted content and access control information. This intermediary enables documents to traverse non-secure channels while maintaining security through embedded encryption and access control mechanisms.
2Object-affected harmful factors
If access control is embedded in distribution versions, then security and protection are improved, but device complexity and system complexity increase
Solution Approach 1:
The patent merges multiple security functions into a single integrated distribution version structure. Access control information, encryption keys, and document content are combined in one package. This consolidation improves security by ensuring all components work together cohesively while managing complexity through a unified rather than fragmented approach.
Solution Approach 2:
The patent performs preliminary actions by pre-embedding access control information and encryption keys into the distribution version before it reaches users. This preliminary preparation eliminates the need for complex authentication processes at access time, simplifying the user experience while maintaining strong security through advance security measure integration.
3Reliability
If encryption and digital signatures are used for secure delivery, then security and reliability are improved, but loss of information and data exposure increase during transit
Solution Approach 1:
The patent extracts sensitive data and access control information into separate, encrypted components within the distribution version. By separating these elements and encrypting them independently, the system minimizes data exposure during transit while maintaining reliability through proper authentication and access control mechanisms.
Data Source
AI summary
A method and system for a business workflow of a composite document are described. An integrity and authenticity of an entry table are identified and verified using a verification key, a map file corresponding to entries in the table are identified using a private user decryption key, signature verification keys and access keys are read from the map file, and authenticity of the map file and the document parts are verified. Following verification, content is delivered to a user for review, update and/or modification of the content, and then is encrypted, signed, and moved along the workflow, normally to the next workflow participant. A secure distribution version of a composite document is created from a master copy by creating a serialization including at least one part of a composite document and at least one user, creating a table listing document parts and associated users, generating encryption and decryption keys, encrypting document parts, applying signatures to encrypted document parts, updating the tables with the signed parts and updating the composite document with the updated tables. A master copy is updated from a secure distribution copy after the distribution copy has completed a workflow and a workflow wrap.


