Selective Deletion of Synchronized Content Copies for Security Clearance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern collaboration systems face risks due to distributed copies of shared content objects remaining accessible to users who no longer possess the required security clearance, as changes in security levels are not promptly reflected across all copies, leading to potential unauthorized access and security vulnerabilities.

Innovation Solution

Implementing a system that detects changes in security-related parameters and selectively deletes synchronized content object copies from user devices, ensuring that only authorized users with sufficient clearance can access the content objects, while retaining the content object management system for continued use within secure boundaries.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If distributed copies of content objects are maintained at user devices for offline access and collaboration, then ease of operation and productivity are improved, but security reliability deteriorates when security clearance changes occur

Engineering Contradiction:
Improveoffline access capabilityVSAvoidsecurity clearance enforcement
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary actions by establishing a change notification mechanism that proactively detects security parameter changes at the content object management system and immediately notifies affected user devices. This allows the system to preemptively handle security clearance changes before unauthorized access can occur, rather than reacting after a security breach is detected.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements a feedback loop where the content object management system monitors security parameter changes and sends notifications back to user devices. User devices then respond by evaluating their local copies against the updated security parameters and deleting copies that no longer meet clearance requirements. This closed-loop feedback ensures continuous security enforcement despite distributed storage.

Inventive Principle:
Principle #23Feedback

2Reliability

If security levels on content objects are raised to prevent unauthorized access, then security reliability is improved, but loss of information occurs when local copies remain accessible to users who no longer have sufficient clearance

Engineering Contradiction:
Improveaccess control enforcementVSAvoidauthorized access denial
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system applies local quality by allowing different security evaluations at different locations. The content object management system maintains the authoritative security parameters, while user devices maintain local copies with embedded security parameters. Each location evaluates access control locally based on its own security parameters, enabling nuanced security enforcement that respects both centralized policy and local context.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system handles parameter changes by detecting modifications to security-related parameters (such as security levels and clearance requirements) and dynamically adjusting access control decisions. When security parameters change at the content object management system, the notification mechanism ensures user devices receive updates and re-evaluate their local copies, maintaining access control integrity without permanently blocking future authorized access.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If local copies are deleted from user devices when security clearance changes, then security reliability is improved, but loss of time occurs due to the need to re-synchronize content objects

Engineering Contradiction:
Improvesecurity clearance enforcementVSAvoidre-synchronization delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system applies partial action by selectively deleting only those local copies that no longer meet security clearance requirements, rather than deleting all local copies. This targeted approach minimizes the amount of content that needs to be re-synchronized, reducing time loss while still maintaining security. Users retain access to content objects for which they still have appropriate clearance.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system performs preliminary evaluation of security parameters before deletion occurs. By comparing local security parameters with updated parameters from the content object management system, the system can predict which copies will need to be deleted and prepare for re-synchronization only of those specific items, rather than performing a complete re-synchronization of all content objects.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11483386B1Selective deletion of synchronized content object copies based on a detected change
Publication Date: 2022.10.25 BOX INC
  • US11483386B1 patent drawing
  • US11483386B1 patent drawing
  • US11483386B1 patent drawing

AI summary

A cloud-based content object management system responds to download requests from user devices to provide access to synchronization code. Using the synchronization code, a user device requests, receives, and stores a user-device-local copy of a subject content object. The cloud-based content object management system determines that at least one security-related parameter pertaining to the subject content object has undergone a change and reaches a determination that the user-device-local copy of the subject content object is to be either deleted or quarantined. Upon such determination, the cloud-based content object management system forms eviction instructions and sends them to the user device, which in turn causes deletion or quarantining of the remote content object copy at the user device, while still retaining directory structure metadata that refers to the now evicted subject content object. The subject content object stored at the cloud-based content object management system is synchronized with other user devices.