Selective Deletion of Synchronized Content Copies for Security Clearance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Modern collaboration systems face risks due to distributed copies of shared content objects remaining accessible to users who no longer possess the required security clearance, as changes in security levels are not promptly reflected across all copies, leading to potential unauthorized access and security vulnerabilities.
Innovation Solution
Implementing a system that detects changes in security-related parameters and selectively deletes synchronized content object copies from user devices, ensuring that only authorized users with sufficient clearance can access the content objects, while retaining the content object management system for continued use within secure boundaries.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If distributed copies of content objects are maintained at user devices for offline access and collaboration, then ease of operation and productivity are improved, but security reliability deteriorates when security clearance changes occur
Solution Approach 1:
The system performs preliminary actions by establishing a change notification mechanism that proactively detects security parameter changes at the content object management system and immediately notifies affected user devices. This allows the system to preemptively handle security clearance changes before unauthorized access can occur, rather than reacting after a security breach is detected.
Solution Approach 2:
The system implements a feedback loop where the content object management system monitors security parameter changes and sends notifications back to user devices. User devices then respond by evaluating their local copies against the updated security parameters and deleting copies that no longer meet clearance requirements. This closed-loop feedback ensures continuous security enforcement despite distributed storage.
2Reliability
If security levels on content objects are raised to prevent unauthorized access, then security reliability is improved, but loss of information occurs when local copies remain accessible to users who no longer have sufficient clearance
Solution Approach 1:
The system applies local quality by allowing different security evaluations at different locations. The content object management system maintains the authoritative security parameters, while user devices maintain local copies with embedded security parameters. Each location evaluates access control locally based on its own security parameters, enabling nuanced security enforcement that respects both centralized policy and local context.
Solution Approach 2:
The system handles parameter changes by detecting modifications to security-related parameters (such as security levels and clearance requirements) and dynamically adjusting access control decisions. When security parameters change at the content object management system, the notification mechanism ensures user devices receive updates and re-evaluate their local copies, maintaining access control integrity without permanently blocking future authorized access.
3Reliability
If local copies are deleted from user devices when security clearance changes, then security reliability is improved, but loss of time occurs due to the need to re-synchronize content objects
Solution Approach 1:
The system applies partial action by selectively deleting only those local copies that no longer meet security clearance requirements, rather than deleting all local copies. This targeted approach minimizes the amount of content that needs to be re-synchronized, reducing time loss while still maintaining security. Users retain access to content objects for which they still have appropriate clearance.
Solution Approach 2:
The system performs preliminary evaluation of security parameters before deletion occurs. By comparing local security parameters with updated parameters from the content object management system, the system can predict which copies will need to be deleted and prepare for re-synchronization only of those specific items, rather than performing a complete re-synchronization of all content objects.
Data Source
AI summary
A cloud-based content object management system responds to download requests from user devices to provide access to synchronization code. Using the synchronization code, a user device requests, receives, and stores a user-device-local copy of a subject content object. The cloud-based content object management system determines that at least one security-related parameter pertaining to the subject content object has undergone a change and reaches a determination that the user-device-local copy of the subject content object is to be either deleted or quarantined. Upon such determination, the cloud-based content object management system forms eviction instructions and sends them to the user device, which in turn causes deletion or quarantining of the remote content object copy at the user device, while still retaining directory structure metadata that refers to the now evicted subject content object. The subject content object stored at the cloud-based content object management system is synchronized with other user devices.


