Context-Aware Policy Engine for Document Data Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Document-level metadata is insufficient for preventing the leakage of sensitive data, especially in collaborative document creation and sharing environments, as it fails to account for real-time document content and context, leading to potential data breaches.

Innovation Solution

Implementing context-aware policies that analyze document content, including keywords, data patterns, and regular expressions, to dynamically control access and actions on documents, ensuring that policies are self-consistent and prioritized to avoid ambiguous results.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If document-level metadata is used for access control, then implementation is simple, but it fails to prevent leakage of sensitive data

Engineering Contradiction:
Improveimplementation simplicityVSAvoiddata protection effectiveness
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent implements dynamic access control by analyzing document content in real-time rather than relying on static metadata. The system dynamically evaluates document content, user context, and policy rules at the moment of access to make informed decisions about data protection, resolving the contradiction between simple implementation and effective protection.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent replaces the mechanical approach of metadata-based access control with a content-aware analysis system. Instead of relying on document-level metadata tags, the system uses text analysis, pattern recognition, and contextual evaluation to determine data sensitivity and apply appropriate protection measures.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If context-aware policies analyze document content in real-time, then data protection effectiveness is improved, but processing time increases

Engineering Contradiction:
Improvedata protection effectivenessVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-defining policy rules, content patterns, and sensitivity thresholds before actual access occurs. The system pre-processes policy configurations and maintains indexes of sensitive content patterns, enabling rapid real-time evaluation without performing complex analysis from scratch during access events.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent ensures continuity of useful action by maintaining persistent policy evaluation contexts and cached analysis results. The system continues monitoring and evaluating document content in real-time without repeated redundant processing, balancing thorough analysis with processing efficiency through continuous rather than intermittent evaluation.

Inventive Principle:
Principle #20Continuity of useful action

3Reliability

If multiple policies are applied to the same document, then comprehensive data protection is achieved, but policy conflict and ambiguity increase

Engineering Contradiction:
Improvedata protection comprehensivenessVSAvoidpolicy management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments policy evaluation into distinct, manageable components by separating policy rules from document content analysis. The system divides policies into specific categories (data sensitivity, user authorization, contextual rules) and evaluates them independently, then combines results systematically, reducing the complexity of managing multiple overlapping policies.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary policy resolution mechanism that mediates between multiple conflicting policies. The system uses a centralized policy evaluation engine that acts as a mediator, reconciling different policy requirements and determining precedence based on predefined resolution rules, thereby reducing ambiguity in multi-policy environments.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8689281B2Management of context-aware policies
Publication Date: 2014.04.01 HEWLETT PACKARD DEVELOPMENT COMPANY LP
  • US8689281B2 patent drawing
  • US8689281B2 patent drawing
  • US8689281B2 patent drawing

AI summary

A method includes obtaining input to modify a policy of a set of context-aware document policies. A policy of the set is applicable to a requested action on a document so as to indicate allowability of the requested action based at least on satisfaction of a condition of the policy that relates to a content of the document. When a plurality of policies of the set are applicable to the requested action on the document, allowability of the requested action is determined by the allowability that is indicated by application of the applicable policy with a highest priority. The modified policy is compared with another policy of the set. If the comparison indicates the modified policy and the other policy are applicable to a single requested action on a single document, the set of policies is automatically ensured to remain self consistent.