Context-Based Electronic Marking for Document Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions fail to effectively prevent unauthorized access to confidential information and identify users who leak such information, as they primarily focus on confidentiality marks without addressing document distribution or user accountability.

Innovation Solution

A system that assigns context-based electronic marks to documents, monitors access activity, and enforces access rules to deny unauthorized access, while also tracking and identifying users who disclose confidential information through features like containerization, text unicalization, and tracker modules.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If confidentiality marks are placed on documents, then document classification is achieved, but unauthorized distribution and user identification capabilities are lost

Engineering Contradiction:
Improveconfidential information protectionVSAvoiddistribution control and user identification
Core Design Contradiction:
Loss of informationVSAdaptability or versatility

Solution Approach 1:

The electronic mark is segmented into multiple functional components: identification data (for classifying document confidentiality levels), tracking data (for monitoring distribution and identifying users), and control data (for enforcing access permissions). This segmentation allows each component to serve its specific function while working together to resolve the contradiction between protection and traceability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The electronic mark system performs multiple functions simultaneously: it classifies documents by confidentiality level, tracks distribution paths, identifies responsible users, and enforces access control. This multi-functionality eliminates the need for separate systems for each purpose, resolving the contradiction by making the mark system versatile enough to handle both protection and identification tasks.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If access control is implemented, then unauthorized access is prevented, but user identification for leak tracking is not achieved

Engineering Contradiction:
Improveaccess controlVSAvoidleak source identification
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system implements feedback mechanisms where the electronic mark continuously tracks document access and distribution. When a document is accessed or distributed, the tracking data records the user identity and transmission path, providing feedback that enables leak source identification while maintaining access control reliability.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The electronic mark is assigned to the document before any access or distribution occurs. This preliminary action ensures that tracking data is already in place to identify users and trace distribution paths, enabling leak tracking capability to be established before any unauthorized actions take place.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If manual mark assignment is used, then mark accuracy is achieved, but processing efficiency and real-time monitoring are reduced

Engineering Contradiction:
Improvemark assignment accuracyVSAvoiddocument processing speed
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system enables automatic assignment of electronic marks based on predefined classification rules and document metadata. The mark assignment process serves itself by automatically analyzing document properties and applying appropriate marks without manual intervention, thereby maintaining accuracy through consistent rule application while dramatically improving processing efficiency.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system changes the parameters of mark assignment from manual input to automated parameter analysis. By analyzing document parameters such as content, metadata, and classification tags, the system automatically determines the appropriate electronic mark to assign, achieving both precision through systematic analysis and productivity through automation.

Inventive Principle:
Principle #35Parameter changes

4Loss of information

If comprehensive monitoring is implemented, then leak detection capability is improved, but system complexity and resource consumption increase

Engineering Contradiction:
Improveleak detection capabilityVSAvoidmonitoring system complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The system merges leak detection functionality directly into the electronic mark structure itself. The tracking data within the mark serves as both the classification identifier and the leak detection mechanism, eliminating the need for separate complex monitoring systems. This combining approach improves leak detection while reducing overall system complexity.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11295027B2System and method for protecting electronic documents containing confidential information from unauthorized access
Publication Date: 2022.04.05 CROSSTECH SOLUTIONS GRP LLC
  • US11295027B2 patent drawing
  • US11295027B2 patent drawing
  • US11295027B2 patent drawing

AI summary

A method for protecting documents includes assigning electronic marks to a document. The marks are assigned based on a context of the document. Access activity with respect to the document is monitored continuously. In response to receiving a request from a user to access the document, permissions to access the document are checked by analyzing metadata of the document and access rules are analyzed. In response to determining that the marks are not included in the list of permitted marks for the user requesting the access to the document, access to the document is denied and a notification to a server is sent indicating an attempted unauthorized access to the document. Attributes of the marks are analyzed, in response to determining that the marks are included in the list of permitted marks. Access to the document is provided in accordance with the attributes of the marks.