Cross-Domain Document Merging via Trusted Services

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems for collaboration across security levels in data processing are limited, as they struggle to manage document changes and maintain data separation effectively between different security domains, leading to conflicts and inefficiencies in sharing and editing documents across varying administrative levels.

Innovation Solution

The implementation of a method and apparatus that allow users from different security domains to access and edit documents while maintaining data separation, using a merge engine to reconcile changes and resolve conflicts, and employing security attributes to determine access rights, ensuring that sensitive information is not shared across unauthorized domains.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a copy of a document is transmitted between different security levels with proprietary modifications, then data separation and security are maintained, but collaboration efficiency and document sharing capability deteriorate

Engineering Contradiction:
Improvedata separationVSAvoidcollaboration efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments a document into multiple portions, each associated with different security levels. Users at different security levels can access and modify their respective portions simultaneously, enabling collaboration without requiring complete document copies to be transmitted across security boundaries. This resolves the contradiction by maintaining data separation while improving collaboration efficiency.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a document server as an intermediary that manages document portions across different security levels. The document server coordinates access, handles modifications, and ensures proper security enforcement without requiring direct peer-to-peer document transmission between users at different security levels. This enables efficient collaboration while maintaining security boundaries.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a user at a higher security level removes or shields changes to maintain confidentiality, then security is preserved, but document collaboration and seamless editing deteriorate

Engineering Contradiction:
ImproveconfidentialityVSAvoidseamless collaboration
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies local quality by associating different security attributes with different portions of the same document. Users at higher security levels can view and edit portions marked for their security level, while users at lower security levels access only their authorized portions. This eliminates the need to remove or shield changes while maintaining confidentiality, as each user naturally sees only what their security level permits.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements dynamic security attributes that can be assigned to different document portions and can change based on user context and security level. This dynamic approach allows the system to automatically enforce appropriate access controls without manual intervention to remove or shield changes, enabling seamless collaboration while preserving confidentiality.

Inventive Principle:
Principle #15Dynamics

3Reliability

If multiple versions of a document are maintained for different security levels, then data separation is ensured, but system complexity and document management difficulty increase

Engineering Contradiction:
Improvedata separationVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple document portions into a single unified document structure on the server, where each portion is associated with specific security attributes. Instead of maintaining separate document copies for different security levels, the system combines them into one document that dynamically presents appropriate portions to users based on their security clearance. This reduces system complexity while maintaining data separation.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates a universal document structure that serves multiple security levels simultaneously. A single document can be accessed by users at different security levels, with the system automatically presenting the appropriate portions to each user based on their security attributes. This multi-functional approach eliminates the need for separate document versions while ensuring data separation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Productivity

If document changes from different security levels are integrated, then collaboration capability improves, but conflict management complexity and error risk increase

Engineering Contradiction:
Improvecollaboration capabilityVSAvoidconflict management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the document into distinct portions with different security attributes, allowing users at different security levels to modify their respective portions independently. This segmentation prevents conflicts by ensuring that modifications to one portion do not interfere with other portions, as each portion has its own security boundary. This enables collaboration while minimizing conflict management complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The document server acts as an intermediary that manages the integration of changes from different security levels. It coordinates modifications, resolves potential conflicts, and ensures proper merging of changes while maintaining security boundaries. This intermediary approach enables collaboration capability improvement while managing conflict complexity centrally rather than requiring complex peer-to-peer conflict resolution.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8166559B2Document accessing through multiple security domains including multi-tear wiki webpage and/or using cross domain trusted service
Publication Date: 2012.04.24 GALOIS INC
  • US8166559B2 patent drawing
  • US8166559B2 patent drawing
  • US8166559B2 patent drawing

AI summary

Methods and apparatuses for accessing documents in a multi-security domain environment are described herein. The novel methods may be processor implemented methods and may include saving by a processor from a first to a second security domain a version of a document, e.g., a wiki webpage with multiple tear portions, wherein the first security is a higher security domain than the second security domain. As part of the saving operation, a determination may be made as to whether the document includes one or more components not to be accessible through the second security domain, and writing the components of the document excluding the one or more components determined not to be accessible through the second security domain into the second security domain. The methods may further include opening the document through the security domain by determining whether a version of the document has been saved to the second security domain, and if so, merging a copy of modifications made to version of the document, if there are any, into the document being open. In various embodiments, a domain specific document server and a cross security domain trusted services are employed to enable among other things, reduction of number of storage devices needed.