Cross-Domain Document Merging via Trusted Services
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems for collaboration across security levels in data processing are limited, as they struggle to manage document changes and maintain data separation effectively between different security domains, leading to conflicts and inefficiencies in sharing and editing documents across varying administrative levels.
Innovation Solution
The implementation of a method and apparatus that allow users from different security domains to access and edit documents while maintaining data separation, using a merge engine to reconcile changes and resolve conflicts, and employing security attributes to determine access rights, ensuring that sensitive information is not shared across unauthorized domains.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a copy of a document is transmitted between different security levels with proprietary modifications, then data separation and security are maintained, but collaboration efficiency and document sharing capability deteriorate
Solution Approach 1:
The patent segments a document into multiple portions, each associated with different security levels. Users at different security levels can access and modify their respective portions simultaneously, enabling collaboration without requiring complete document copies to be transmitted across security boundaries. This resolves the contradiction by maintaining data separation while improving collaboration efficiency.
Solution Approach 2:
The patent introduces a document server as an intermediary that manages document portions across different security levels. The document server coordinates access, handles modifications, and ensures proper security enforcement without requiring direct peer-to-peer document transmission between users at different security levels. This enables efficient collaboration while maintaining security boundaries.
2Reliability
If a user at a higher security level removes or shields changes to maintain confidentiality, then security is preserved, but document collaboration and seamless editing deteriorate
Solution Approach 1:
The patent applies local quality by associating different security attributes with different portions of the same document. Users at higher security levels can view and edit portions marked for their security level, while users at lower security levels access only their authorized portions. This eliminates the need to remove or shield changes while maintaining confidentiality, as each user naturally sees only what their security level permits.
Solution Approach 2:
The patent implements dynamic security attributes that can be assigned to different document portions and can change based on user context and security level. This dynamic approach allows the system to automatically enforce appropriate access controls without manual intervention to remove or shield changes, enabling seamless collaboration while preserving confidentiality.
3Reliability
If multiple versions of a document are maintained for different security levels, then data separation is ensured, but system complexity and document management difficulty increase
Solution Approach 1:
The patent merges multiple document portions into a single unified document structure on the server, where each portion is associated with specific security attributes. Instead of maintaining separate document copies for different security levels, the system combines them into one document that dynamically presents appropriate portions to users based on their security clearance. This reduces system complexity while maintaining data separation.
Solution Approach 2:
The patent creates a universal document structure that serves multiple security levels simultaneously. A single document can be accessed by users at different security levels, with the system automatically presenting the appropriate portions to each user based on their security attributes. This multi-functional approach eliminates the need for separate document versions while ensuring data separation.
4Productivity
If document changes from different security levels are integrated, then collaboration capability improves, but conflict management complexity and error risk increase
Solution Approach 1:
The patent segments the document into distinct portions with different security attributes, allowing users at different security levels to modify their respective portions independently. This segmentation prevents conflicts by ensuring that modifications to one portion do not interfere with other portions, as each portion has its own security boundary. This enables collaboration while minimizing conflict management complexity.
Solution Approach 2:
The document server acts as an intermediary that manages the integration of changes from different security levels. It coordinates modifications, resolves potential conflicts, and ensures proper merging of changes while maintaining security boundaries. This intermediary approach enables collaboration capability improvement while managing conflict complexity centrally rather than requiring complex peer-to-peer conflict resolution.
Data Source
AI summary
Methods and apparatuses for accessing documents in a multi-security domain environment are described herein. The novel methods may be processor implemented methods and may include saving by a processor from a first to a second security domain a version of a document, e.g., a wiki webpage with multiple tear portions, wherein the first security is a higher security domain than the second security domain. As part of the saving operation, a determination may be made as to whether the document includes one or more components not to be accessible through the second security domain, and writing the components of the document excluding the one or more components determined not to be accessible through the second security domain into the second security domain. The methods may further include opening the document through the security domain by determining whether a version of the document has been saved to the second security domain, and if so, merging a copy of modifications made to version of the document, if there are any, into the document being open. In various embodiments, a domain specific document server and a cross security domain trusted services are employed to enable among other things, reduction of number of storage devices needed.


