Cryptographic Document Retention with Offline Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional security systems are inadequate in protecting proprietary information from unauthorized access, both internally and externally, and struggle to enforce document retention policies in distributed computing environments, especially for electronic documents residing on off-line systems.

Innovation Solution

Implementing a document retention system that uses cryptographic security criteria to restrict access to electronic documents based on a recurring cut-off retention schedule, where security keys are periodically updated and expire after a specified period, preventing access to documents no longer intended for retention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cryptographic techniques are used to secure electronic documents in distributed environments, then document security and retention enforcement are improved, but system complexity and key management overhead increase

Engineering Contradiction:
Improvedocument securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments document security by applying different retention periods and cryptographic keys to different documents or document portions. Each document can have its own retention policy and associated key, allowing granular control over security enforcement without requiring complex centralized management of all documents uniformly.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary cryptographic processing by pre-computing and storing cryptographic keys associated with retention periods before documents need to be accessed. Keys are generated and distributed in advance according to predetermined retention schedules, eliminating the need for complex real-time key management when documents are accessed.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If cryptographic keys are periodically updated with recurring cut-off schedules, then document retention enforcement is improved, but key management complexity and processing overhead increase

Engineering Contradiction:
Improveretention enforcementVSAvoidprocessing overhead
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system implements periodic key updates by generating and distributing cryptographic keys according to predetermined recurring cut-off schedules. Keys are updated at regular intervals (e.g., daily, weekly, monthly) based on retention policies, automating the retention enforcement process and reducing manual intervention while maintaining reliable document access control.

Inventive Principle:
Principle #19Periodic action

3Reliability

If access to electronic documents is restricted based on retention policies, then data protection is improved, but accessibility and ease of operation deteriorate

Engineering Contradiction:
Improvedata protectionVSAvoiddocument accessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system enables self-service document access by automatically evaluating retention policies and providing appropriate cryptographic keys to users based on their access requests and the document's retention status. The system autonomously determines whether a document should be accessible and provides the necessary keys without requiring manual security administration, making the process transparent and easy to use while maintaining strong data protection.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS7748045B2Method and system for providing cryptographic document retention with off-line access
Publication Date: 2010.06.29 PROGRESS SOFTWARE CORP
  • US7748045B2 patent drawing
  • US7748045B2 patent drawing
  • US7748045B2 patent drawing

AI summary

Techniques for utilizing security criteria to implement document retention for electronic documents are disclosed. The security criteria can also limit when, how and where access to the electronic documents is permitted. The security criteria can pertain to keys (or ciphers) used to secure (e.g., encrypt) electronic files (namely, electronic documents), or to unsecure (e.g., decrypt) electronic files already secured. At least a portion of the security criteria can be used to implement document retention, namely, a document retention policy. After a secured electronic document has been retained for the duration of the document retention policy, the associated security criteria becomes no longer available, thus preventing subsequent access to the secured electronic document. In other words, access restrictions on electronic documents can be used to prevent access to electronic documents which are no longer to be retained.