Cryptographic Key Management for Document Retention Policies
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional security systems fail to reliably protect proprietary information from unauthorized access, both internally and externally, and are inadequate in implementing document retention policies for electronic documents, especially when retention periods depend on unscheduled future events.
Innovation Solution
A method and system that utilize security criteria to impose document retention policies on electronic documents, restricting access by encrypting and decrypting files using cryptographic keys, where the retention policy is based on unscheduled future events, ensuring that access is restricted once the retention period expires.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If cryptographic keys are made available for accessing electronic documents, then access to documents is enabled, but unauthorized access and security breaches occur when retention periods expire
Solution Approach 1:
The system performs preliminary actions by establishing retention policies and scheduling future events before the retention period expires. The key management system proactively revokes access keys based on pre-defined retention criteria and scheduled events, preventing unauthorized access before it can occur rather than reacting after a breach.
Solution Approach 2:
The system implements feedback mechanisms by continuously monitoring document access requests against retention policies. The key management system receives feedback about access attempts and automatically responds by granting or revoking keys based on whether the document is still within its retention period, creating a closed-loop security system.
2Adaptability or versatility
If document retention policies are implemented with unscheduled future events, then flexible retention control is achieved, but system complexity increases due to key management overhead
Solution Approach 1:
The patent introduces a key management system as an intermediary between documents and users. This mediator handles the complexity of retention policies, key generation, and access control automatically, allowing flexible retention based on unscheduled events without requiring complex user-side implementation. The intermediary absorbs the system complexity while providing simple interfaces to users.
3Ease of operation
If access keys are retained indefinitely for potential future access, then document accessibility is maintained, but secure disposal of sensitive information cannot be achieved
Solution Approach 1:
The system implements dynamic key management where access keys have temporary validity periods rather than being static or indefinite. Keys are automatically revoked after retention periods expire or when scheduled events occur, making the security state dynamic and adaptive. This allows the system to balance accessibility during the retention period with secure disposal afterward, as the key validity changes over time based on policy conditions.
Data Source
AI summary
Techniques for utilizing security criteria to implement document retention for electronic documents are disclosed. The security criteria can also limit when, how and where access to the electronic documents is permitted. The security criteria can pertain to keys (or ciphers) used to secure (e.g., encrypt) electronic files (namely, electronic documents), or to unsecure (e.g., decrypt) electronic files already secured. At least a portion of the security criteria can be used to implement document retention, namely, a document retention policy. After a secured electronic document has been retained for the duration of the document retention policy, the associated security criteria becomes no longer available, thus preventing subsequent access to the secured electronic document. In other words, access restrictions on electronic documents can be used to prevent access to electronic documents which are no longer to be retained.


