Cryptographic Key Management for Document Retention Policies

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional security systems fail to reliably protect proprietary information from unauthorized access, both internally and externally, and are inadequate in implementing document retention policies for electronic documents, especially when retention periods depend on unscheduled future events.

Innovation Solution

A method and system that utilize security criteria to impose document retention policies on electronic documents, restricting access by encrypting and decrypting files using cryptographic keys, where the retention policy is based on unscheduled future events, ensuring that access is restricted once the retention period expires.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If cryptographic keys are made available for accessing electronic documents, then access to documents is enabled, but unauthorized access and security breaches occur when retention periods expire

Engineering Contradiction:
Improvedocument accessVSAvoidunauthorized access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary actions by establishing retention policies and scheduling future events before the retention period expires. The key management system proactively revokes access keys based on pre-defined retention criteria and scheduled events, preventing unauthorized access before it can occur rather than reacting after a breach.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms by continuously monitoring document access requests against retention policies. The key management system receives feedback about access attempts and automatically responds by granting or revoking keys based on whether the document is still within its retention period, creating a closed-loop security system.

Inventive Principle:
Principle #23Feedback

2Adaptability or versatility

If document retention policies are implemented with unscheduled future events, then flexible retention control is achieved, but system complexity increases due to key management overhead

Engineering Contradiction:
Improveretention policy flexibilityVSAvoidkey management system
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a key management system as an intermediary between documents and users. This mediator handles the complexity of retention policies, key generation, and access control automatically, allowing flexible retention based on unscheduled events without requiring complex user-side implementation. The intermediary absorbs the system complexity while providing simple interfaces to users.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If access keys are retained indefinitely for potential future access, then document accessibility is maintained, but secure disposal of sensitive information cannot be achieved

Engineering Contradiction:
Improvedocument accessibilityVSAvoidinformation security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system implements dynamic key management where access keys have temporary validity periods rather than being static or indefinite. Keys are automatically revoked after retention periods expire or when scheduled events occur, making the security state dynamic and adaptive. This allows the system to balance accessibility during the retention period with secure disposal afterward, as the key validity changes over time based on policy conditions.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS8613102B2Method and system for providing document retention using cryptography
Publication Date: 2013.12.17 PROGRESS SOFTWARE CORP
  • US8613102B2 patent drawing
  • US8613102B2 patent drawing
  • US8613102B2 patent drawing

AI summary

Techniques for utilizing security criteria to implement document retention for electronic documents are disclosed. The security criteria can also limit when, how and where access to the electronic documents is permitted. The security criteria can pertain to keys (or ciphers) used to secure (e.g., encrypt) electronic files (namely, electronic documents), or to unsecure (e.g., decrypt) electronic files already secured. At least a portion of the security criteria can be used to implement document retention, namely, a document retention policy. After a secured electronic document has been retained for the duration of the document retention policy, the associated security criteria becomes no longer available, thus preventing subsequent access to the secured electronic document. In other words, access restrictions on electronic documents can be used to prevent access to electronic documents which are no longer to be retained.