Distributed Document Security via Member Definitions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data management systems in computer networks face challenges in securely controlling access to documents, as existing methods lack efficient mechanisms to dynamically manage and enforce unique access rights for users within a work group, leading to potential unauthorized access.

Innovation Solution

A method and system for distributed dynamic security are implemented, where user access rights are determined through member definitions linked to specific document portions, using user identifiers and digital signatures to control access, with an access controller ensuring only authorized users can access encrypted documents.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional access control methods are used, then system simplicity is maintained, but security and flexibility in managing user access rights deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments access control into member definitions that are independently stored and linked to specific document portions. Each member definition contains user identifiers and access rights that can be independently managed, allowing fine-grained control over different parts of a document without requiring a complete system redesign.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a new dimension of access control by linking member definitions to specific portions of documents rather than controlling access at the entire document level. This dimensional change enables different users to have different access rights to different portions of the same document, enhancing security without requiring multiple separate documents.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Adaptability or versatility

If uniform access rights are applied to all users, then system simplicity is maintained, but adaptability to different user needs deteriorates

Engineering Contradiction:
Improveaccess right flexibilityVSAvoidaccess control complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by assigning different access rights to different portions of a document based on specific member definitions. Each portion of the document can have customized access control characteristics, allowing users to have read access to some portions while having no access to others, thereby achieving flexible adaptability without uniform treatment.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent creates a universal access control framework where member definitions serve multiple functions: they identify users, define access rights, link to document portions, and enable both encryption and decryption operations. This multi-functionality allows the system to handle diverse access requirements through a single unified mechanism.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If document access is encrypted for security, then unauthorized access is prevented, but ease of legitimate access deteriorates

Engineering Contradiction:
Improveaccess securityVSAvoidaccess convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements preliminary action by pre-establishing member definitions that contain both encryption and decryption capabilities. Users are pre-configured with their access rights and corresponding cryptographic keys before accessing documents, so that when they need to access authorized portions, the decryption process is already prepared and can proceed smoothly without additional security hurdles.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8132261B1Distributed dynamic security capabilities with access controls
Publication Date: 2012.03.06 ORACLE INT CORP
  • US8132261B1 patent drawing
  • US8132261B1 patent drawing
  • US8132261B1 patent drawing

AI summary

A method and system are disclosed for distributed dynamic security of a document. Portions of a document are associated with a plurality of member definitions. Each member definition contains an access right associated with a user. An access controller receives a request from a user and determines whether that user has sufficient access rights to access a portion of the document.