Document Access Across Security Domains via Component Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems for collaboration across multiple security levels in data processing struggle with managing document changes and maintaining data separation, leading to conflicts and inefficiencies when users with different security levels modify documents.

Innovation Solution

Implementing a method that allows users with higher security access to edit and manage documents while maintaining data separation by filtering out private components and using a merge engine to reconcile changes from different security domains, ensuring that only accessible components are shared and edited across domains.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a copy of a document is transmitted and cleansed between different security levels, then data separation and security are maintained, but collaboration efficiency deteriorates and document modification management becomes complex

Engineering Contradiction:
Improvedata separationVSAvoidcollaboration efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments a document into multiple components, each with its own security classification. This allows different components to be accessed and modified by users at different security levels simultaneously, enabling collaboration without requiring complete document cleansing and copying between security domains.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements a nested document structure where a parent document contains multiple child components with different security classifications. This hierarchical nesting allows the document as a whole to maintain security boundaries while individual components can be shared across security levels, eliminating the need for complete document copying.

Inventive Principle:
Principle #7Nested doll (Nesting)

2Reliability

If users keep private copies of modified documents, then security requirements are met, but document version management and conflict resolution become difficult

Engineering Contradiction:
Improvesecurity complianceVSAvoiddocument management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent provides a merge engine that automatically combines modifications from different security levels into a single coordinated version of the document. This eliminates the need for users to maintain separate private copies, as all changes are integrated through the unified multi-component structure with automated conflict resolution.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent implements automated feedback mechanisms where the system monitors modifications across security levels and triggers appropriate conflict resolution processes. This feedback loop manages document versions automatically, reducing the complexity of manual version control while maintaining security compliance.

Inventive Principle:
Principle #23Feedback

3Reliability

If higher security level users remove or shield changes before transmission, then confidential information is protected, but collaboration seamlessness deteriorates and user effort increases

Engineering Contradiction:
ImproveconfidentialityVSAvoidcollaboration seamlessness
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent performs preliminary classification of document components into different security levels during document creation or initial sharing. This preliminary action establishes the security architecture in advance, so that subsequent collaborations occur automatically within the defined security boundaries without requiring users to manually remove or shield changes before each transmission.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8171557B2Document accessing through multiple security domains
Publication Date: 2012.05.01 GALOIS INC
  • US8171557B2 patent drawing
  • US8171557B2 patent drawing
  • US8171557B2 patent drawing

AI summary

Methods and apparatuses for accessing documents in a multi-security domain environment are described herein. The novel methods may be processor implemented methods and may include saving by a processor from a first to a second security domain a version of a document, wherein the first security is a higher security domain than the second security domain. As part of the saving operation, a determination may be made as to whether the document includes one or more components not to be accessible through the second security domain, and writing the components of the document excluding the one or more components determined not to be accessible through the second security domain into the second security domain. The methods may further include opening the document through the security domain by determining whether a version of the document has been saved to the second security domain, and if so, merging a copy of modifications made to version of the document, if there are any, into the document being open. In various embodiments, a domain specific document server and a cross security domain trusted services are employed to enable among other things, reduction of number of storage devices needed.