Document File Location-Based Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing techniques for securing document data by restricting usage locations are inefficient as they require costly special-purpose terminals and do not provide security for data transferred outside predetermined areas.
Innovation Solution
A document file system that includes usage location information and a data management program to control access based on the user's current location, allowing access within predetermined areas while restricting or prohibiting access outside these areas without the need for special-purpose terminals.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If costly special-purpose terminals are provided to each user to restrict data usage locations, then data security is improved, but device cost and complexity increase significantly
Solution Approach 1:
The patent embeds a data management program within the document file itself, creating a self-contained security mechanism that copies the security logic into the data structure rather than requiring special external hardware terminals. This allows standard terminals to enforce location-based access control through the embedded program.
Solution Approach 2:
The patent replaces expensive special-purpose terminals with ordinary standard terminals that can run the embedded data management program. The security function is achieved through software rather than dedicated hardware, making the solution cost-effective and accessible to common users.
2Reliability
If special-purpose terminals are required for accessing protected data, then data security is improved, but workflow efficiency deteriorates due to the need to switch between general-purpose and special-purpose terminals
Solution Approach 1:
The patent enables standard terminals to perform both general-purpose computing tasks and security-enforced data access functions through the embedded data management program. This multi-functionality eliminates the need for separate special-purpose terminals, allowing users to maintain a single terminal for all operations.
Solution Approach 2:
The patent combines the security control mechanism directly into the document file structure, merging the data and its access control logic into a single integrated unit. This eliminates the need for separate security hardware and streamlines the user workflow.
3Adaptability or versatility
If data is transferred outside predetermined locations, then data accessibility is improved, but data security deteriorates without proper control mechanisms
Solution Approach 1:
The patent implements dynamic location verification through the embedded data management program, which continuously checks whether the current terminal location matches the predetermined usage location stored in the document file. This dynamic control allows data to be accessed anywhere while enforcing location-based security policies.
Solution Approach 2:
The patent incorporates a feedback mechanism where the data management program receives location information from the terminal, compares it with the predetermined location, and adjusts data access permissions accordingly. This closed-loop control ensures security is maintained even when data is transferred outside predetermined locations.
Data Source
AI summary
A document file is configured to restrict, without a costly special-purpose terminal or the like, use of document data contained therein, if the document data is taken out of a predetermined location. A document file contains (i) electronic document data, (ii) usage location information indicating one or more usage locations in which use of the electronic document data is less restricted, and (ii) a data management program that causes, when a user requests use of the electronic document data, a computer to request for user location information indicating the current location of the user. Under control of the data management program, use of the electronic document data is permitted within a first usage pattern, if the user location is included in the usage locations. If not, use of the electronic document data is prohibited or permitted within a second usage pattern which is more restricted than the first usage pattern.


