Document Management Appliance Secure Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network appliances and enterprise content management systems fail to provide secure and efficient access to and retrieval of computer files, with most NAS devices prioritizing storage space over file management and ECM systems being expensive and complex.

Innovation Solution

A network attached document management appliance with unique identifiers for secure access, database management software, and server pipe service for secure data transfer, allowing users to manage and retrieve files securely and efficiently through a browser interface with permissions and encryption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If NAS devices are used for file storage and sharing, then storage space availability is improved, but secure access and rapid retrieval of files deteriorates

Engineering Contradiction:
Improvestorage space availabilityVSAvoidsecure access
Core Design Contradiction:
Quantity of substanceVSReliability

Solution Approach 1:

The system segments file access control by implementing unique identifiers for both files and users, creating discrete access control units. Each file is associated with specific user identifiers, enabling granular permission management where access rights are assigned individually to each user-file pair rather than applying blanket access controls to entire storage systems.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces an intermediary access control mechanism that mediates between storage space and users. This intermediary layer verifies user credentials against stored file permissions before granting access, acting as a security gatekeeper that enables secure retrieval without compromising storage capacity or speed.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If ECM systems are implemented for document management, then secure and organized document storage is improved, but system complexity and cost deteriorates

Engineering Contradiction:
Improvesecure document storageVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system achieves multiple functions using a unified approach: the same unique identifier mechanism handles both security authentication and file retrieval operations. The database management system simultaneously manages permission verification, file location, and access control without requiring separate specialized subsystems, thereby reducing overall system complexity while maintaining security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system changes the parameter of access control from complex hierarchical permissions to a simplified identifier-based system. By representing access rights as discrete identifier pairs (user ID, file ID) with associated permission levels, the system maintains comprehensive security control while dramatically reducing the complexity of implementation and management compared to traditional ECM systems.

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If traditional file sharing systems are used, then storage accessibility is improved, but rapid location and retrieval of files deteriorates

Engineering Contradiction:
Improvefile accessibilityVSAvoidfile retrieval time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The system performs preliminary organization by associating each file with unique identifiers and storing metadata about file locations and access permissions in advance. When a user needs to retrieve a file, the system queries this pre-organized information structure to immediately locate the file without having to search through the entire storage system, thereby enabling rapid retrieval while maintaining ease of access.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10536459B2Document management systems and methods
Publication Date: 2020.01.14 KPTOOLS
  • US10536459B2 patent drawing
  • US10536459B2 patent drawing
  • US10536459B2 patent drawing

AI summary

A system for managing files over a network comprises a first computer hosting managed folders and files and one or more second computers. The first computer comprises database management software, server software such as server pipe software, and a first unique token. The second computer comprises a software module adapted and configured to be integrated into application software, client software such as client pipe software, and a second unique token. The computers communicate in part using the server and client software to establish a secure session for file access and transfer between the first and second computers.