Document Management System with Centralized Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Electronic documents face a higher risk of unauthorized copying and data leakage compared to paper documents, as existing systems have not effectively addressed the need for secure management and protection.

Innovation Solution

A document management system comprising processing apparatuses on local networks and a management apparatus on an external network, which executes a protection process to generate and manage protected documents, utilizing encryption and metadata to control access and distribution, ensuring secure use and minimizing leakage risks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If electronic documents are managed using conventional systems, then ease of access and distribution is improved, but security against unauthorized copying and data leakage deteriorates

Engineering Contradiction:
Improveaccess and distributionVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The document is segmented into multiple encrypted fragments or blocks, each distributed to different processing apparatuses. No single apparatus holds the complete document, preventing unauthorized copying while allowing authorized users to reconstruct and access the document through controlled combination of fragments.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A management apparatus acts as an intermediary between users and processing apparatuses. It controls access requests, verifies permissions, and coordinates document reconstruction, thereby enabling secure access without exposing the complete document to any single point.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If protection processes are implemented on processing apparatuses, then security against data leakage is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Processing apparatuses automatically execute protection processes including encryption, fragmentation, and access control verification without requiring manual intervention. The system self-manages security operations, reducing operational complexity despite the sophisticated protection mechanisms in place.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The management apparatus provides universal control functions across multiple processing apparatuses, handling authentication, permission verification, and document reconstruction coordination. This centralized multi-functional approach simplifies the overall system architecture compared to implementing independent security systems at each processing node.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If status monitoring and permission control are implemented by the management apparatus, then control over document protection execution is improved, but communication overhead and system complexity increase

Engineering Contradiction:
ImprovecontrolVSAvoidcommunication complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Processing apparatuses transmit their status information to the management apparatus, which uses this feedback to make informed decisions about permission grants and protection process execution. This feedback mechanism enables controlled access without requiring constant bidirectional communication, reducing communication overhead while maintaining reliable control.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10896262B2Document management system and management apparatus
Publication Date: 2021.01.19 FUJIFILM BUSINESS INNOVATION CORP
  • US10896262B2 patent drawing
  • US10896262B2 patent drawing
  • US10896262B2 patent drawing

AI summary

A document management system includes one or more processing apparatuses and a management apparatus. Each processing apparatus is located on one of local networks, and executes a protection process to generate a protected document from a document. The management apparatus is located on an external network connected to the local networks, and manages the processing apparatus(es). Each processing apparatus includes a transmitter and a generator. The transmitter transmits a status of the processing apparatus to the management apparatus. The generator executes the protection process on an input document and generates a protected document upon being permitted by the management apparatus to execute the protection process. The management apparatus includes a receiver and a controller. The receiver receives, from the processing apparatus(es), statuses of the processing apparatus(es). The controller controls whether to permit each processing apparatus to execute the protection process on the basis of the status of the processing apparatus.