Multi-User Document Management with Rights-Based Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current document management tools lack the necessary security and efficiency for managing composite documents in a shared multi-user environment, failing to adequately control access and validation across different users and workstations.

Innovation Solution

A computer system with a document data processing tool, a document data display manager, and a user rights manager, utilizing an object model with access and validation methods, allowing secure access and validation based on user rights, and enabling collaborative document management through a tree diagram interface with tabbed display/input zones, where access and validation status are dynamically managed.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If current document management tools are used for multi-user composite document management, then basic document access is enabled, but security and control over access and validation are insufficient

Engineering Contradiction:
Improvedocument securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments document management into distinct functional components: a processing tool for document creation and maintenance, a display manager for presentation and interaction, and a rights manager for security control. Each component handles specific aspects of document management, allowing complex security requirements to be addressed through modular, specialized modules rather than a monolithic system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The rights manager acts as an intermediary between users and the document management system, mediating all access and validation operations. It enforces security policies by determining whether users can access specific zones or validate document portions, providing centralized security control without requiring complex security logic throughout the entire system.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If multi-user access to composite documents is enabled, then collaborative work is improved, but control over user access rights and validation rights becomes difficult

Engineering Contradiction:
Improvecollaborative work efficiencyVSAvoidaccess control management
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The patent applies local quality by assigning different access rights and validation rights to different users for different zones within a composite document. The rights manager evaluates user credentials against zone-specific security policies, allowing fine-grained control where each document zone can have its own access requirements independent of other zones.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The rights manager provides universal security control across all users and all document zones through a single centralized component. It handles both access rights determination and validation rights determination, as well as signature authorization, making it a multi-functional security gateway that simplifies operation by providing consistent security management throughout the system.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Stability of the object's composition

If validation rights are restricted based on user roles, then document integrity is improved, but user flexibility in document modification is reduced

Engineering Contradiction:
Improvedocument integrityVSAvoiduser flexibility
Core Design Contradiction:
Stability of the object's compositionVSAdaptability or versatility

Solution Approach 1:

The system implements dynamic validation control where the rights manager evaluates user credentials, document zone properties, and security policies in real-time to determine validation rights. This allows the system to adaptively grant or deny validation permissions based on the specific context of each user-zone interaction, rather than applying static, one-size-fits-all restrictions.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameter of validation control from a binary restricted/unrestricted model to a multi-dimensional evaluation based on user credentials, zone security levels, and document state. The rights manager adjusts validation permissions dynamically by evaluating multiple parameters simultaneously, allowing document integrity to be maintained while preserving user flexibility where appropriate.

Inventive Principle:
Principle #35Parameter changes

4Reliability

If hierarchical validation with level indicators is implemented, then document validation control is improved, but system complexity increases

Engineering Contradiction:
Improvevalidation controlVSAvoidvalidation mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The validation mechanism is segmented into hierarchical levels with level indicators assigned to different document zones. Each zone can have its own validation requirements and status tracking, allowing complex validation control to be broken down into manageable, independent level-based units that are evaluated separately by the rights manager.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS7814049B2Computer device for managing documents in multi-user mode
Publication Date: 2010.10.12 TRACE ONE
  • US7814049B2 patent drawing
  • US7814049B2 patent drawing
  • US7814049B2 patent drawing

AI summary

A computer device for managing Documents in multi-user mode, including a document data processing tool, a document data display manager, and a document user rights manager.