Digital Document Security via Identifier Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for securing digital documents either render them entirely unusable through encryption or fail to provide a simple, automated way to restrict access to sensitive information, making it difficult to manage different security levels for various types of data within a document.

Innovation Solution

A computer-implemented method that allocates identifiers to sensitive data within a digital document, storing these identifiers in a secure storage unit with access rules, allowing the document to be updated with these identifiers instead of the sensitive data, enabling secure, selective access based on user profiles, devices, and locations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encryption is applied to secure digital documents, then access to sensitive information is restricted, but the document becomes entirely unusable without the encryption key

Engineering Contradiction:
ImprovesecurityVSAvoidusability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments the document into two types of data: sensitive data (second type) that requires security restrictions, and non-sensitive data (first type) that can be freely accessed. This segmentation allows the document to maintain usability for general information while securing only the sensitive portions through identifiers and access rules stored in a secure storage unit.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary mechanism using identifiers (display values and link values) that mediate between the sensitive data and the user. Instead of directly encrypting the entire document, the system uses these identifiers as intermediaries to control access to sensitive data through the secure storage unit, while allowing non-sensitive data to be accessed directly.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If redaction is applied to secure digital documents, then access to sensitive information is restricted, but there is no simple or automated means to recover the sensitive information

Engineering Contradiction:
ImprovesecurityVSAvoidautomation
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent applies preliminary action by automatically identifying and classifying data into first and second types before the document is distributed. The system pre-processes the document to replace sensitive data with identifiers and stores access rules in advance, enabling automated security management without requiring manual redaction or recovery operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements self-service through automated data classification and identifier generation. The secure storage unit automatically manages access requests based on predefined rules, eliminating the need for manual intervention in security operations and enabling the system to securely manage sensitive information autonomously.

Inventive Principle:
Principle #25Self-service

3Reliability

If encryption keys are used to secure digital documents, then access to sensitive information is restricted, but significant controls over the key distribution and control are required

Engineering Contradiction:
ImprovesecurityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the sensitive data from the document and replaces it with identifiers that point to a secure storage unit. This extraction eliminates the need for complex key management systems, as the secure storage unit centrally manages access control without requiring distribution and control of encryption keys across multiple systems.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The secure storage unit serves multiple functions: storing sensitive data, managing access rules, controlling authentication, and providing centralized security management. This multi-functional approach replaces the need for separate key management systems, reducing overall system complexity while maintaining strong security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Ease of operation

If the document is made freely distributable, then ease of sharing is improved, but access to sensitive information cannot be restricted

Engineering Contradiction:
ImprovesharingVSAvoidaccess control
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies local quality by implementing different access controls for different parts of the document. Non-sensitive data (first type) is freely shareable and accessible to anyone, while sensitive data (second type) has restricted access controlled by the secure storage unit. This allows the document to be freely distributed while maintaining selective access control where needed.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10970408B2Method for securing a digital document
Publication Date: 2021.04.06 THALES DIS CPL USA INC
  • US10970408B2 patent drawing
  • US10970408B2 patent drawing

AI summary

A method for securing a digital document comprising first and second types of data, where a set of data of the second type is previously identified in an initial version of the document. For each data of the second type, an identifier is allocated to the data and an entry comprising the data is stored in a secure storage unit. The identifier comprises a display value and a link value. The data is reachable in the secure storage unit through the link value. The secure storage unit is configured to use access rules for authorizing or denying a request initiated by a user for accessing data of the second type contained in an entry of the secure storage unit. An updated version of the digital document is generated by replacing each data of the second type by its allocated identifier in the initial version of the digital document.