Document Sharing via Information Boundary and Access Control List
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In organizational file management, there is a need to balance friction-free collaboration with information security, as file owners want to control how shared files are re-distributed, but existing solutions lack mechanisms to enforce access boundaries and control lists dynamically.
Innovation Solution
An item management application detects information boundaries and access control lists to manage sharing actions, applying rules to govern access and permissions, allowing recipients to be added to access lists for search and discovery, while enforcing boundaries on how items can be shared.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If file owners allow friction-free collaboration by allowing any second-order recipients access through shared links, then ease of operation is improved, but information security deteriorates
Solution Approach 1:
The patent implements dynamic access control by allowing the document owner to configure different sharing settings (first-order vs. second-order recipient permissions) that can be adjusted based on the specific document and trust level. This dynamic configuration enables the system to adapt between friction-free collaboration and security enforcement without requiring manual approval for each sharing instance.
Solution Approach 2:
The patent applies different access control qualities to different levels of recipients. First-order recipients receive full access permissions while second-order recipients receive limited access based on configured settings. This local differentiation of access rights allows the system to provide friction-free collaboration for direct collaborators while maintaining security for indirect recipients.
2Reliability
If file owners specify boundaries to control re-sharing, then information security is improved, but device complexity increases
Solution Approach 1:
The patent implements preliminary action by requiring the document owner to configure access control settings (information boundary and access control list) before sharing the document. These pre-configured boundaries automatically enforce security rules on all subsequent sharing actions, eliminating the need for manual approval of each re-sharing instance while maintaining security control.
Solution Approach 2:
The system enables self-service access control where the document owner independently configures their own sharing boundaries and access control lists without requiring administrative intervention. The configured rules then automatically manage access for all recipients, reducing the need for complex centralized management while maintaining security enforcement.
3Reliability
If multiple authentication processes are implemented, then information security is improved, but processing speed deteriorates
Solution Approach 1:
The patent implements preliminary authentication by establishing the information boundary and access control list before document access. The system pre-determines which recipients have access rights, eliminating the need for multiple authentication checks during actual document access. This preliminary setup enables fast access for authorized users while maintaining security.
Data Source
AI summary
An item is shared based on an information boundary and access control settings. An application such as a document management application detects a selection of an information boundary to manage a sharing action associated with the item. The information boundary includes rules to define how the item is shared. A selection of an access control list is also detected to manage recipients who have an access to the item. The access control list allows a recipient in the list an ability to search and discover the item. In response to a detection of the sharing action to share the item, the information boundary and the access control list is applied to the item. The item is then shared based on the information boundary and the access control list through a link of the item transmitted to a recipient.


