Document Sharing via Information Boundary and Access Control List

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In organizational file management, there is a need to balance friction-free collaboration with information security, as file owners want to control how shared files are re-distributed, but existing solutions lack mechanisms to enforce access boundaries and control lists dynamically.

Innovation Solution

An item management application detects information boundaries and access control lists to manage sharing actions, applying rules to govern access and permissions, allowing recipients to be added to access lists for search and discovery, while enforcing boundaries on how items can be shared.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If file owners allow friction-free collaboration by allowing any second-order recipients access through shared links, then ease of operation is improved, but information security deteriorates

Engineering Contradiction:
Improveease of operationVSAvoidinformation security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements dynamic access control by allowing the document owner to configure different sharing settings (first-order vs. second-order recipient permissions) that can be adjusted based on the specific document and trust level. This dynamic configuration enables the system to adapt between friction-free collaboration and security enforcement without requiring manual approval for each sharing instance.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent applies different access control qualities to different levels of recipients. First-order recipients receive full access permissions while second-order recipients receive limited access based on configured settings. This local differentiation of access rights allows the system to provide friction-free collaboration for direct collaborators while maintaining security for indirect recipients.

Inventive Principle:
Principle #3Local quality

2Reliability

If file owners specify boundaries to control re-sharing, then information security is improved, but device complexity increases

Engineering Contradiction:
Improveinformation securityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by requiring the document owner to configure access control settings (information boundary and access control list) before sharing the document. These pre-configured boundaries automatically enforce security rules on all subsequent sharing actions, eliminating the need for manual approval of each re-sharing instance while maintaining security control.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables self-service access control where the document owner independently configures their own sharing boundaries and access control lists without requiring administrative intervention. The configured rules then automatically manage access for all recipients, reducing the need for complex centralized management while maintaining security enforcement.

Inventive Principle:
Principle #25Self-service

3Reliability

If multiple authentication processes are implemented, then information security is improved, but processing speed deteriorates

Engineering Contradiction:
Improveinformation securityVSAvoidprocessing speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements preliminary authentication by establishing the information boundary and access control list before document access. The system pre-determines which recipients have access rights, eliminating the need for multiple authentication checks during actual document access. This preliminary setup enables fast access for authorized users while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10747896B2Item sharing based on information boundary and access control list settings
Publication Date: 2020.08.18 MICROSOFT TECHNOLOGY LICENSING LLC
  • US10747896B2 patent drawing
  • US10747896B2 patent drawing
  • US10747896B2 patent drawing

AI summary

An item is shared based on an information boundary and access control settings. An application such as a document management application detects a selection of an information boundary to manage a sharing action associated with the item. The information boundary includes rules to define how the item is shared. A selection of an access control list is also detected to manage recipients who have an access to the item. The access control list allows a recipient in the list an ability to search and discover the item. In response to a detection of the sharing action to share the item, the information boundary and the access control list is applied to the item. The item is then shared based on the information boundary and the access control list through a link of the item transmitted to a recipient.