Dynamic Access Control for Collaborative Document Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In collaborative document management between organizations, ensuring secure access control and protection of confidential information is challenging, especially when relationships sour, as existing systems lack robust mechanisms for revoking access and protecting proprietary data.
Innovation Solution
A system and method for managing collaborative documents owned by users from different organizations, where both users have full ownership rights, allowing them to control access and revoke permissions, ensuring that confidential information is protected by locking out access entirely or redacting contributions from the other party upon termination of cooperation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If collaborative document sharing is enabled between organizations, then information exchange and collaboration efficiency are improved, but security control and protection of confidential information deteriorate when relationships sour
Solution Approach 1:
The patent implements dynamic access control where ownership rights and access permissions are not static but can be changed in real-time. Multiple owners can independently modify access permissions, adding or removing users and changing their privilege levels dynamically. This allows the system to adapt security controls based on the current collaborative relationship status, resolving the contradiction between maintaining open collaboration and ensuring security control.
Solution Approach 2:
The system introduces an intermediary access control mechanism that mediates between multiple owners and potential users. The access control list (ACL) acts as an intermediary layer that enforces security policies without preventing collaboration. This intermediary structure allows the system to maintain both collaboration efficiency and security control by filtering access requests through defined permission rules.
2Ease of operation
If full access is granted to all collaborators, then collaboration smoothness is improved, but ability to revoke access and protect proprietary data deteriorates
Solution Approach 1:
The system enables dynamic modification of access permissions without disrupting ongoing collaboration. Multiple owners can independently add or remove users and change their access levels at any time. This dynamic capability allows the system to maintain smooth collaboration during active projects while simultaneously preserving the ability to revoke access when needed, resolving the contradiction between ease of operation and adaptability.
Solution Approach 2:
The system performs preliminary setup of multiple owners with full rights at the beginning of collaboration, establishing a foundation that enables both smooth operation and future access revocation. By pre-configuring the access control structure with multiple owners and defined permission levels, the system prepares the framework that allows easy collaboration now while maintaining the capability to revoke access later when relationships change.
3Adaptability or versatility
If multiple owners with full rights are implemented, then control flexibility is improved, but system complexity deteriorates
Solution Approach 1:
The patent segments ownership rights and access control into distinct, manageable units. Each owner is assigned specific full rights to the document, and access permissions are segmented into discrete user entries in an access control list. This segmentation allows multiple owners to have independent control flexibility while the system manages complexity by organizing permissions into structured, modular units that can be independently configured and modified.
Solution Approach 2:
The system implements a universal access control mechanism that handles multiple owners, multiple users, and various permission levels through a single unified framework. The access control list serves as a multi-functional structure that can manage addition of users, removal of users, privilege changes, and revocation of access all through the same interface and permission model. This universality reduces system complexity by providing a single versatile solution rather than requiring separate mechanisms for each control function.
Data Source
AI summary
Disclosed herein is a system and method for managing collaborative electronic data that is owned by two different users who belong to different organizations. Both users are also granted ownership rights of collaborative electronic data created by the users. Users then contribute to the collaborative electronic data by providing information that may be confidential to their organization. The users want to ensure that they can cut off access to the confidential information if and when the relationship between the users or organizations sours. When one of the users with ownership privileges decides to end the cooperation with the other users, that user simply revokes access to the collaborative electronic data to the other user. As a result of the revocation all users are no longer able to see or access at least a portion of the collaborative electronic data to protect confidential information of all the parties.


