Dynamic Document Access Control via Obligation Policies
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional access control methods fail to perform active control and alter access permissions based on document manipulation, leading to potential risks such as printing non-legitimate documents.
Innovation Solution
A file-access control apparatus and program that utilize a storage device, evaluation control module, and external service unit to acquire and evaluate executability data, authentication results, and user attributes, enabling active control through inhibition-type and obligation-type policies to manage document access dynamically.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If conventional access control methods are used to determine whether specific accesses can be permitted, then access control decisions can be made based on authorization data, but active control and alteration of access permissions based on document manipulation cannot be performed
Solution Approach 1:
The patent implements dynamic access control by introducing an evaluation control module that continuously monitors document manipulation events and automatically adjusts access permissions in real-time. The system transitions from static authorization checks to dynamic policy evaluation, where access rights are altered based on current document status and predefined obligation-type policies, resolving the contradiction between control flexibility and system complexity.
Solution Approach 2:
The system establishes a feedback loop where document manipulation events are captured, evaluated against obligation-type policies, and used to modify access permissions. The evaluation control module receives event data from the document application unit, processes it through policy evaluation, and feeds back control decisions to the document application unit, enabling active control while maintaining manageable system complexity through structured feedback mechanisms.
2Manufacturing precision
If detailed access control contents are described using access control policy type systems, then more detailed access control items can be specified, but the system cannot perform active control or alter access permissions in response to document manipulation
Solution Approach 1:
The patent applies preliminary action by pre-defining obligation-type policies that specify what control actions should be taken in response to specific document manipulation events. These policies are established in advance with detailed access control contents, and the evaluation control module automatically executes the appropriate pre-defined policies when triggering events occur, achieving both precise control specifications and automatic response capability.
Solution Approach 2:
The system implements self-service through automated policy evaluation and execution. The evaluation control module autonomously monitors document events, evaluates them against predefined policies, and executes control actions without requiring manual intervention. This automation maintains high precision in access control while enabling the system to actively respond to document manipulation, resolving the contradiction between control precision and automation extent.
3Ease of operation
If access control is based on static authorization data, then simple permission decisions can be made, but the system cannot respond to changing document status or perform active control
Solution Approach 1:
The patent segments the access control system into distinct functional components: an inhibition-type policy evaluation unit for basic permission denial, and an obligation-type policy evaluation unit for active control based on document events. This segmentation allows the system to maintain simple operation for basic access control while adding reliable automated responses to document status changes through the obligation-type policies, resolving the contradiction between operational simplicity and security reliability.
Data Source
AI summary
In a file-access control system according to an embodiment of this invention, control data in accordance with actions made is imparted, as an obligation-type policy, to a document file. Next, a policy evaluation control unit evaluates and executes the obligation-type policy imparted to the document file in accordance with the action to the document file. The execution of the obligation-type policy includes the controlling of a document application on the basis of an obligation fulfillment action. Therefore, an active control can be performed in accordance with any manipulation made to the document, and the access to the document can be changed.


