Dynamic Resharing Policy for Secure File Distribution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing file resharing in online systems is complicated due to the difficulty in balancing user-friendly and secure policies, especially when authorized users need to reshare files within organizations, as existing solutions lack adequate measures to ensure that shared files are not redistributed to unauthorized users.

Innovation Solution

An online file sharing system that allows users to reshare files only to the extent permitted by a resharing policy, which can be based on attributes such as the initiator, receiver, author, or shared file, with centralized management and control by administrators to ensure secure and user-friendly distribution.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If authorized users are permitted to reshare files freely, then ease of operation is improved, but security deteriorates as files may be redistributed to unauthorized users

Engineering Contradiction:
Improvefile resharing capabilityVSAvoidfile access security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system implements dynamic resharing policies that adapt based on file attributes, user roles, and organizational hierarchy. Administrators can configure different resharing permissions for different file types, users, and contexts, allowing the system to flexibly balance accessibility and security requirements rather than using static universal permissions

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system introduces an intermediary policy enforcement mechanism that mediates between users wanting to reshare files and security requirements. The server evaluates resharing requests against configured policies involving file attributes, user characteristics, and organizational structure before permitting or blocking reshare actions

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If strict resharing policies are enforced to ensure security, then reliability is improved, but ease of operation deteriorates due to limitations on file distribution

Engineering Contradiction:
Improvefile access securityVSAvoidfile resharing capability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system segments resharing permissions into granular categories based on file attributes (type, sensitivity), user attributes (role, department, clearance level), and organizational hierarchy. This segmentation allows precise control where different permission levels are assigned to different segments of users and files, avoiding overly restrictive blanket policies

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The policy enforcement mechanism serves multiple functions simultaneously: it enforces security constraints, enables legitimate resharing operations, provides audit capabilities, and adapts to different organizational structures. This multi-functionality allows a single system to handle diverse security requirements without requiring separate mechanisms for each scenario

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If multiple copies of files are maintained for sharing, then productivity is improved through concurrent access, but device complexity increases due to copy management overhead

Engineering Contradiction:
Improvefile access efficiencyVSAvoidfile copy management
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system creates controlled copies of files for sharing purposes while maintaining centralized policy enforcement. Instead of managing complex distributed file systems, the server generates appropriate copies with embedded access controls and permissions, allowing concurrent access without requiring sophisticated replication management infrastructure

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system implements feedback mechanisms that track file access, resharing actions, and policy violations. This feedback enables administrators to monitor and adjust policies based on actual usage patterns, optimizing the balance between maintaining file copies for productivity and managing the complexity of copy distribution

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11516251B2File resharing management
Publication Date: 2022.11.29 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11516251B2 patent drawing
  • US11516251B2 patent drawing
  • US11516251B2 patent drawing

AI summary

Managing file distribution in an online file sharing system implemented by at least one server includes inviting a first entity to access a shared file hosted by the online file sharing system, and allowing the first entity to reshare the shared the through the online file sharing system with at least a second entity only to an extent permitted by a resharing policy stored by the online file sharing system.