Dynamic Security Policies for File Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional security systems for protecting proprietary information on private networks are insufficient, as they rely on static security criteria that cannot be easily altered, making them vulnerable to unauthorized access from within or outside the network, especially when passwords are compromised.

Innovation Solution

Implementing a dynamic security system that uses process-driven security policies, where access restrictions to electronic files can be automatically changed as they transition through different states, allowing for flexible and robust security management by associating specific security policies with each state of a workflow.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If static security criteria are used to protect electronic files, then security management is simple to implement, but the system lacks flexibility and cannot adapt to changing security requirements

Engineering Contradiction:
Improvesecurity policy adaptabilityVSAvoidsecurity system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic security policies that automatically adjust access restrictions based on the current state of electronic files in a workflow process. Security criteria transition from static to dynamic, allowing the system to adapt security requirements as files move through different process states without requiring manual administrator intervention for each change.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The security system automatically manages security criteria transitions based on process state changes. The system self-adjusts security policies without requiring continuous administrator intervention, enabling automatic security management that reduces operational complexity while maintaining adaptability.

Inventive Principle:
Principle #25Self-service

2Productivity

If manual administrator intervention is required to change security criteria, then security control is precise, but the administrative burden increases significantly for large volumes of electronic resources

Engineering Contradiction:
Improvesecurity management efficiencyVSAvoidadministrator time consumption
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The system automatically transitions security criteria based on process state changes, eliminating the need for administrators to manually update security settings for each file. This self-service mechanism dramatically improves security management productivity while reducing the time administrators would otherwise spend on repetitive security configuration tasks.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Security policies are pre-configured for different process states, allowing the system to automatically apply appropriate security criteria when files transition between states. This preliminary configuration approach enables efficient security management at scale without requiring real-time administrator intervention.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If passwords are used for access control, then implementation is simple, but security is compromised when passwords are leaked or detected

Engineering Contradiction:
Improveaccess control reliabilityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the security criteria from static password-based authentication and integrates it into the process workflow state management. Security control is separated from traditional authentication mechanisms and embedded within the business process states, improving reliability by tying access control to process context rather than vulnerable password systems.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The process state acts as an intermediary between users and electronic files, mediating access control decisions based on the current state rather than relying solely on password authentication. This intermediary mechanism enhances security reliability by adding contextual control layers beyond simple password verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS7703140B2Method and system for securing digital assets using process-driven security policies
Publication Date: 2010.04.20 INTELLECTUAL VENTURES I LLC
  • US7703140B2 patent drawing
  • US7703140B2 patent drawing
  • US7703140B2 patent drawing

AI summary

Techniques for dynamically altering security criteria used in a file security system are disclosed. The security criteria pertains to keys (or ciphers) used by the file security system to encrypt electronic files to be secured or to decrypt electronic files already secured. The security criteria can, among other things, include keys that are required to gain access to electronic files. Here, the keys can be changed automatically as electronic files transition between different states of a process-driven security policy. The dynamic alteration of security criteria enhances the flexibility and robustness of the security system. In other words, access restrictions on electronic files can be dependent on the state of the process-driven security policy.