Encrypted Document Versioning via PDRL Policy Nesting

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current electronic document management systems lack effective mechanisms for versioning and controlling access to modifiable encrypted documents, particularly in managing access rights, archiving, and ensuring secure revocation and shredding of documents.

Innovation Solution

The implementation of a system that uses a document control policy, represented in Portable Document Rights Language (PDRL) expressed in XML, to manage versioning of encrypted documents, with features for tracking document history, archiving, and secure key management, including reversible revocation and irreversible shredding of access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If document control policies are applied to encrypted documents, then access control is improved, but system complexity increases

Engineering Contradiction:
Improveaccess controlVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements nested document control policies where policies are organized in a hierarchical structure with parent-child relationships. Each policy can reference other policies, creating a nested arrangement that allows complex access control rules to be organized in manageable layers. This nesting approach enables the system to handle sophisticated access control requirements while maintaining organizational structure and reducing overall system complexity through systematic arrangement.

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The patent segments document control policies into distinct, independent policy objects that can be individually managed. Each policy is a separate entity with its own set of rules, allowing the system to break down complex access control into manageable segments. This segmentation enables independent modification, deletion, and activation of specific policies without affecting the entire system, thereby reducing operational complexity while maintaining robust access control.

Inventive Principle:
Principle #1Segmentation

2Loss of information

If versioning is implemented for encrypted documents, then document history tracking is improved, but storage requirements increase

Engineering Contradiction:
Improvedocument history trackingVSAvoidstorage requirements
Core Design Contradiction:
Loss of informationVSQuantity of substance

Solution Approach 1:

The patent applies local quality by differentiating between document content storage and metadata storage. Version information, such as timestamps, user identifiers, and change summaries, is stored as lightweight metadata rather than full document copies. This approach preserves complete document history tracking while significantly reducing storage requirements, as only the essential versioning metadata is retained rather than redundant full document content.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent uses selective copying for version management, where only the changes and metadata associated with each version are copied and stored, rather than creating complete copies of the entire document. This selective copying approach maintains comprehensive version history while minimizing storage consumption by copying only the necessary versioning information rather than duplicate full document content.

Inventive Principle:
Principle #26Copying

3Adaptability or versatility

If reversible revocation is implemented, then access control flexibility is improved, but security risk increases

Engineering Contradiction:
Improveaccess control flexibilityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements dynamic access control through reversible revocation mechanisms that allow access rights to be changed from granted to revoked and back. This dynamic flexibility enables the system to adapt to changing organizational needs and user requirements. The reversibility feature allows administrators to restore access to documents or users when circumstances change, providing operational flexibility while maintaining security through controlled, audited transitions in access rights.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent incorporates feedback mechanisms in the revocation process, where the system tracks and records all revocation and restoration actions. This feedback loop allows the system to monitor access control changes, provide audit trails for accountability, and enable selective revocation based on recorded conditions. The feedback mechanism ensures that reversible revocation is used responsibly by maintaining awareness of all access control changes and their implications for security.

Inventive Principle:
Principle #23Feedback

4Object-affected harmful factors

If shredding access is implemented, then security is improved, but operational complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidoperational complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent extracts the shredding function as a separate, dedicated operation from normal access control. The shredding mechanism independently handles the destruction of access rights and associated metadata, separating this security-critical function from routine access management. This extraction allows the system to implement thorough shredding of document access and related data while maintaining simpler operational workflows for normal access control operations, as shredding is handled as a distinct process with its own procedures and audit mechanisms.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS8656159B1Versioning of modifiable encrypted documents
Publication Date: 2014.02.18 ADOBE INC
  • US8656159B1 patent drawing
  • US8656159B1 patent drawing
  • US8656159B1 patent drawing

AI summary

In some embodiments, a method includes receiving a modifiable electronic document. The method includes generating a new version of the modifiable electronic document. The method also includes encrypting the new version of the modifiable electronic document using an encryption key that is used to encrypt the modifiable electronic document and different versions of the modifiable electronic document. The method includes saving the new version of the modifiable electronic document.