Encrypted Document Distribution with FSM-Based Section Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems lack effective methods for securely managing the distribution and access control of confidential documents across a network of geographically dispersed nodes, ensuring only authorized users can interact with document sections according to predefined access rights and workflow sequences.

Innovation Solution

A method utilizing a finite state machine (FSM) executable software code and asymmetric cryptography to manage document distribution and access, where each node processes encrypted documents based on control data, including access control lists and user rights maps, ensuring secure and controlled interaction with document sections.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If asymmetric cryptography is used to encrypt documents for distribution across a network, then document security and access control are improved, but system complexity and computational overhead increase

Engineering Contradiction:
Improvedocument securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-distributing public keys to all nodes in the network before document distribution begins. Each node stores a registry of public keys corresponding to other nodes, allowing immediate encryption without key exchange delays. This pre-prepared infrastructure reduces the computational overhead during actual document distribution while maintaining strong asymmetric cryptography-based security.

Inventive Principle:
Principle #10Preliminary action

2Manufacturing precision

If fine-grained access control lists and rights maps are implemented for each document section, then access control precision is improved, but processing time and computational resources increase

Engineering Contradiction:
Improveaccess control precisionVSAvoidprocessing time
Core Design Contradiction:
Manufacturing precisionVSLoss of time

Solution Approach 1:

The patent segments documents into distinct sections with individual access control lists and rights maps. Each section can be independently encrypted and accessed based on specific user permissions. This segmentation allows the system to apply fine-grained access control only where necessary rather than processing entire documents, reducing overall processing time while maintaining high precision control over sensitive sections.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by applying different access control policies to different sections of the same document. Each section can have its own ACL and rights map tailored to specific security requirements. This allows highly restrictive control for sensitive sections while permitting broader access for less sensitive sections, optimizing processing efficiency while maintaining precise access control where needed.

Inventive Principle:
Principle #3Local quality

3Reliability

If finite state machine code is embedded in documents to track workflow states and authorized user sequences, then workflow control and compliance tracking are improved, but document processing complexity increases

Engineering Contradiction:
Improveworkflow controlVSAvoiddocument processing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies self-service by embedding finite state machine (FSM) code directly within document structures. The FSM automatically tracks workflow states, determines authorized next users, and enforces compliance rules without requiring external system intervention. The document itself executes the logic for state transitions and access control, reducing the need for complex external workflow management infrastructure while improving reliability through self-contained validation.

Inventive Principle:
Principle #25Self-service

4Productivity

If documents are distributed to multiple geographically dispersed nodes simultaneously, then collaboration efficiency is improved, but network bandwidth consumption and synchronization overhead increase

Engineering Contradiction:
Improvecollaboration efficiencyVSAvoidnetwork bandwidth consumption
Core Design Contradiction:
ProductivityVSLoss of energy

Solution Approach 1:

The patent implements local quality by allowing each node to store and process only the document sections and metadata relevant to its local users and context. Rather than replicating entire documents across all nodes, each node maintains a customized local copy with only the necessary portions encrypted for its authorized users. This reduces network bandwidth consumption during distribution while maintaining collaboration efficiency by enabling local access and processing.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12361147B2Systems and methods for managing document content access via security over a network of nodes
Publication Date: 2025.07.15 ICON CLINICAL RESEARCH LTD
  • US12361147B2 patent drawing
  • US12361147B2 patent drawing
  • US12361147B2 patent drawing

AI summary

A method of managing distribution of a document and access to its contents with security in a network having nodes is described. The nodes may have digital processors for remote communication over a wide area network and local data stores. The exemplary method includes a node sending a document in encrypted format and including a payload, and control data including destination data, access control data, and signature data, and a document destination list. The sending node may only send the document to nodes on the destination list. A node may receive the document, decrypt at least some of the document, and process the document according to the control data by extracting the control data and managing document payload access and document storage and user access according to the control data.