Identity Service Dynamic Key Management for Document Collaboration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current techniques do not adequately address dynamic security management in document collaboration environments, where participants have varying access rights and authentication information, leading to challenges in managing disparities and ensuring secure access to shared resources.

Innovation Solution

A method involving a document with a list of collaborators, a symmetric key, and encrypted versions for each collaborator, managed by an identity service that dynamically adds or removes collaborators, regenerates the symmetric key, and updates encrypted versions based on trust specifications and public keys, ensuring secure access and management of access rights.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If static collaborative security techniques are used, then security management is simplified, but the system cannot adapt to dynamic changes in collaborators and access rights

Engineering Contradiction:
Improveadaptability to dynamic changesVSAvoidsecurity management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic security by allowing the system to adapt to changing collaboration scenarios. The identity service dynamically manages access rights, adds or removes collaborators, and updates encrypted symmetric keys in real-time based on trust specifications and public key changes, making the security system flexible and adaptive rather than static

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The identity service acts as an intermediary between collaborators and the document security system. It mediates access control by verifying trust specifications, managing public keys, and distributing updated encrypted symmetric keys to appropriate collaborators, thereby simplifying the overall security management complexity through centralized coordination

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If dynamic security management is implemented, then access control flexibility is improved, but key management complexity increases

Engineering Contradiction:
Improveaccess control flexibilityVSAvoidkey management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The identity service serves as an intermediary that handles the complexity of dynamic key management. When collaborators are added or removed, or when public keys change, the identity service automatically regenerates the symmetric key and updates encrypted versions for all collaborators, eliminating the need for manual key management and reducing complexity despite dynamic access control requirements

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms where the identity service continuously monitors trust specifications and public key changes among collaborators. When changes are detected, the service triggers automatic symmetric key regeneration and redistribution, ensuring access control flexibility while managing key complexity through automated feedback-driven updates

Inventive Principle:
Principle #23Feedback

3Reliability

If manual security management is used, then system simplicity is maintained, but security reliability deteriorates in dynamic collaboration environments

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidoperational simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The security system performs self-service through automated key management. The identity service automatically detects changes in collaborator lists or public keys, regenerates the symmetric key, and distributes updated encrypted keys to collaborators without manual intervention. This automation maintains security reliability in dynamic environments while preserving operational simplicity for users

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system uses feedback loops where the identity service continuously monitors collaboration dynamics and trust specifications. When changes are detected, the service automatically triggers security updates and key regeneration, ensuring high security reliability while requiring minimal operational input from users, thus maintaining ease of operation

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS7467415B2Distributed dynamic security for document collaboration
Publication Date: 2008.12.16 ORACLE INT CORP
  • US7467415B2 patent drawing
  • US7467415B2 patent drawing
  • US7467415B2 patent drawing

AI summary

Techniques are provided for dynamically managing security for document collaboration. A document is associated with a list of collaborators, which can access the document. One collaborator is an identity service. The identity service is capable of dynamically encrypting versions of an access key needed by a collaborator to access the document and capable of dynamically adding or removing collaborators from the list of collaborators.