IRM Server Broker for Multi-Policy Evaluation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing information rights management (IRM) systems are limited in their operational situations, as they require a single identity provider and policy evaluator, restricting flexibility and compatibility with different applications and scenarios, especially when data is transferred between applications with different user roles and policies.
Innovation Solution
An IRM server acts as a broker between authors, policy evaluators, and claim providers, allowing for multiple policy evaluators and claim providers to be used, enabling the combination of results and decoupling the identity and policy mechanisms, thus extending the operational situations of IRM systems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a single identity provider and policy evaluator are used in existing IRM systems, then the system implementation is simple, but the adaptability and versatility are limited
Solution Approach 1:
The patent segments the monolithic IRM system into independent components: multiple identity providers, multiple policy evaluators, and a broker. This segmentation allows each component to operate independently and be selected based on specific operational requirements, thereby increasing adaptability while managing complexity through modular design.
Solution Approach 2:
The broker is designed as a universal component that can work with any identity provider and policy evaluator combination. It provides a standardized interface that accommodates multiple operational situations and scenarios, making the system versatile without requiring complex custom integrations for each scenario.
2Adaptability or versatility
If multiple policy evaluators and claim providers are used, then the flexibility and compatibility are improved, but the device complexity increases
Solution Approach 1:
The broker acts as an intermediary between authors, recipients, and multiple policy evaluators/claim providers. It manages the complexity of coordinating multiple evaluators and providers by providing a unified interface and handling the coordination logic, thereby enabling flexibility without exposing the full complexity to users.
Solution Approach 2:
The patent merges the functions of multiple identity providers and policy evaluators through a single broker interface. Instead of requiring separate integration logic for each provider and evaluator, the broker combines their functionalities into a unified system that appears as a single coherent component to users.
3Adaptability or versatility
If the IRM server acts as a broker between authors and recipients, then the operational situations are extended, but the device complexity increases
Solution Approach 1:
The IRM server functioning as a broker introduces an intermediary layer between authors and recipients that manages policy evaluation and rights enforcement. This broker pattern extends operational situations by supporting multiple evaluators and providers while encapsulating the complexity within the broker itself, presenting a simplified interface to external users.
Data Source
AI summary
Information rights management (IRM) systems enable information to be protected after it has been accessed by or delivered to an authorized individual. For example, this might be to allow an email to be viewed for a limited time by specified individuals but to prevent that email from being forwarded. However, existing IRM systems are limited in the situations in which they may operate. An IRM server is provided which communicates with one or more policy evaluators which are independent of the IRM server. Results from the different policy evaluators may be combined by the IRM server and one or more identity providers may be used in conjunction with each policy evaluator. By enabling the IRM server to act as a broker between authors, recipients and policy evaluators situations in which IRM systems may operate are greatly extended.


