Offline Document Access via Pre-authorized Group Keys

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional document control systems require online connectivity to access secured documents and lack seamless integration with existing enterprise infrastructure, leading to complexities in user authentication and document permissions management.

Innovation Solution

A document control system that pre-authorizes clients for offline access using group keys, allows actions based on document permissions, and synchronizes user-group information, enabling offline document access while maintaining audit logs and supporting multiple authentication mechanisms, thus integrating with existing enterprise systems for simplified management and deployment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional document control systems require online connectivity to access secured documents, then security is maintained through server contact, but offline access capability is lost

Engineering Contradiction:
ImprovesecurityVSAvoidoffline access capability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary actions by caching cryptographic document keys and offline access information on the client before the user goes offline. This allows the client to open documents for a limited time when offline, having already received the necessary authorization and keys while online. The server pre-approves offline access and provides cached credentials in advance.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If separate software plug-ins are used for each document management system integration, then compatibility with different systems is achieved, but system complexity increases

Engineering Contradiction:
Improveintegration compatibilityVSAvoidsoftware architecture complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system implements a universal document control server that can integrate with multiple document management systems through a single architecture. The server receives document permissions information from various sources (Documentum, SharePoint, etc.) and provides unified offline access control, eliminating the need for separate plug-ins for each system while maintaining compatibility with all of them.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If document permissions information is stored centrally on the server, then access control security is maintained, but offline access to permission information is prevented

Engineering Contradiction:
Improveaccess control securityVSAvoidoffline permission verification
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary action by caching document permissions information and offline access information on the client before offline operation. The server provides the client with cached credentials, document keys, and permission data in advance, allowing the client to verify permissions offline while maintaining security through pre-approved authorization.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system uses an intermediary approach by introducing offline access information as a mediator between the central server and the client. This intermediary contains cached credentials and permission data that enable offline verification without direct server contact, while still representing the server's authorized decisions.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS7930757B2Offline access in a document control system
Publication Date: 2011.04.19 ADOBE INC
  • US7930757B2 patent drawing
  • US7930757B2 patent drawing
  • US7930757B2 patent drawing

AI summary

Systems and techniques to provide offline access in a document control system. In general, in one implementation, the technique includes: receiving a request from a client, and pre-authorizing the client, in response to the request, to allow actions by a user as a member of a group of users by sending to the client offline access information including a first key associated with the group, the first key being useable at the client to access an electronic document by decrypting a second key in the electronic document. Receiving a request can involve receiving a request from the client to take an action with respect to a second document. The technique can also include verifying the user at the client as an authenticated user, and the offline access information can include user-specific keys, group-specific keys, a policy, and a document revocation list.