Offline Document Access via Pre-authorized Group Keys
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional document control systems require online connectivity to access secured documents and lack seamless integration with existing enterprise infrastructure, leading to complexities in user authentication and document permissions management.
Innovation Solution
A document control system that pre-authorizes clients for offline access using group keys, allows actions based on document permissions, and synchronizes user-group information, enabling offline document access while maintaining audit logs and supporting multiple authentication mechanisms, thus integrating with existing enterprise systems for simplified management and deployment.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional document control systems require online connectivity to access secured documents, then security is maintained through server contact, but offline access capability is lost
Solution Approach 1:
The system performs preliminary actions by caching cryptographic document keys and offline access information on the client before the user goes offline. This allows the client to open documents for a limited time when offline, having already received the necessary authorization and keys while online. The server pre-approves offline access and provides cached credentials in advance.
2Adaptability or versatility
If separate software plug-ins are used for each document management system integration, then compatibility with different systems is achieved, but system complexity increases
Solution Approach 1:
The system implements a universal document control server that can integrate with multiple document management systems through a single architecture. The server receives document permissions information from various sources (Documentum, SharePoint, etc.) and provides unified offline access control, eliminating the need for separate plug-ins for each system while maintaining compatibility with all of them.
3Reliability
If document permissions information is stored centrally on the server, then access control security is maintained, but offline access to permission information is prevented
Solution Approach 1:
The system performs preliminary action by caching document permissions information and offline access information on the client before offline operation. The server provides the client with cached credentials, document keys, and permission data in advance, allowing the client to verify permissions offline while maintaining security through pre-approved authorization.
Solution Approach 2:
The system uses an intermediary approach by introducing offline access information as a mediator between the central server and the client. This intermediary contains cached credentials and permission data that enable offline verification without direct server contact, while still representing the server's authorized decisions.
Data Source
AI summary
Systems and techniques to provide offline access in a document control system. In general, in one implementation, the technique includes: receiving a request from a client, and pre-authorizing the client, in response to the request, to allow actions by a user as a member of a group of users by sending to the client offline access information including a first key associated with the group, the first key being useable at the client to access an electronic document by decrypting a second key in the electronic document. Receiving a request can involve receiving a request from the client to take an action with respect to a second document. The technique can also include verifying the user at the client as an authenticated user, and the offline access information can include user-specific keys, group-specific keys, a policy, and a document revocation list.


