Pervasive Security System for Secured File Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security measures, such as firewalls and VPNs, are insufficient in protecting proprietary information from unauthorized access, both internally and externally, within enterprise environments, as they fail to reliably secure digital assets at all times.

Innovation Solution

A pervasive security system that employs a server module for access control management, utilizing encrypted documents with access rules and user keys, allowing only authenticated users with appropriate privileges to access secured documents, and includes a distributed architecture for scalability and reliability, enabling off-line access and dynamic reconfiguration based on user location.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security measures (firewalls, VPNs) are deployed, then network perimeter protection is provided, but they fail to reliably protect digital assets from internal unauthorized access

Engineering Contradiction:
Improvesecurity protection reliabilityVSAvoidinternal unauthorized access
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments security protection into multiple layers: document-level encryption, user authentication, and access control lists. Each document is independently encrypted with its own key, and access is controlled through individual ACLs rather than relying solely on network perimeter security. This segmentation allows granular control over who can access specific digital assets, preventing internal unauthorized access even when network perimeter defenses are bypassed.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies preliminary action by encrypting documents before they are accessed or transmitted. Documents are encrypted at rest and during transmission, so that even if intercepted or accessed internally, the content remains protected. Access keys are distributed only to authorized users through secure key management systems, ensuring that encryption is already in place before any access attempt occurs.

Inventive Principle:
Principle #10Preliminary action

2Loss of information

If documents are encrypted and secured, then confidentiality is maintained, but access control and user authentication become more complex

Engineering Contradiction:
Improveinformation confidentialityVSAvoidaccess control system complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary key management system that mediates between encrypted documents and users. Instead of requiring users to directly manage complex encryption keys, the system uses key distribution centers and authentication services to automatically handle key generation, distribution, and revocation. This intermediary layer simplifies the user experience while maintaining strong encryption and access control.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a universal access control framework that can be applied to multiple document types and users through standardized interfaces. The same encryption and access control mechanisms work across different platforms and document formats, reducing complexity through standardization. Access control lists and authentication protocols are designed to be platform-independent, allowing the system to handle diverse access scenarios with a unified approach.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If centralized access control is implemented, then security management is simplified, but system availability decreases when the central server is down

Engineering Contradiction:
Improvesecurity management easeVSAvoidsystem availability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements local quality by caching access control information and encryption keys locally on user devices and local servers. Instead of requiring all access decisions to be made by a central server, each device stores relevant ACLs and keys locally, enabling it to make access decisions independently. This distributed caching approach maintains security management simplicity while ensuring system availability even when the central server is unavailable.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent introduces dynamics by allowing the system to adapt between centralized and decentralized operation modes. When the central server is available, it provides centralized key management and access control updates. When the server is unavailable, the system dynamically switches to using locally cached information for access decisions. This dynamic behavior ensures both ease of security management and continuous system availability.

Inventive Principle:
Principle #15Dynamics

4Object-affected harmful factors

If documents are encrypted for security, then protection against external threats is improved, but document transportation and sharing become more difficult

Engineering Contradiction:
Improveexternal threat protectionVSAvoiddocument transportation ease
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The patent applies parameter changes by dynamically adjusting encryption parameters based on the transmission context. Different encryption algorithms, key lengths, and protocols are selected depending on whether the document is being stored, transmitted over secure channels, or shared with external parties. This allows documents to maintain strong protection against external threats while optimizing for ease of transportation and sharing in different scenarios.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent uses preliminary action by pre-configuring encryption parameters and access control settings before document transportation. Documents are encrypted with appropriate parameters selected in advance based on the intended recipient and transmission method. This preliminary configuration ensures protection against external threats while simplifying the transportation process, as the encryption is already in place and does not require complex real-time negotiations during sharing.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS7729995B1Managing secured files in designated locations
Publication Date: 2010.06.01 INTELLECTUAL VENTURES I LLC
  • US7729995B1 patent drawing
  • US7729995B1 patent drawing
  • US7729995B1 patent drawing

AI summary

Techniques for managing files in a designated location are disclosed. An example of the designated location is a folder, a directory, a repository, a device, or a storage place. A set of access rules is applied to a designated location such that all files in the designated location shall have substantially similar security. As a result, secured files can be easily created and managed with respect to the designated location and users with access privilege to the designated location can access most of the files, in not all, in the designated location.