Pervasive Security System for Secured File Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security measures, such as firewalls and VPNs, are insufficient in protecting proprietary information from unauthorized access, both internally and externally, within enterprise environments, as they fail to reliably secure digital assets at all times.
Innovation Solution
A pervasive security system that employs a server module for access control management, utilizing encrypted documents with access rules and user keys, allowing only authenticated users with appropriate privileges to access secured documents, and includes a distributed architecture for scalability and reliability, enabling off-line access and dynamic reconfiguration based on user location.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional security measures (firewalls, VPNs) are deployed, then network perimeter protection is provided, but they fail to reliably protect digital assets from internal unauthorized access
Solution Approach 1:
The patent segments security protection into multiple layers: document-level encryption, user authentication, and access control lists. Each document is independently encrypted with its own key, and access is controlled through individual ACLs rather than relying solely on network perimeter security. This segmentation allows granular control over who can access specific digital assets, preventing internal unauthorized access even when network perimeter defenses are bypassed.
Solution Approach 2:
The patent applies preliminary action by encrypting documents before they are accessed or transmitted. Documents are encrypted at rest and during transmission, so that even if intercepted or accessed internally, the content remains protected. Access keys are distributed only to authorized users through secure key management systems, ensuring that encryption is already in place before any access attempt occurs.
2Loss of information
If documents are encrypted and secured, then confidentiality is maintained, but access control and user authentication become more complex
Solution Approach 1:
The patent introduces an intermediary key management system that mediates between encrypted documents and users. Instead of requiring users to directly manage complex encryption keys, the system uses key distribution centers and authentication services to automatically handle key generation, distribution, and revocation. This intermediary layer simplifies the user experience while maintaining strong encryption and access control.
Solution Approach 2:
The patent creates a universal access control framework that can be applied to multiple document types and users through standardized interfaces. The same encryption and access control mechanisms work across different platforms and document formats, reducing complexity through standardization. Access control lists and authentication protocols are designed to be platform-independent, allowing the system to handle diverse access scenarios with a unified approach.
3Ease of operation
If centralized access control is implemented, then security management is simplified, but system availability decreases when the central server is down
Solution Approach 1:
The patent implements local quality by caching access control information and encryption keys locally on user devices and local servers. Instead of requiring all access decisions to be made by a central server, each device stores relevant ACLs and keys locally, enabling it to make access decisions independently. This distributed caching approach maintains security management simplicity while ensuring system availability even when the central server is unavailable.
Solution Approach 2:
The patent introduces dynamics by allowing the system to adapt between centralized and decentralized operation modes. When the central server is available, it provides centralized key management and access control updates. When the server is unavailable, the system dynamically switches to using locally cached information for access decisions. This dynamic behavior ensures both ease of security management and continuous system availability.
4Object-affected harmful factors
If documents are encrypted for security, then protection against external threats is improved, but document transportation and sharing become more difficult
Solution Approach 1:
The patent applies parameter changes by dynamically adjusting encryption parameters based on the transmission context. Different encryption algorithms, key lengths, and protocols are selected depending on whether the document is being stored, transmitted over secure channels, or shared with external parties. This allows documents to maintain strong protection against external threats while optimizing for ease of transportation and sharing in different scenarios.
Solution Approach 2:
The patent uses preliminary action by pre-configuring encryption parameters and access control settings before document transportation. Documents are encrypted with appropriate parameters selected in advance based on the intended recipient and transmission method. This preliminary configuration ensures protection against external threats while simplifying the transportation process, as the encryption is already in place and does not require complex real-time negotiations during sharing.
Data Source
AI summary
Techniques for managing files in a designated location are disclosed. An example of the designated location is a folder, a directory, a repository, a device, or a storage place. A set of access rules is applied to a designated location such that all files in the designated location shall have substantially similar security. As a result, secured files can be easily created and managed with respect to the designated location and users with access privilege to the designated location can access most of the files, in not all, in the designated location.


