Policy-Based Document Encryption and Key Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current document management systems face challenges in providing comprehensive access control and full-time protection for documents, especially when they are in motion or across heterogeneous operating environments, as existing encryption techniques are computationally expensive and lack efficient key management, and application-specific solutions are not portable or transparent.

Innovation Solution

A policy-based system that uses shared key rings and domain keys to encrypt and decrypt documents automatically, allowing seamless sharing and protection across different domains and operating systems, with a policy enforcer managing encryption keys and controlling access without user intervention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encryption is applied to protect documents at rest and in motion, then document security is improved, but computational expense and key management complexity increase

Engineering Contradiction:
Improvedocument securityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a policy enforcer as an intermediary component that manages encryption keys and controls document access. The policy enforcer acts as a mediator between the document management system and encryption mechanisms, automatically handling key distribution, rotation, and access decisions based on policies, thereby reducing key management complexity while maintaining strong encryption protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements automated encryption and decryption processes that operate without manual user intervention. The policy enforcer automatically applies encryption to documents at rest, manages key lifecycle operations, and handles decryption when access is authorized, making the security mechanism self-managing and reducing operational burden.

Inventive Principle:
Principle #25Self-service

2Reliability

If document management systems provide access control, then access security is improved, but protection ceases when documents are checked out or copied

Engineering Contradiction:
Improveaccess securityVSAvoidprotection duration
Core Design Contradiction:
ReliabilityVSDuration of action of stationary object

Solution Approach 1:

The patent applies encryption to documents before they are checked out or copied, ensuring protection is established in advance. The policy enforcer pre-encrypts documents at rest and maintains encryption during transmission, so that protection continues seamlessly throughout the document lifecycle regardless of location or access state.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The encryption mechanism is designed to work universally across different document states and locations. The same policy enforcer and encryption framework protect documents whether they are at rest in the repository, in motion during transmission, or accessed locally by users, providing continuous protection across the entire document lifecycle.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If file system encryption is used, then documents are protected at rest, but files become unprotected when copied to non-encrypted file systems

Engineering Contradiction:
Improvedata protection at restVSAvoidportability across file systems
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements encryption at the document level rather than the file system level, allowing encrypted documents to be copied to different file systems while maintaining protection. The encryption is embedded with the document content and managed by the policy enforcer, so copied documents retain their encryption and security policies regardless of the destination file system.

Inventive Principle:
Principle #26Copying

4Reliability

If application-specific encryption is implemented, then document protection is provided, but the solution lacks portability and requires application-specific implementations

Engineering Contradiction:
Improvedocument protectionVSAvoidportability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements a universal policy enforcer and encryption framework that operates independently of specific applications or file systems. The same core components can protect documents across different platforms, applications, and storage locations, providing portable and consistent security without requiring application-specific encryption implementations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11057355B2Protecting documents using policies and encryption
Publication Date: 2021.07.06 NEXTLABS INC
  • US11057355B2 patent drawing
  • US11057355B2 patent drawing
  • US11057355B2 patent drawing

AI summary

A system protects documents at rest and in motion using declarative policies and encryption. A document at rest includes documents on a device such as the hard drive of a computer. A document in motion is a document that is passing through a policy enforcement point. The policy enforcement point can be a server (e.g., mail server, instant messenger server, file server, or network connection server).