Script-Embedded Electronic File Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for controlling access to electronic files, such as using passwords, are inadequate in ensuring secure access and usage once the files are sent to recipients, as recipients can freely view, manipulate, and proliferate the information.

Innovation Solution

Embedding a script in electronic files that detects a token associated with the recipient device, allowing access only if the token is present or if the device is authorized, without requiring user interaction, and optionally embedding the token into the file before sending it, with the capability to revoke access by issuing a revocation token.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional methods such as passwords are used to control access to electronic files, then the access control mechanism is simple to implement, but the security and control over the file is inadequate

Engineering Contradiction:
Improveaccess control securityVSAvoidaccess control mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent embeds the script directly into the electronic file structure, creating a nested configuration where the access control mechanism is contained within the file itself. This allows the file to carry its own authentication logic without requiring external password managers or complex centralized systems, thereby improving security while keeping the overall system relatively simple.

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The script automatically detects the presence of a token on the recipient device and enables or denies access without requiring user intervention. The system performs self-authentication by scanning for the token and making access decisions autonomously, eliminating the need for manual password entry or complex user authentication processes.

Inventive Principle:
Principle #25Self-service

2Ease of operation

If the script detects token without communicating with user, then the ease of operation is improved, but the security control is reduced

Engineering Contradiction:
Improveaccess process simplicityVSAvoidaccess control security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The script performs automatic token detection and access decision-making without requiring user interaction. The system scans for the presence of a token on the device and autonomously enables or denies file access, making the process simple for users while maintaining security through automated verification of authentication credentials.

Inventive Principle:
Principle #25Self-service

3Reliability

If the token is valid for limited period, then the security is improved through time-limited access, but the productivity is reduced due to frequent token renewal

Engineering Contradiction:
Improveaccess securityVSAvoidfile access efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements dynamic token validity periods that can be configured based on security requirements. The script checks the token's expiration status and adjusts access permissions accordingly, allowing flexible time-limited access that balances security with operational efficiency. This dynamic approach enables short validity periods for high-security scenarios while allowing longer periods for trusted users, optimizing the balance between security and productivity.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS8453258B2Protecting an electronic document by embedding an executable script
Publication Date: 2013.05.28 BANK OF AMERICA CORP
  • US8453258B2 patent drawing
  • US8453258B2 patent drawing
  • US8453258B2 patent drawing

AI summary

Embodiments of the present invention relate to methods and apparatuses for safeguarding information by, for example, controlling access to electronic files. Some embodiments of the present invention provide a method that includes embedding a script in an electronic file, where the script comprises commands that when operated on by a processor allow a recipient device to access the electronic file if either a token associated with the recipient device is detected or the recipient device is determined to be an authorized device.