Secure Document Access via Link Value and Augmented Reality

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for managing paper documents with sensitive information lack a simple and automated way to restrict access, making it inconvenient to distribute such documents while maintaining security.

Innovation Solution

A computer-implemented method and system that detects missing sensitive data in a current document version, generates a link value, retrieves metadata, and only provides access if the user agrees and meets access rules, using a secure storage unit and augmented reality for rendering.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If redaction is applied to paper documents, then access to sensitive information is restricted, but the document cannot be freely distributed and recovery of sensitive information is difficult

Engineering Contradiction:
Improveaccess controlVSAvoiddocument distribution
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The document is segmented into two parts: a public version with redacted sensitive information that can be freely distributed, and a private version with complete information stored in a secure storage unit. The public version includes placeholders or indicators that trigger retrieval of sensitive data from the secure storage when needed, allowing both free distribution and controlled access.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A secure storage unit acts as an intermediary between the public document and the sensitive information. This intermediary component stores the complete sensitive data separately and provides it to authorized users through controlled retrieval mechanisms, enabling the document to be distributed publicly while maintaining secure access to sensitive information.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If redaction is applied to paper documents, then sensitive information is masked, but automated recovery of sensitive information is not possible

Engineering Contradiction:
Improveinformation securityVSAvoiddata recovery
Core Design Contradiction:
ReliabilityVSExtent of automation

Solution Approach 1:

The system creates a copy of the complete document (including sensitive information) and stores it in the secure storage unit. This copy serves as an automated source that can be retrieved and processed without manual intervention, enabling automated recovery of sensitive information while maintaining security through controlled access to the stored copy.

Inventive Principle:
Principle #26Copying

3Reliability

If access control is implemented in paper documents, then sensitive data is protected, but the system complexity increases

Engineering Contradiction:
Improveaccess controlVSAvoidsystem structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The access control mechanism is extracted from the physical document itself and placed in a separate secure storage unit. The paper document remains simple with only redacted content and triggers, while the complex authentication and access control logic is contained in the secure storage system, separating the simple public document from the complex security infrastructure.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10956590B2Methods for securely managing a paper document
Publication Date: 2021.03.23 THALES DIS CPL USA INC
  • US10956590B2 patent drawing
  • US10956590B2 patent drawing
  • US10956590B2 patent drawing

AI summary

A method for securely accessing a document containing a set of data comprises (a) detecting the existence of target data belonging to an enhanced version of the document and missing from the current version of the document, (b) generating a link value allocated to the target data by applying a preset function to a subset of said set of data, (c) retrieving metadata from a secure storage unit by using the link value and, using a message based on said metadata, proposing to the user to get the target data, (d) getting both agreement of the user and credentials of the user, (e) generating a request by using the link value and said credentials for retrieving the target data from the secure storage unit, (f) providing the user with the target data only if the secure storage unit successfully checked the compliance of the request with preset access rules.