Secure Document Management Using Segmented Security Labels

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional document management systems lack stringent access control mechanisms, making it difficult for organizations to balance data sharing and collaboration with secure access management, especially when dealing with sensitive information.

Innovation Solution

A method that generates a security label for each document, including clearance and secondary security components based on user profiles, which is stored as an attribute and used to determine authorized access, ensuring that only permitted users can access or interact with sensitive data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If conventional document management systems are used to allow personnel to share data and collaborate, then ease of operation and collaboration capability are improved, but access control security and data protection capability deteriorate

Engineering Contradiction:
Improvedata sharing and collaboration capabilityVSAvoidaccess control security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The security label is segmented into multiple components including clearance level, secondary security components, and handling requirements. Each component can be independently evaluated against the user's security access profile, allowing fine-grained access control while maintaining ease of document sharing operations

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The security label acts as an intermediary mechanism between the document and the user's security access profile. The system automatically compares the security label components with the user's profile to determine authorized access, eliminating the need for manual security checks while maintaining strict access control

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If stringent access control mechanisms are implemented to protect sensitive data, then access control security is improved, but ease of operation and data sharing capability deteriorate

Engineering Contradiction:
Improveaccess control securityVSAvoiddata sharing capability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

Security labels are assigned to documents in advance during creation or import, with all necessary security components (clearance level, secondary security components, handling requirements) pre-configured. This preliminary action eliminates the need for complex real-time security negotiations during document sharing operations

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The document management system automatically performs security label comparisons with user profiles without requiring manual intervention. The system self-services the access control determination by evaluating security label components against security access profiles, maintaining both security and ease of operation

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8234693B2Secure document management
Publication Date: 2012.07.31 EVERFOX HOLDINGS LLC
  • US8234693B2 patent drawing
  • US8234693B2 patent drawing
  • US8234693B2 patent drawing

AI summary

A method for providing secure document management includes receiving a document from a user having an associated security access profile and generating a security label to be stored as an attribute of the document. The security label includes a clearance component selected from an authorized subset of clearance components that are determined based on the security access profile associated with the user, and also includes one or more secondary security components selected from an authorized subset of secondary security components that are determined based on the clearance component of the security label and the security access profile associated with the user. The method includes storing the document in a document repository storing a plurality of documents each having an associated security label, and determining whether a third-party user is authorized to access the document based on a comparison of a security access profile of the third-party user and the security label associated with the document.