Content Repository Filtering for Fine-Grained Document Sharing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing document sharing technologies lack dynamic access control based on business rules, leading to loss of control over document usage and potential security issues, especially with sensitive information, and do not provide fine-grained access rights management.
Innovation Solution
A system with a content management unit that receives and injects content restriction rules into policy rules, intercepts API calls, and uses a filtering unit to dynamically filter content based on these rules, rendering filtered content through a graphical user interface, allowing for fine-grained access control and secure sharing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If conventional document sharing approaches are used, then document exchange is simple and easy, but loss of control over document usage and security issues arise
Solution Approach 1:
The patent introduces a content management repository as an intermediary system between document creators and recipients. This intermediary enables secure sharing by intercepting document access requests, evaluating user permissions against predefined policies, and delivering only authorized content portions. The repository mediates between the simplicity of document exchange and the need for security control, resolving the contradiction by adding a layered security infrastructure that operates transparently to users.
Solution Approach 2:
The patent applies segmentation by dividing documents into distinct content portions (e.g., pages, sections, paragraphs) and assigning different access rights to different segments. This allows fine-grained control where users can access specific portions of documents based on their roles and permissions. The segmentation mechanism resolves the contradiction by enabling selective disclosure - maintaining ease of operation for authorized users while ensuring security through granular access control.
2Device complexity
If simple file-level access restrictions are implemented, then access control is easy to manage, but fine-grained access rights based on business rules cannot be achieved
Solution Approach 1:
The patent implements dynamics by enabling access control policies to change adaptively based on user attributes, document metadata, and business rules. Rather than static file-level permissions, the system dynamically evaluates access requests against configurable policies that can respond to various conditions (e.g., user role, document type, time sensitivity). This dynamic approach resolves the contradiction by providing versatile, rule-based access control while maintaining manageable complexity through automated policy enforcement.
Solution Approach 2:
The patent utilizes parameter changes by allowing access control parameters to be configured and modified based on business requirements. Administrators can define policies using configurable parameters such as user groups, document categories, and access conditions. The system changes access parameters dynamically based on these configurations, enabling fine-grained control without requiring complex manual permission management for each individual case.
3Ease of operation
If users with higher access levels can see all content, then ease of operation is maintained, but security issues arise when sensitive information should be restricted
Solution Approach 1:
The patent applies local quality by assigning different visibility and access characteristics to different portions of content based on their sensitivity and user permissions. Instead of uniform access control, the system evaluates each content segment individually and applies appropriate quality attributes (visibility, accessibility, modifiability) based on user roles and document policies. This resolves the contradiction by ensuring that sensitive information remains restricted while maintaining ease of operation for authorized users who can access appropriate content without technical barriers.
Data Source
AI summary
A system for secure sharing of documents via a content management repository is provided. The system includes a content management unit, a filtering unit, a graphical user interface, and a memory communicatively coupled to the content management unit. The content management unit is configured to receive content restriction rules for content stored in the content management repository. The content management unit is further configured to inject the content restriction rules into policy rules. The content management unit is configured to intercept an Application Programming Interface call for the content from a user. The filtering unit is configured to dynamically filter the content based on the content restriction rules. The graphical user interface is configured to render the filtered content to display the filtered content to the user.


