Secure Document Sharing via Server-Mediated Browser Rendering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing document sharing methods often fail to enforce security restrictions once documents are shared, allowing unauthorized copying, printing, or dissemination, which can violate compliance rules and compromise data security.
Innovation Solution
A platform-independent document representation is generated, which includes security restrictions that can be enforced by a server and client-side code, ensuring that documents are shared with compliance rules in place, such as restrictions on copying or printing, and can be accessed only by compliant devices within specified geographic locations or networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If documents are shared using email or file transfer services, then document accessibility is improved, but security restriction enforcement deteriorates
Solution Approach 1:
A server acts as an intermediary between the document sharer and the document recipient. The server hosts the document and enforces security restrictions (copying, printing, etc.) before allowing access, thereby maintaining both document accessibility and security control. The server mediates the sharing process by providing controlled access rather than direct file transfer.
Solution Approach 2:
Security restrictions are configured and enforced in advance before the document is actually accessed by the recipient. The server pre-configures policies regarding copying, printing, and other document operations, ensuring that security controls are already in place when the document becomes accessible, preventing unauthorized actions before they occur.
2Reliability
If security restrictions are enforced on shared documents, then data security is improved, but document sharing functionality deteriorates
Solution Approach 1:
Security restrictions are made dynamic and configurable rather than static and fixed. The system allows different security policies to be applied to different documents, users, or contexts (e.g., allowing printing in some cases, blocking in others). This dynamic approach maintains data security while adapting to various document sharing scenarios and user needs.
Solution Approach 2:
Different security restrictions are applied to different aspects or portions of the document sharing functionality. Instead of applying a uniform security policy to all document operations, the system allows granular control where specific restrictions (copying, printing, downloading) can be independently configured for different documents or users, maintaining versatility while ensuring security.
Data Source
AI summary
Disclosed are various embodiments for sharing documents among users of an enterprise as well as with users external to an enterprise. A document is identified and document components extracted from the document. A browser representation is generated that, when rendered or interpreted by a browser, causes the browser to generate a user interface that presents at least a portion of the document as the document would be viewed by a native viewer.


