Secure Object Manager for Computer-Based Objects
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing computer systems lack effective mechanisms to control the disposition of computer-based objects, such as data and files, once they are transmitted or copied, leading to potential unauthorized redistribution and loss of value for the originator.
Innovation Solution
A secure object management system that includes a secure object manager and secure object agent, which transmit and enforce instructions on the disposition of computer-based objects, ensuring only authorized actions can be taken on the objects, including restrictions on redistribution, access, and lifetime control.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If computer-based objects are copied and transmitted to remote locations for use by others, then the utility and accessibility of the objects is improved, but the security and control over the objects' disposition deteriorates
Solution Approach 1:
Disposition instructions are attached to the object before transmission,预先 specifying the allowed actions and restrictions. This preliminary action ensures that control mechanisms are in place before the object reaches the remote location, resolving the contradiction by maintaining security constraints while enabling widespread accessibility.
Solution Approach 2:
A secure object agent acts as an intermediary between the object and the remote system, enforcing disposition instructions and controlling what actions can be taken on the object. This intermediary mechanism allows the object to be accessible remotely while maintaining the originator's control through the agent's enforcement of disposition rules.
2Productivity
If redistribution of objects is allowed to clients, then the productivity and value delivery are improved, but the loss of information and asset protection deteriorates
Solution Approach 1:
Different disposition rules are applied to different clients or contexts. The system allows selective redistribution to authorized clients while preventing unauthorized redistribution to others. This local differentiation enables productive value delivery to legitimate clients while protecting against information loss through targeted restrictions on unauthorized parties.
3Reliability
If strict control mechanisms are implemented to prevent unauthorized redistribution, then the security and asset protection are improved, but the ease of operation and system complexity deteriorates
Solution Approach 1:
The secure object agent automatically enforces disposition instructions without requiring continuous human intervention or complex manual control mechanisms. The system self-regulates by checking disposition rules before allowing actions on the object, which maintains strong asset protection while keeping the operation simple and automated.
4Reliability
If disposition instructions are attached to objects, then the control and security are improved, but the device complexity and processing overhead increase
Solution Approach 1:
Disposition instructions are merged with the object itself, forming a unified package that travels together. This combination eliminates the need for separate control systems or databases to track object disposition rules, reducing overall system complexity while maintaining effective control through the integrated instruction-object unit.
Data Source
AI summary
A secure object manager obtains, from an authorized person, a specification for disposition of at least one object, and creates first instructions, pertaining to the disposition, for a remote secure-object agent on a remote system. A copy of the object and the first instructions are sent to a remote secure-object agent on a remote system, which controls the copy based on the first instructions.


