Secure Redacted Document Access via Location-Based Container
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The proliferation of mobile devices has made it challenging for organizations to maintain secure and controlled access to sensitive documents, as perimeter-based security models are difficult to enforce due to the need for external access and the ease of data transfer, leading to concerns about privacy and security, especially when employees access documents in public or unauthorized locations.
Innovation Solution
A computerized method and apparatus that generates a container with multiple redacted versions of a document, each with a level of redaction corresponding to a specific viewing location, using encryption and custom code to ensure only authorized users access appropriate levels of information based on their location, allowing secure viewing without the need for separate viewer applications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If perimeter-based security model is used to control document access, then security is improved, but external access capability deteriorates
Solution Approach 1:
The document is segmented into multiple redacted versions with different levels of redaction, each corresponding to different viewing locations. The container is divided into multiple redacted documents (e.g., first redacted document for public locations, second redacted document for private locations), allowing selective access based on location while maintaining security through the perimeter model.
Solution Approach 2:
Different levels of redaction are applied locally to different portions of the document based on the viewing location. The system determines the appropriate redaction level based on the location identifier and applies corresponding redaction to the document portions, ensuring appropriate security at each location without compromising overall access capability.
2Object-affected harmful factors
If special viewer application with redacted documents is provided, then privacy protection is improved, but device complexity and management overhead increase
Solution Approach 1:
The container format is designed to be universally compatible with existing document viewing applications. The viewing application uses standard functionality to display the container and its contents, eliminating the need for specialized viewer software. The same application can handle various redaction levels and location-based access control without requiring separate applications for each function.
Solution Approach 2:
The container acts as an intermediary between the secure redacted documents and the standard viewing application. It encapsulates the security mechanisms and location-based access control, allowing standard applications to interact with secure documents without needing direct integration with the security system. The container mediates between the security layer and the application layer.
3Reliability
If multiple redacted versions of documents are maintained, then location-based access control is improved, but storage requirements and document management complexity increase
Solution Approach 1:
Multiple redacted document versions are merged into a single container structure. Instead of managing separate document files for different locations, the system combines them into one container that holds all redacted versions. This reduces the number of individual document objects while maintaining the ability to provide location-based access control to different versions.
Solution Approach 2:
The redacted document versions are prepared in advance before the actual viewing occurs. The container is pre-configured with multiple redacted versions corresponding to different locations, and the system only needs to select and transmit the appropriate version based on the location identifier at viewing time, rather than creating versions dynamically during access.
4Ease of operation
If encryption information is transmitted to requesting device, then document accessibility is improved, but security vulnerability increases
Solution Approach 1:
The encryption information transmission is made dynamic based on the specific redacted document and location requirements. The system transmits encryption information only when needed for a specific document access request, rather than providing it continuously. The encryption information can be adjusted dynamically based on the location identifier and the specific redacted version being accessed, allowing selective decryption only for authorized locations.
Data Source
AI summary
Described are computer-based methods and apparatuses, including computer program products, for secure redacted document access. A viewing application for viewing documents is executed, the viewing application comprising standard code for the viewing application that can not process the container data type, and custom code configured to allow the viewing application to process a container data type. A container of the container data type is received from a remote computing device comprising a set of redacted documents corresponding to an original document, each redacted document having a level of redaction corresponding to a viewing location, and a header comprising encryption information for each redacted document in the set of redacted documents. The container is processed based on a location of the computing device and the custom code.


