Secure Redacted Document Access via Location-Based Container

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The proliferation of mobile devices has made it challenging for organizations to maintain secure and controlled access to sensitive documents, as perimeter-based security models are difficult to enforce due to the need for external access and the ease of data transfer, leading to concerns about privacy and security, especially when employees access documents in public or unauthorized locations.

Innovation Solution

A computerized method and apparatus that generates a container with multiple redacted versions of a document, each with a level of redaction corresponding to a specific viewing location, using encryption and custom code to ensure only authorized users access appropriate levels of information based on their location, allowing secure viewing without the need for separate viewer applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If perimeter-based security model is used to control document access, then security is improved, but external access capability deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidexternal access capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The document is segmented into multiple redacted versions with different levels of redaction, each corresponding to different viewing locations. The container is divided into multiple redacted documents (e.g., first redacted document for public locations, second redacted document for private locations), allowing selective access based on location while maintaining security through the perimeter model.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different levels of redaction are applied locally to different portions of the document based on the viewing location. The system determines the appropriate redaction level based on the location identifier and applies corresponding redaction to the document portions, ensuring appropriate security at each location without compromising overall access capability.

Inventive Principle:
Principle #3Local quality

2Object-affected harmful factors

If special viewer application with redacted documents is provided, then privacy protection is improved, but device complexity and management overhead increase

Engineering Contradiction:
Improveprivacy protectionVSAvoidviewer application complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The container format is designed to be universally compatible with existing document viewing applications. The viewing application uses standard functionality to display the container and its contents, eliminating the need for specialized viewer software. The same application can handle various redaction levels and location-based access control without requiring separate applications for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The container acts as an intermediary between the secure redacted documents and the standard viewing application. It encapsulates the security mechanisms and location-based access control, allowing standard applications to interact with secure documents without needing direct integration with the security system. The container mediates between the security layer and the application layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If multiple redacted versions of documents are maintained, then location-based access control is improved, but storage requirements and document management complexity increase

Engineering Contradiction:
Improvelocation-based access controlVSAvoidnumber of document versions
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

Multiple redacted document versions are merged into a single container structure. Instead of managing separate document files for different locations, the system combines them into one container that holds all redacted versions. This reduces the number of individual document objects while maintaining the ability to provide location-based access control to different versions.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The redacted document versions are prepared in advance before the actual viewing occurs. The container is pre-configured with multiple redacted versions corresponding to different locations, and the system only needs to select and transmit the appropriate version based on the location identifier at viewing time, rather than creating versions dynamically during access.

Inventive Principle:
Principle #10Preliminary action

4Ease of operation

If encryption information is transmitted to requesting device, then document accessibility is improved, but security vulnerability increases

Engineering Contradiction:
Improvedocument accessibilityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The encryption information transmission is made dynamic based on the specific redacted document and location requirements. The system transmits encryption information only when needed for a specific document access request, rather than providing it continuously. The encryption information can be adjusted dynamically based on the location identifier and the specific redacted version being accessed, allowing selective decryption only for authorized locations.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS8892872B2Secure redacted document access
Publication Date: 2014.11.18 IVANTI US LLC
  • US8892872B2 patent drawing
  • US8892872B2 patent drawing
  • US8892872B2 patent drawing

AI summary

Described are computer-based methods and apparatuses, including computer program products, for secure redacted document access. A viewing application for viewing documents is executed, the viewing application comprising standard code for the viewing application that can not process the container data type, and custom code configured to allow the viewing application to process a container data type. A container of the container data type is received from a remote computing device comprising a set of redacted documents corresponding to an original document, each redacted document having a level of redaction corresponding to a viewing location, and a header comprising encryption information for each redacted document in the set of redacted documents. The container is processed based on a location of the computing device and the custom code.