Security Containers for Document Component Granular Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing techniques for securing content provide only all-or-nothing access and functional controls, lacking granular control over individual document components, which limits the ability of content creators to manage access and operations at a finer level.

Innovation Solution

The use of security containers that encapsulate document components with conditional logic and key distribution information, allowing for fine-grained access and functional control, enabling authorized users and processes to access and manipulate components while preventing unauthorized access and use.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If traditional access control techniques are used at the file or document level, then implementation is simple, but granular control over individual document components is lost

Engineering Contradiction:
Improvecontrol granularityVSAvoidimplementation simplicity
Core Design Contradiction:
Device complexityVSEase of manufacture

Solution Approach 1:

The patent segments document control into individual component-level security containers. Each security container encapsulates a specific document component (image, text, table, etc.) with its own access control rules and encryption keys, enabling fine-grained control over individual components rather than treating the entire document as a single unit.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces security containers as intermediary objects between the document components and the access control system. These containers act as mediators that enforce access policies, manage encryption keys, and control operations on embedded components without requiring changes to the host application's core architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If content is provided in clear form to users, then ease of access is improved, but security and control over the content is lost

Engineering Contradiction:
Improvecontent accessibilityVSAvoidcontent security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies different security qualities to different document components based on their sensitivity and requirements. Each security container can have its own encryption level, access control list, and operational restrictions, allowing critical components to be heavily protected while less sensitive components remain more accessible.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent dynamically changes security parameters (encryption status, access rights, operational constraints) based on user authentication, context, and policy rules. The same document component can be encrypted for unauthorized users but decrypted and accessible for authorized users with appropriate permissions.

Inventive Principle:
Principle #35Parameter changes

3Device complexity

If functional controls are implemented at the document level, then implementation is straightforward, but control over individual component operations is insufficient

Engineering Contradiction:
Improvecontrol structureVSAvoidcomponent operation control
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent segments functional control at the component level within security containers. Each container can independently enforce operational restrictions (copy, move, edit, print) on its embedded component, allowing different control policies for different components within the same document.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic functional controls that can change based on context, user identity, and security policies. Operational permissions are not static but can be adjusted dynamically through the security container's policy evaluation mechanism.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS7515717B2Security containers for document components
Publication Date: 2009.04.07 WORKDAY INC
  • US7515717B2 patent drawing
  • US7515717B2 patent drawing
  • US7515717B2 patent drawing

AI summary

Methods, systems, computer program products, and methods of doing business whereby document components are secured or controlled using “security containers” which encapsulate the components (and other component metadata). A “security container” encapsulates the component (i.e., content) that is to be controlled within a higher-level construct such as a compound document. The security container also contains rules for interacting with the encapsulated component, and one or more encryption keys usable for decrypting the component and rules for authorized requesters.