Sequential Access Control for Secure Digital Documents

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Digital documents lack effective mechanisms to ensure sequential and secure access, making it difficult to prevent unauthorized access and modifications, especially when transmitted outside a secure environment.

Innovation Solution

A method and apparatus that encrypt and sign digital documents into atomic units, controlling access through a document management system that manages sequential access by using key-map files and workflow wraps, ensuring participants access the document in a predetermined order by decrypting and verifying the document level information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If digital documents are stored in a database with access control, then unauthorized access can be prevented, but users must be granted access to the database or network which complicates the system architecture

Engineering Contradiction:
Improveaccess control securityVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the document into atomic units with individual encryption keys, allowing fine-grained access control without requiring users to access a centralized database. Each atomic unit can be independently controlled and distributed, eliminating the need for complex network access control infrastructure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies preliminary encryption and signing to the document and its atomic units before distribution. Access control is established in advance through cryptographic mechanisms rather than requiring runtime database access control, simplifying the system architecture while maintaining security.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If digital documents allow modifications, then usability is improved, but it becomes difficult to prevent counterfeiting and unauthorized changes

Engineering Contradiction:
Improvedocument modification capabilityVSAvoiddocument authenticity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies digital signatures and encryption to atomic units before distribution, creating preliminary protective measures that prevent counterfeiting. Any modification to the document or its atomic units would break the cryptographic chains, making unauthorized changes detectable while still allowing authorized modifications.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The patent creates a feedback mechanism through cryptographic verification where the system can detect and verify document integrity. Digital signatures and encryption provide continuous feedback about the authenticity and modification status of the document and its atomic units throughout the workflow.

Inventive Principle:
Principle #23Feedback

3Reliability

If sequential access control is implemented, then document workflow security is improved, but the system complexity increases

Engineering Contradiction:
Improveworkflow securityVSAvoidaccess control mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the document into atomic units that can be independently controlled and distributed. Each atomic unit contains its own encryption key and can be accessed by different participants in the workflow independently, simplifying sequential access control compared to controlling access to the entire document as a single unit.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the parameter of document structure from a single unified document to multiple atomic units with different encryption keys. This parameter change enables flexible sequential access control where different participants can access different atomic units in a defined order without requiring complex centralized control mechanisms.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8793503B2Managing sequential access to secure content using an encrypted wrap
Publication Date: 2014.07.29 HEWLETT PACKARD DEVELOPMENT COMPANY LP
  • US8793503B2 patent drawing
  • US8793503B2 patent drawing
  • US8793503B2 patent drawing

AI summary

In a method for managing sequential access to secure content by a plurality of workflow participants, a key-map file for each of the participants is created. Each of the key-map files contains a subset of encryption and signature keys for the content. The key-map files are sorted in an order that is the reverse of a workflow order in which the workflow participants for which the key-map files were created are to access the secure content. An encrypted later wrap including a later key-map file for a later workflow participant along the workflow order and an encrypted first wrap including a prior key-map file for a prior workflow participant and the encrypted later wrap are created. In addition, the first wrap is incorporated into a document serialization for the content.