Access Control for Shared Content in Online Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Online content management systems lack effective mechanisms for administrators to control and limit the sharing of content outside of a group, potentially leading to the inadvertent sharing of sensitive data with unauthorized users.

Innovation Solution

Implementing methods and systems that allow administrators to manage access to shared content by determining approved requestors, controlling types of shared links, and setting permissions for group members, including options for always public, always private, or user-specified privacy settings, to restrict sharing outside the group.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If administrators allow easy sharing of content outside the group, then collaboration and accessibility are improved, but security and confidentiality are compromised

Engineering Contradiction:
Improveease of sharingVSAvoidunauthorized access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary approval mechanism between the content sharer and external requestors. When a user attempts to share content externally, the system intercepts the request and requires administrator approval before granting access. This intermediary layer prevents unauthorized sharing while maintaining ease of use for approved collaborations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary verification by checking whether external requestors are in the approved list before allowing access to shared content. This preliminary action prevents unauthorized users from accessing sensitive data while still enabling easy access for pre-approved collaborators.

Inventive Principle:
Principle #10Preliminary action

2Object-affected harmful factors

If administrators implement strict access control mechanisms, then security is improved, but ease of sharing and collaboration is reduced

Engineering Contradiction:
Improveunauthorized accessVSAvoidease of sharing
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The system automatically checks whether external requestors are in the approved list without requiring manual administrator intervention for each access request. This self-service mechanism maintains security through automated verification while preserving ease of access for approved users.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The approved list serves multiple functions: it acts as an approval mechanism for external sharing, an access control list for protected content, and a collaboration whitelist. This multi-functionality reduces the need for separate mechanisms, maintaining both security and ease of use.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If the system allows external users to access content without login, then accessibility is improved, but control over shared content is reduced

Engineering Contradiction:
ImproveaccessibilityVSAvoidcontrol mechanism
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The system performs preliminary verification by checking whether external requestors are in the approved list before allowing access to shared content. This preliminary action prevents unauthorized users from accessing sensitive data while still enabling easy access for pre-approved collaborators.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary approval mechanism between the content sharer and external requestors. When a user attempts to share content externally, the system intercepts the request and requires administrator approval before granting access. This intermediary layer prevents unauthorized sharing while maintaining ease of use for approved collaborations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9294485B2Controlling access to shared content in an online content management system
Publication Date: 2016.03.22 DROPBOX INC
  • US9294485B2 patent drawing
  • US9294485B2 patent drawing
  • US9294485B2 patent drawing

AI summary

Systems and methods for controlling access to shared content in an online content management system, include receiving a request to access a content item from a requester, wherein the content item is stored in a synchronized online content management system. The example method then includes determining that the requester is in an approved list of requestors and granting access to the content item. In one variation, the request to access the content item includes activation of a shared link. In another variation, the request to access the content item includes access to a shared folder in the synchronized online content management system. In a third variation, determining that the requester is in an approved list of requesters includes determining that the requester is logged into a primary and secondary account, and that the requester is in an approved list for the secondary account.