Access Control for Shared Content in Online Systems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Online content management systems lack effective mechanisms for administrators to control and limit the sharing of content outside of a group, potentially leading to the inadvertent sharing of sensitive data with unauthorized users.
Innovation Solution
Implementing methods and systems that allow administrators to manage access to shared content by determining approved requestors, controlling types of shared links, and setting permissions for group members, including options for always public, always private, or user-specified privacy settings, to restrict sharing outside the group.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If administrators allow easy sharing of content outside the group, then collaboration and accessibility are improved, but security and confidentiality are compromised
Solution Approach 1:
The patent introduces an intermediary approval mechanism between the content sharer and external requestors. When a user attempts to share content externally, the system intercepts the request and requires administrator approval before granting access. This intermediary layer prevents unauthorized sharing while maintaining ease of use for approved collaborations.
Solution Approach 2:
The system performs preliminary verification by checking whether external requestors are in the approved list before allowing access to shared content. This preliminary action prevents unauthorized users from accessing sensitive data while still enabling easy access for pre-approved collaborators.
2Object-affected harmful factors
If administrators implement strict access control mechanisms, then security is improved, but ease of sharing and collaboration is reduced
Solution Approach 1:
The system automatically checks whether external requestors are in the approved list without requiring manual administrator intervention for each access request. This self-service mechanism maintains security through automated verification while preserving ease of access for approved users.
Solution Approach 2:
The approved list serves multiple functions: it acts as an approval mechanism for external sharing, an access control list for protected content, and a collaboration whitelist. This multi-functionality reduces the need for separate mechanisms, maintaining both security and ease of use.
3Ease of operation
If the system allows external users to access content without login, then accessibility is improved, but control over shared content is reduced
Solution Approach 1:
The system performs preliminary verification by checking whether external requestors are in the approved list before allowing access to shared content. This preliminary action prevents unauthorized users from accessing sensitive data while still enabling easy access for pre-approved collaborators.
Solution Approach 2:
The patent introduces an intermediary approval mechanism between the content sharer and external requestors. When a user attempts to share content externally, the system intercepts the request and requires administrator approval before granting access. This intermediary layer prevents unauthorized sharing while maintaining ease of use for approved collaborations.
Data Source
AI summary
Systems and methods for controlling access to shared content in an online content management system, include receiving a request to access a content item from a requester, wherein the content item is stored in a synchronized online content management system. The example method then includes determining that the requester is in an approved list of requestors and granting access to the content item. In one variation, the request to access the content item includes activation of a shared link. In another variation, the request to access the content item includes access to a shared folder in the synchronized online content management system. In a third variation, determining that the requester is in an approved list of requesters includes determining that the requester is logged into a primary and secondary account, and that the requester is in an approved list for the secondary account.


