Token-Based Data Access Control for Electronic Documents
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Electronic documents can inadvertently share or transmit sensitive information or malicious data due to their ability to access external resources, posing security and privacy concerns within internal networks.
Innovation Solution
Implementing a token-based system that restricts data access from electronic documents by requiring 'get' and 'send' tokens for accessing or transmitting data, with automatic approval for certain scenarios and operator approval for others to prevent unauthorized data sharing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If documents are configured to access external data resources, then data sharing capability is improved, but security and privacy risks increase
Solution Approach 1:
The patent introduces a token as an intermediary mechanism between documents and external data resources. Tokens mediate the access relationship by requiring documents to possess valid tokens before accessing external resources, thereby enabling controlled data sharing while preventing unauthorized access and security risks
2Ease of operation
If automatic approval is implemented for data access, then ease of operation is improved, but security control is worsened
Solution Approach 1:
The patent applies different approval policies to different types of data access operations. Get operations (receiving data) are automatically approved to ensure ease of operation, while send operations (transmitting data) require explicit approval to maintain security control. This localized differentiation resolves the contradiction by applying appropriate control levels to appropriate operations
Data Source
AI summary
A system and method for restricting data access from an electronic document configured to access external data resources (e.g., websites, disk storage). To restrict unwanted data sharing, the document is prohibited from accessing external data resources unless it has a token corresponding to the resource. “Get” tokens and “send” tokens are granted, respectively, whenever the document is permitted to receive data from or send data to a data resource. Every attempt to receive data is automatically approved. An attempt to send data is approved automatically only if the document: (a) has no get tokens, (b) has only one get token and is attempting to send to the same resource, or (c) already has a send token corresponding to the resource and the set of get tokens has not changed since data was last sent to the resource. Otherwise, the attempt must be approved by an operator or data access policy.


