Twin File Search for Sensitive Document Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing database search systems face challenges in balancing user search interests with confidentiality, particularly in handling sensitive documents, as they often lack robust access control mechanisms to ensure that only authorized users can access sensitive information, leading to security risks and data leakage.

Innovation Solution

The method involves creating 'twin files' that are machine-readable and contain partial information from working documents, allowing for secure search operations while maintaining confidentiality, where the search engine accesses only twin files, and users are granted access to corresponding working documents based on their authorization levels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If the search engine accesses all working documents directly, then search completeness is improved, but security and confidentiality protection deteriorate

Engineering Contradiction:
Improvesearch completenessVSAvoidsecurity risk
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The patent divides working documents into two separate versions: machine-readable twin files for search operations and human-readable working documents for actual access. This segmentation allows the search engine to access twin files without exposing sensitive human-readable documents, thus maintaining both search completeness and security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces twin files as an intermediary between the search engine and working documents. The twin files serve as a buffer that allows search operations to occur without direct access to sensitive documents, acting as a mediator that protects confidentiality while enabling search functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If access authorization is restricted to protect sensitive documents, then security is improved, but search accessibility deteriorates

Engineering Contradiction:
Improveconfidentiality protectionVSAvoidsearch accessibility
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The patent segments access rights by creating twin files that can be accessed by search engines without requiring user authorization, while human-readable working documents maintain their authorization requirements. This allows search operations to proceed freely while protected documents remain secure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates machine-readable copies (twin files) of working documents that contain the same information but in a different format. These copies enable search operations without compromising the security of the original human-readable documents, as the twin files cannot be directly read by humans.

Inventive Principle:
Principle #26Copying

3Productivity

If sensitive documents are stored centrally for easy access, then search efficiency is improved, but vulnerability to data leakage deteriorates

Engineering Contradiction:
Improvesearch efficiencyVSAvoiddata leakage risk
Core Design Contradiction:
ProductivityVSObject-generated harmful factors

Solution Approach 1:

The patent segments document storage by maintaining twin files in a centralized search index while keeping human-readable working documents in their original locations. This allows efficient centralized search operations while distributing the actual sensitive documents, reducing the risk of centralized data leakage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates machine-readable copies (twin files) that are stored in a centralized index for efficient search operations. The original human-readable documents remain in their source locations, so even if the centralized index is compromised, the actual sensitive documents remain secure and distributed.

Inventive Principle:
Principle #26Copying

Data Source

PatentEP4432131A1Method for searching sensitive documents and system therefor
Publication Date: 2024.09.18 SECUNET SECURITY NETWORKS GMBH
  • EP4432131A1 patent drawingFigure 1
  • EP4432131A1 patent drawingFigure 2A~2C
  • EP4432131A1 patent drawingFigure 3A~3B

AI summary

The invention relates to a method for searching sensitive documents, wherein an electronic platform (1) comprises several clients (2) and preferably at least one server (3), wherein text-containing working documents (5, 15) are created or integrated into the platform (1), wherein the working documents (5, 15) are stored in a human-readable file format, wherein the working documents (5, 15) are automatically at least partially copied and converted within the platform (1), and the converted copies represent twin files (7, 17), wherein the platform (1) links each working document (5, 15) with the corresponding twin file (7, 17), wherein the respective working document (5, 15) and the twin file (7, 17) linked to the working document (5, 15) form a file pair (8, 18), wherein the search engine (6) during the search process (20) searches for at least a part of the twin files (7, 15).17) accesses and searches the contents of the twin files (7, 17) to fulfill the search query (20), wherein the search engine (6) creates a hit set (9) based on found twin files (7, 17), wherein a result set (11a, 11b) is displayed to the user (4), wherein the result set (11a, 11b) represents working documents (5, 15), and wherein the represented working documents (5, 15) of the result set (11a, 11b) are linked to the found twin files (7, 17) of the hit set (9).