Usage Rights Management via Policy Tagging
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current rights management systems are inadequate for dynamic, distributed, and collaborative environments, as they fail to efficiently manage and enforce usage rights, particularly in scenarios where usage rights need frequent changes and multiple users have individual copies of protected data objects on diverse devices, and they tightly control creation, modification, and distribution, making it difficult to distinguish between authors and owners.
Innovation Solution
A system and method that separates the publication and modification of protected data objects from the ownership and manipulation of usage policies, allowing for dynamic control over data objects through centralized management of usage rights, enabling changes to control policies without access to all copies, and allowing multiple data objects to reference the same policy, with a Control Policy Tag (CPT) attached to each object for secure and transparent access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If usage rights are tightly coupled to encrypted data objects in traditional rights management systems, then unauthorized access is prevented, but policy changes cannot be propagated to distributed copies without access to all copies
Solution Approach 1:
The patent segments the usage rights into two independent components: (1) encryption keys that remain tightly coupled with data objects for security, and (2) policy metadata stored separately in a centralized policy server. This allows the policy component to be updated independently and propagated to users without requiring access to all distributed data object copies, while the encryption component maintains security through traditional binding.
Solution Approach 2:
The patent introduces a policy server as an intermediary between users and data objects. The policy server stores and manages usage policy metadata, allowing centralized policy changes to be propagated to users through the intermediary without requiring direct access to distributed data object copies. This mediator enables efficient policy distribution while maintaining the security of encrypted objects.
2Reliability
If traditional rights management systems control creation, modification, and distribution of protected data objects, then usage rights are enforced, but it becomes difficult to distinguish between authors and owners
Solution Approach 1:
The patent separates the concepts of authorship and ownership by segmenting rights management into: (1) data object creation and authorship attribution, and (2) usage policy definition and ownership control. Authors can create objects and be attributed, while owners define usage policies through the policy server. This segmentation allows clear distinction between authors (creators) and owners (policy controllers) while maintaining enforcement.
Solution Approach 2:
The patent extracts usage policy definition from the data object itself and places it in a separate policy server. This extraction allows the policy metadata to be independently managed by owners without being tied to the authorship information embedded in the data object. Owners can define and modify policies separately from the original authorship context.
3Reliability
If rights management systems require access to all copies of data objects for policy changes, then usage rights are maintained, but system complexity and resource requirements increase
Solution Approach 1:
The patent extracts usage policy metadata from distributed data object copies and centralizes it in a policy server. This extraction eliminates the need for rights management systems to access or manage all distributed copies when making policy changes. The centralized policy server maintains usage rights through metadata management alone, significantly reducing system complexity and resource requirements compared to approaches requiring access to all copies.
4Ease of operation
If encryption keys are distributed to users for data object access, then authorized users can decrypt objects, but unauthorized users may obtain unprotected copies
Solution Approach 1:
The patent segments the security model into: (1) encryption keys that are securely distributed to authorized users for decryption, and (2) usage policy metadata that controls and tracks authorized access. This segmentation allows authorized users to access and decrypt objects while the policy metadata maintains accountability and prevents unauthorized redistribution by tracking legitimate access instances.
Solution Approach 2:
The patent implements feedback mechanisms where usage policy metadata records and tracks authorized decryption events. This feedback loop allows the system to monitor and control unauthorized copying by tracking legitimate access patterns, enabling detection and prevention of unauthorized redistribution while maintaining ease of access for authorized users.
Data Source
AI summary
In a network of intermittently-connected computers, a method and apparatus for maintaining and managing control over data objects authored, accessed, and altered by users in dynamic, distributed, and collaborative contexts. The invention method and apparatus attach to each data object an identification of a respective control policy. Each control policy comprises at least an indication of a subset of the users who may access the data object, an indication of the privileges granted to each subset of users able to access the data object, and an indication of a subset of users who may define or edit the control policy. The invention method and apparatus separate the management of the control policies of data objects from the creation and use of the data objects. The invention method and apparatus automate common policy changes, distribution of policy changes to the enforcement agents, and propagation of control policies to derivative works.


