Virtual Document Management via Gateway Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a need for a user interface that provides secure access from mobile devices to an aggregated set of on-premise Enterprise Content Management (ECM) and cloud storage services, while enforcing policies and monitoring/tracking mobile device use of managed content across various storage locations.

Innovation Solution

The Averail Cloud Content Exchange service implements a secure virtual document management system that uses encryption and policy control solutions across multiple storage services, providing a managed container for mobile devices to access and manage content securely across on-premise ECM and cloud storage services, ensuring compliance with enterprise policies and permissions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If mobile devices access content across multiple storage locations (on-premise ECM and cloud storage services), then accessibility and versatility are improved, but security and policy enforcement become more complex

Engineering Contradiction:
Improveaccessibility to contentVSAvoidsecurity management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a gateway server as an intermediary component that mediates between mobile devices and multiple storage locations (on-premise ECM and cloud storage services). The gateway server centralizes security policy enforcement, authentication, and content access control, thereby maintaining security without compromising the versatility of accessing content across different storage systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If content is encrypted and secured across multiple storage domains, then data security is improved, but ease of operation and access simplicity deteriorate

Engineering Contradiction:
Improvedata securityVSAvoidaccess simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements automatic encryption and decryption mechanisms that operate transparently in the background. The system automatically encrypts content when stored, manages encryption keys, and decrypts content when accessed by authorized users, without requiring manual intervention. This maintains strong security while preserving ease of operation for legitimate users.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The gateway server acts as an intermediary that handles complex security operations including encryption, decryption, and key management. By centralizing these operations, the system maintains high security standards while presenting a simplified interface to end users who don't need to manually manage encryption details.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If policy control and monitoring are enforced across distributed storage systems, then compliance and security are improved, but device complexity and operational overhead increase

Engineering Contradiction:
ImprovecomplianceVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the system into distinct functional components: mobile devices for content access, gateway server for policy enforcement and monitoring, and multiple storage locations for content storage. This segmentation allows policy control and monitoring functions to be centralized in the gateway server, improving compliance without distributing complexity across all system components.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The gateway server serves as an intermediary that centralizes policy control, authentication, and monitoring functions. By consolidating these complex operations in a single component rather than distributing them across multiple devices and storage systems, the system achieves high compliance standards while managing complexity centrally rather than分散ly.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9830468B2User interface for secure virtual document management system
Publication Date: 2017.11.28 IVANTI INC
  • US9830468B2 patent drawing
  • US9830468B2 patent drawing
  • US9830468B2 patent drawing

AI summary

A user interface for a virtual file management system that provides user access to managed content on mobile devices. The system comprises storage domains storing the managed content distributively using file systems, and a data infrastructure that organizes the managed content into a virtual file system. The data infrastructure includes a component that maintains policies defining controls for permissible operations on the managed content, the permissible operations including the file system primitives. A client application including a user interface is hosted on the mobile devices and is coupled to the data infrastructure and the storage domains and includes an enforcement component that retrieves and enforces the policies by applying the controls on the mobile devices.