Virtual Document Management via Gateway Policy Enforcement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
There is a need for a user interface that provides secure access from mobile devices to an aggregated set of on-premise Enterprise Content Management (ECM) and cloud storage services, while enforcing policies and monitoring/tracking mobile device use of managed content across various storage locations.
Innovation Solution
The Averail Cloud Content Exchange service implements a secure virtual document management system that uses encryption and policy control solutions across multiple storage services, providing a managed container for mobile devices to access and manage content securely across on-premise ECM and cloud storage services, ensuring compliance with enterprise policies and permissions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If mobile devices access content across multiple storage locations (on-premise ECM and cloud storage services), then accessibility and versatility are improved, but security and policy enforcement become more complex
Solution Approach 1:
The patent introduces a gateway server as an intermediary component that mediates between mobile devices and multiple storage locations (on-premise ECM and cloud storage services). The gateway server centralizes security policy enforcement, authentication, and content access control, thereby maintaining security without compromising the versatility of accessing content across different storage systems.
2Reliability
If content is encrypted and secured across multiple storage domains, then data security is improved, but ease of operation and access simplicity deteriorate
Solution Approach 1:
The patent implements automatic encryption and decryption mechanisms that operate transparently in the background. The system automatically encrypts content when stored, manages encryption keys, and decrypts content when accessed by authorized users, without requiring manual intervention. This maintains strong security while preserving ease of operation for legitimate users.
Solution Approach 2:
The gateway server acts as an intermediary that handles complex security operations including encryption, decryption, and key management. By centralizing these operations, the system maintains high security standards while presenting a simplified interface to end users who don't need to manually manage encryption details.
3Reliability
If policy control and monitoring are enforced across distributed storage systems, then compliance and security are improved, but device complexity and operational overhead increase
Solution Approach 1:
The patent segments the system into distinct functional components: mobile devices for content access, gateway server for policy enforcement and monitoring, and multiple storage locations for content storage. This segmentation allows policy control and monitoring functions to be centralized in the gateway server, improving compliance without distributing complexity across all system components.
Solution Approach 2:
The gateway server serves as an intermediary that centralizes policy control, authentication, and monitoring functions. By consolidating these complex operations in a single component rather than distributing them across multiple devices and storage systems, the system achieves high compliance standards while managing complexity centrally rather than分散ly.
Data Source
AI summary
A user interface for a virtual file management system that provides user access to managed content on mobile devices. The system comprises storage domains storing the managed content distributively using file systems, and a data infrastructure that organizes the managed content into a virtual file system. The data infrastructure includes a component that maintains policies defining controls for permissible operations on the managed content, the permissible operations including the file system primitives. A client application including a user interface is hosted on the mobile devices and is coupled to the data infrastructure and the storage domains and includes an enforcement component that retrieves and enforces the policies by applying the controls on the mobile devices.


