Volatile Document Container for Secure Online Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods of accessing and editing content files from a server result in security risks due to the need for local storage on client devices, leading to unauthorized access and retention of sensitive information.

Innovation Solution

A method that uses a document container in volatile memory to store and manage content files, bypassing non-volatile memory and implementing rule-based policies to control access and storage, ensuring secure online access by automatically deleting files when the container is destroyed.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If content files are downloaded and stored in non-volatile memory on the client device, then the user can access and edit the files locally, but security risks increase due to unauthorized access and retention of sensitive information

Engineering Contradiction:
Improvelocal file access and editingVSAvoidunauthorized access and data retention
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the content files from non-volatile memory and places them exclusively in volatile memory space. The document container isolates files in a temporary storage area that automatically clears upon container destruction, removing files from the persistent storage environment where unauthorized access could occur.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The document container acts as an intermediary layer between the user and the content files. It provides a controlled environment with substitute menus that mediate all file operations, allowing local editing capabilities while maintaining security through centralized control and automatic cleanup mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Duration of action of moving object

If content files are stored locally on the client device, then editing and viewing can be performed offline, but the risk of accidental or intentional copying and distribution increases

Engineering Contradiction:
Improveoffline access durationVSAvoidfile copying and distribution
Core Design Contradiction:
Duration of action of moving objectVSObject-generated harmful factors

Solution Approach 1:

The patent employs volatile memory as a disposable storage medium for content files. Unlike permanent storage, volatile memory automatically loses its data when power is removed or the container is destroyed, providing offline access capability while ensuring files cannot be permanently retained or distributed.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Solution Approach 2:

The system automatically discards content files when the document container is destroyed, with no manual intervention required. The volatile memory naturally clears its contents, providing automatic file recovery and elimination of security risks associated with leftover files on the system.

Inventive Principle:
Principle #34Discarding and recovering

3Productivity

If conventional download and upload processes are used, then file access and synchronization are achieved, but multiple local copies are created increasing security vulnerabilities

Engineering Contradiction:
Improvefile access and synchronization efficiencyVSAvoidnumber of local file copies
Core Design Contradiction:
ProductivityVSQuantity of substance

Solution Approach 1:

The patent segments the file storage into two distinct parts: volatile memory for active editing and non-volatile memory for permanent storage. This segmentation ensures that only one working copy exists in volatile memory at any time, eliminating the proliferation of local copies while maintaining efficient access and synchronization capabilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Instead of the conventional approach of downloading to permanent storage and then uploading, the patent inverts the process by using volatile memory as the primary working storage and directly uploading from there. This reversal eliminates the intermediate permanent storage step that creates security vulnerabilities.

Inventive Principle:
Principle #13The other way round (Inversion)

4Adaptability or versatility

If users have direct access to client device storage, then file management flexibility is improved, but the ability to control and audit file operations is reduced

Engineering Contradiction:
Improvefile management flexibilityVSAvoidstorage access control mechanism
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The substitute menus within the document container serve as an intermediary interface between the user and the file system. They provide familiar file management operations while actually routing all actions through a controlled pathway that maintains security policies and enables auditing without reducing user flexibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The document container provides multiple functions within a single unified interface: it offers file viewing, editing, saving, and uploading capabilities while simultaneously enforcing security policies, managing memory resources, and controlling file operations. This multi-functionality maintains user flexibility while adding necessary control mechanisms.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS7797724B2Methods and apparatus for secure online access on a client device
Publication Date: 2010.09.14 CITRIX SYSTEMS INC
  • US7797724B2 patent drawing
  • US7797724B2 patent drawing
  • US7797724B2 patent drawing

AI summary

A method of securely accessing at a client device content from a server without using the non-volatile memory of the client device is disclosed. The bypassing of non-volatile memory lessens the security risk of unauthorized viewing of the server originated content. An transport mechanism is initiated on a client device and creates a document container. Downloaded documents from a server are mapped into the document container and saved within the document container in volatile memory. Substitute menus are generated within the container to replace application menus. User documents are saved directly to the originating server via the substitute menus. The downloaded copies in volatile memory automatically delete when the document container is destroyed thereby reducing security concerns of unauthorized viewing of the content at the client device.