Management of confidential document distribution and security
Abstract
A method of managing distribution of a document and access to its contents with security in a network having nodes is described. The nodes may have digital processors for remote communication over a wide area network and local data stores. The exemplary method includes a node sending a document in encrypted format and including a payload, and control data including destination data, access control data, and signature data, and a document destination list. The sending node may only send the document to nodes on the destination list. A node may receive the document, decrypt at least some of the document, and process the document according to the control data by extracting the control data and managing document payload access and document storage and user access according to the control data.
Claims
exact text as granted — not AI-modified1 . A method of managing distribution of a document and access to its contents with security in a network comprising nodes with digital processors for remote communication over a wide area network and local data stores,
the method being implemented by said processors and comprising steps of:
a node, acting as a sending node, sending a document in encrypted format into the network and said document including:
a payload with document content, and
control data including destination data, an access control rights map, and
signature data, and a document destination list, and
finite state machine (FSM) executable software code for managing document state,
a node, acting as a receiving node and executing a software client application, receiving the document, decrypting at least some of it, and processing the document according to said control data by extracting the control data and managing document payload access and document storage and user access according to the control data, and in which:
said software client application acts as a listener for documents directed towards that receiving node, and also acts as a compiler and executor of the control data embedded within the received document,
the receiving node software client application processes the control data in a manner transparently to authorised users, and
the receiving node executes the finite state machine FSM executable software code to allow it and the document to access a current document state, and to enable the document to move through a document-specific set of allowable states.
2 . The method as claimed in claim 1 , wherein the receiving node extracts the payload and outputs data to authorised users, by mapping sections of the payload to an access control list ACL, in which each authorized user participant has access to some or all of the document.
3 . The method as claimed in claim 1 , wherein the receiving node stores in an access log of the document a record of authorised user access to the payload.
4 . The method as claimed in claim 1 , wherein the control data includes mapped document sections including:
an interested parties section defining authorised users, an access control section defining, for each authorised user, a user identifier and a rights map governing access to the document internal structure, an access log section recording historical user access data including identifier of said user and time and nature of each access.
5 . The method as claimed in claim 1 , wherein the nodes perform encryption and decryption using public and private keys in which the public key is used to verify and encrypt and the private key is used to decrypt.
6 . The method as claimed in claim 1 , wherein the document includes one or more of:
network configuration data including destination nodes and optimisation settings relating to network load for distributing the document in an efficient manner, an access control list specifying levels of authorisation for recipients of the document, an access log which records access to the document, both machine access and human user access, payload attributes including one or more of version numbers, checksums, and priorities, and signature-relations records includes settings relating to a map of signatures and workflow for a sequence of signatures and verifications to be enforced.
7 . The method as claimed in claim 1 , wherein the document includes executable code for dynamic instantiation of the document by the sending node.
8 . The method as claimed in claim 1 , wherein the document is processed by the receiving node as an instantiation of the FSM which understands, through its executable code, a sequence of document-specific allowable states for that document and provides document-specific features for use by the authorized users.
9 . The method as claimed in claim 1 , wherein the receiving node determines a next user according to a next actor in a workflow which is determined according to a map within the document, and said map is aligned to the current state of the document as held in the FSM code to ensure that the document goes to the next agreed-upon step in the process.
10 . The method as claimed in claim 1 , wherein the receiving node determines a next user according to a next actor in a workflow which is determined according to a map within the document, and said map is aligned to the current state of the document as held in the FSM code to ensure that the document goes to the next agreed-upon step in the process; and wherein the document payload is sent a plurality of times each with a different set of participating parties, and each FSM state in the document is known ahead of its distribution, and FSM state data is included in the control data when the document is distributed.
11 . The method as claimed in claim 1 , comprising the sending node performing a look-up of an array of participants to determine at document run time.
12 . The method as claimed in claim 1 , comprising the sending node performing a look-up of an array of participants to determine at document run time; and wherein said look-up provides instructions for a level of granularity of controlling interaction of a receiving node with specific parts of a document, according to meta data about the document and its constituent parts.
13 . The method as claimed in claim 1 , wherein the document includes semantic definitions of the sections within the document.
14 . The method as claimed in claim 1 , wherein the document includes semantic definitions of the sections within the document; and wherein the semantic definitions are expressed as RDF and/or XML/JSON representations.
15 . The method as claimed in claim 1 , wherein the rights map is included in an access control list providing a desired fine grained and deep level of control.
16 . The method as claimed in claim 1 , comprising allowing an authorized user to sign in with access to one document section, but make no other alterations, or to allow an update to a specific section of the document but not to another section.
17 . The method as claimed in claim 1 , wherein the FSM code and the access control data are dynamically modified to enable intelligent document analysis at run time to determine any shifts in access control requirements over its lifetime, in which the document has M states and N authorized users who have read/write access, an authorized user acts on the document and moves it from a first state to a second state which causes that user to lose write access, but a subsequent state change caused by a second user causes said first user to re-gain write access.
18 . The method as claimed in claim 1 , wherein the FSM executable software code manages the movement of the document from one document state to another document state by providing standard services to the underlying receiving node processor and the document allows a consistent approach to state changes across all document types, in which the FSM executable code maintains the state of the document.
19 . The method as claimed in claim 1 , wherein updates to the document are tracked and controlled by the nodes in a distributed audit trail, while guaranteeing that only those authorized users who have access rights to relevant document sections can interact.
20 . A network comprising a plurality of nodes with digital data processors and storage and being configured to perform a method of claim 1 .
21 . A non-transitory computer storage medium comprising software code for implementing a method of claim 1 when executed by digital data processors.Join the waitlist — get patent alerts
Track US2020082106A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.