EP1528455A1

Offline access in a document control system

Abstract

Systems and techniques to provide offline access in a document control system. In general, in one implementation, the technique includes: receiving a request from a client, and pre-authorizing the client, in response to the request, to allow actions by a user as a member of a group of users by sending to the client offline access information including a first key associated with the group, the first key being useable at the client to access an electronic document by decrypting a second key in the electronic document. Receiving a request can involve receiving a request from the client to take an action with respect to a second document. The technique can also include verifying the user at the client as an authenticated user, and the offline access information can include user-specific keys, group-specific keys, a policy, and a document revocation list.

EP1528455A1, drawing sheet 1
Sheet 1 of 12

Term

Term ended

Projected expiry passed 29 October 2024, 1.9 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

57 claims: 27 independent, 30 dependent

  1. 1
    A method comprising:receiving a request from a client;and pre-authorizing the client, in response to the request, to allow actions by a user as a member of a group of users by sending to the client offline access information comprising a first key associated with the group, the first key being useable at the client to access an electronic document by decrypting a second key in the electronic document.
  2. 3
    The method of one of the preceding claims, wherein pre-authorizing the client comprises comparing current user-group information for the user with received user-group information for the user from the client.
  3. 4
    The method of one of the preceding claims, wherein the client allows actions with respect to the electronic document based on document-permissions information residing in the electronic document.
  4. 5
    The method of one of the preceding claims, wherein the offline access information further comprises document-permissions information associated with multiple documents, including the electronic document, and the client allows actions with respect to the electronic document based on the document-permissions information.
  5. 6
    The method of one of the preceding claims, wherein receiving a request comprises receiving a request from the client to take an action with respect to a second document.
  6. 12
    A method comprising:receiving from a document control server, when online, offline access information comprising a first key associated with a group of users of the document control server;and allowing access to an electronic document, when offline, by performing operations comprising using the first key to decrypt a second key in the electronic document and governing actions with respect to the electronic document based on document-permissions information associated with the electronic document.
  7. 15
    The method of one of the preceding claims 12 to 14, wherein the offline access information comprises at least one user-specific key, at least one group-specific key, including the first key, at least one set of document-permissions information associated with multiple documents, and a document revocation list.
  8. 16
    The method of one of the preceding claims 12 to 15, further comprising preventing access to the document, when offline, if a difference between a current time and a receipt time of the offline access information exceeds a server-synchronization-frequency parameter.
  9. 18
    The method of one of the preceding claims 12 to 17, further comprising:maintaining an offline audit log;and uploading the offline audit log when online.
  10. 19
    A method comprising:encrypting an electronic document;and incorporating into the encrypted electronic document an address of a document control server, document-permissions information, and an encryption key useable in decrypting the encrypted electronic document, the encryption key being encrypted with a key generated by, and associated with a group of users of, the document control server.
  11. 22
    The method of one of the preceding claims 19 to 21, wherein the document-permissions information specifies access permissions at a level of granularity smaller than the electronic document.
  12. 23
    A software product tangibly embodied in a machine-readable medium, the software product comprising instructions operable to cause one or more data processing apparatus to perform operations comprising:receiving a request from a client;and pre-authorizing the client, in response to the request, to allow actions by a user as a member of a group of users by sending to the client offline access information comprising a first key associated with the group, the first key being useable at the client to access an electronic document by decrypting a second key in the electronic document.
  13. 26
    The software product of one of the preceding claim 23 to 25, wherein the client allows actions with respect to the electronic document based on document-permissions information residing in the electronic document.
  14. 27
    The software product of one of the preceding claims 23 to 26, wherein the offline access information further comprises document-permissions information associated with multiple documents, including the electronic document, and the client allows actions with respect to the electronic document based on the document-permissions information.
  15. 28
    The software product of one of the preceding claims 23 to 27, wherein receiving a request comprises receiving a request from the client to take an action with respect to a second document.
  16. 34
    A software product tangibly embodied in a machine-readable medium, the software product comprising instructions operable to cause one or more data processing apparatus to perform operations comprising:receiving from a document control server, when online, offline access information comprising a first key associated with a group of users of the document control server;and allowing access to an electronic document, when offline, by performing operations comprising using the first key to decrypt a second key in the electronic document and governing actions with respect to the electronic document based on documerit-permissions information associated with the electronic document.
  17. 38
    The software product of one of the preceding claims 34 to 37, wherein the operations further comprise preventing access to the document, when offline, if a difference between a current time and a receipt time of the offline access information exceeds a server-synchronization-frequency parameter.
  18. 40
    The software product of one of the preceding claims 34 to 39, wherein the operations further comprise:maintaining an offline audit log;and uploading the offline audit log when online.
  19. 41
    A software product tangibly embodied in a machine-readable medium, the software product comprising instructions operable to cause one or more data processing apparatus to perform operations comprising:encrypting an electronic document;and incorporating into the encrypted electronic document an address of a document control server, document-permissions information, and an encryption key useable in decrypting the encrypted electronic document, the encryption key being encrypted with a key generated by, and associated with a group of users of, the document control server.
  20. 45
    A system comprising:a document control server that synchronizes offline access information with a client in response to a client request, the offline access information comprising a first key associated with a group, the first key being useable at the client to access an electronic document by decrypting a second key in the electronic document;and the client that allows access to the electronic document, when offline, by a user as a member of the group, using the first key to decrypt the second key in the electronic document and governing actions with respect to the electronic document based on document-permissions information associated with the electronic document.
  21. 48
    The system of one of the preceding claims 45 to 47, wherein the offline access information further comprises:at least one user-specific key;at least one group-specific key, including the first key;and at least one set of document-permissions information associated with multiple documents.
  22. 49
    The system of one of the preceding claims 45 to 48, wherein the client comprises an agent that periodically contacts the document control server to synchronize the offline access information.
  23. 50
    The system of one of the preceding claims 45 to 49, wherein the document control server comprises:a server core with configuration and logging components;an internal services component that provides functionality across dynamically loaded methods;and dynamically loaded external service providers, including one or more access control service providers.
  24. 51
    The system of one of the preceding claims 45 to 50, further comprising:a business logic tier comprising a cluster of document control servers, including the document control server;an application tier including the client comprising a viewer client, a securing client, and an administration client;and a load balancer that routes client requests to the document control servers.
  25. 52
    The system of one of the preceding claims 45 to 51, wherein the client request comprises a request from the client to take an action with respect to a second document.
  26. 55
    The system of one of the preceding claims 52 to 54, wherein the server comprises a permissions-broker server operable to obtain and send, in response to the request, a software program comprising instructions operable to cause one or more data processing apparatus to perform operations effecting an authentication procedure, and the client uses the authentication program to identify a current user and control the action with respect to the second document based on the current user and document-permissions information associated with the second document.
  27. 56
    A system comprising:server means for transparently providing offline access information for controlled documents to pre-authorize a client to allow actions by a user as a member of a group of users, the offline access information comprising a first key associated with the group, the first key being useable at the client to access an electronic document by decrypting a second key in the electronic document;and client means for accessing the electronic document using the offline access information.
Independent claims27