Role-based redaction of content
Disclosed are various embodiments for redacting or modifying content in documents that are provided to users. A user's clearance level can be determined by analyzing the role of the user within the enterprise. A redaction level can be determined from the clearance level. A document or other content can be modified or redacted based upon the redaction level.
1 . A non-transitory computer-readable medium embodying a program executable in a computing device, the program, when executed by the computing device, causing the computing device to at least:
obtain a request to provide a document to a user associated with a user account, wherein the request is received from a user device of the user;
identify a role associated with the user account;
identify a clearance level associated with the role;
identify redactable content in the document, including identifying a content type associated with the redactable content;
determine one or more compliance conditions associated with the user device from which the request was received, the compliance conditions comprising at least one of a geographic location of the user device, a network type through which the user device accesses the document, or a configuration state of the user device;
determine a redaction level associated with the redactable content based upon the clearance level associated with the role and the one or more compliance conditions associated with the user device, wherein the redaction level includes a scaling level that specifies a degree to which the redactable content is to be generalized, wherein determining the redaction level comprises evaluating one or more compliance rules associated with the user device and the clearance level associated with the role to determine how the redactable content is to be modified for the user device;
select a generalization algorithm associated with the identified content type, the generalization algorithm defining a transformation for modifying the redactable content according to the scaling level;
generate a modified document based upon the redaction level, wherein generating the modified document includes generalizing a portion of the redactable content such that the portion of the redactable content is replaced in the modified document with a more generalized version of the redactable content, wherein the more generalized version of the redactable content is generated by applying the selected generalization algorithm to the redactable content based on the scaling level, wherein the generalization algorithm is controlled by the scaling level such that different scaling levels cause different degrees of generalization of the redactable content; and
cause the modified document to be accessible to the user associated with the user account.
2 . The non-transitory computer-readable medium of claim 1 , wherein the content type comprises a proper noun, and a redaction rule generated based on the redaction level specifies redaction of the proper noun based upon the clearance level associated with the role.
3 . The non-transitory computer-readable medium of claim 1 , wherein the content type comprises an identification number, and a redaction rule generated based on the redaction level specifies redaction of the identification number based upon the clearance level associated with the role.
4 . The non-transitory computer-readable medium of claim 1 , wherein the content type comprises a financial value or a location, and a redaction rule generated based on the redaction level specifies generalization of the financial value or the location based upon the clearance level associated with the role.
5 . The non-transitory computer-readable medium of claim 1 , wherein the content type comprises device identifying information, and a redaction rule generated based on the redaction level specifies generalization of the device identifying information based upon the clearance level associated with the role.
6 . The non-transitory computer-readable medium of claim 1 , wherein the configuration state of the user device further comprises one or more of:
whether the user device has been modified to obtain root access or superuser privileges;
whether one or more unauthorized applications are installed on the user device;
whether one or more required applications specified by an administrator are installed on the user device; and
whether the user device employs data-at-rest encryption for stored content.
7 . A system, comprising:
at least one computing device;
at least one application executed by the at least one computing device, the at least one application, when executed, causing the at least one computing device to at least:
obtain a request to provide a document to a user associated with a user account, wherein the request is received from a user device of the user;
identify a role associated with the user account;
identify a clearance level associated with the role;
identify redactable content in the document, including identifying a content type associated with the redactable content;
determine one or more compliance conditions associated with the user device from which the request was received, the compliance conditions comprising at least one of a geographic location of the user device, a network type through which the user device accesses the document, or a configuration state of the user device;
determine a redaction level associated with the redactable content based upon the clearance level associated with the role and the one or more compliance conditions associated with the user device, wherein the redaction level includes a scaling level that specifies a degree to which the redactable content is to be generalized, wherein determining the redaction level comprises evaluating one or more compliance rules associated with the user device and the clearance level associated with the role to determine how the redactable content is to be modified for the user device;
select a generalization algorithm associated with the identified content type, the generalization algorithm defining a transformation for modifying the redactable content according to the scaling level;
generate a modified document based upon the redaction level, wherein generating the modified document includes generalizing a portion of the redactable content such that the portion of the redactable content is replaced in the modified document with a more generalized version of the redactable content, wherein the more generalized version of the redactable content is generated by applying the selected generalization algorithm to the redactable content based on the scaling level, wherein the generalization algorithm is controlled by the scaling level such that different scaling levels cause different degrees of generalization of the redactable content; and
cause the modified document to be accessible to the user associated with the user account.
8 . The system of claim 7 , wherein the content type comprises a proper noun, and a redaction rule generated based on the redaction level specifies redaction of the proper noun based upon the clearance level associated with the role.
9 . The system of claim 7 , wherein the content type comprises an identification number, and a redaction rule generated based on the redaction level specifies redaction of the identification number based upon the clearance level associated with the role.
10 . The system of claim 7 , wherein the content type comprises a financial value or a location, and a redaction rule generated based on the redaction level specifies generalization of the financial value or the location based upon the clearance level associated with the role.
11 . The system of claim 7 , wherein the content type comprises device identifying information, and a redaction rule generated based on the redaction level specifies generalization of the device identifying information based upon the clearance level associated with the role.
12 . The system of claim 7 , wherein the configuration state of the user device comprises one or more of:
whether the user device has been modified to obtain root access or superuser privileges;
whether one or more unauthorized applications are installed on the user device;
whether one or more required applications specified by an administrator are installed on the user device; and
whether the user device employs data-at-rest encryption for stored content.
13 . A method, comprising:
obtaining, by at least one computing device, a request to provide a document to a user associated with a user account, wherein the request is received from a user device of the user;
identifying, by the at least one computing device, a role associated with the user account; identifying, by the at least one computing device, a clearance level associated with the role;
identifying, by the at least one computing device, redactable content in the document, including identifying a content type associated with the redactable content;
determining, by the at least one computing device, one or more compliance conditions associated with the user device from which the request was received, the compliance conditions comprising at least one of a geographic location of the user device, a network type through which the user device accesses the document, or a configuration state of the user device;
determining, by the at least one computing device, a redaction level associated with the redactable content based upon the clearance level associated with the role and the one or more compliance conditions associated with the user device, wherein the redaction level includes a scaling level that specifies a degree to which the redactable content is to be generalized, wherein determining the redaction level comprises evaluating one or more compliance rules associated with the user device and the clearance level associated with the role to determine how the redactable content is to be modified for the user device;
selecting a generalization algorithm associated with the identified content type, the generalization algorithm defining a transformation for modifying the redactable content according to the scaling level;
generating, by the at least one computing device, a modified document based upon the redaction level, wherein generating the modified document includes generalizing a portion of the redactable content such that the portion of the redactable content is replaced in the modified document with a more generalized version of the redactable content, wherein the more generalized version of the redactable content is generated by applying the selected generalization algorithm to the redactable content based on the scaling level, wherein the generalization algorithm is controlled by the scaling level such that different scaling levels cause different degrees of generalization of the redactable content; and
causing, by the at least one computing device, the modified document to be accessible to the user associated with the user account.
14 . The method of claim 13 , wherein the content type comprises a proper noun, and a redaction rule generated based on the redaction level specifies redaction of the proper noun based upon the clearance level associated with the role.
15 . The method of claim 13 , wherein the content type comprises an identification number, and a redaction rule generated based on the redaction level specifies redaction of the identification number based upon the clearance level associated with the role.
16 . The method of claim 13 , wherein the content type comprises a financial value or a location, and a redaction rule generated based on the redaction level specifies generalization of the financial value or the location based upon the clearance level associated with the role.
17 . The method of claim 13 , wherein the configuration state of the user device comprises one or more of:
whether the user device has been modified to obtain root access or superuser privileges;
whether one or more unauthorized applications are installed on the user device;
whether one or more required applications specified by an administrator are installed on the user device; and
whether the user device employs data-at-rest encryption for stored content.