AI-Based Cloud Access Security Broker for Sensitive File Sharing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security systems struggle to efficiently classify and control the sharing of sensitive files across remote locations using AI, leading to potential data breaches and compliance issues.
Innovation Solution
Implementing an AI-based cloud access security broker (CASB) that determines file accessibility by flagging files for external sharing, using an AI engine to classify content against predetermined criteria, and making files inaccessible if they satisfy sensitive data classifications, with features like visual indicators and user interaction for control.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If files are allowed to be shared externally from remote locations, then ease of operation and collaboration improve, but security and data protection deteriorate
Solution Approach 1:
The patent introduces a cloud access security broker (CASB) as an intermediary component that sits between the file sharing system and external access points. The CASB intercepts file access requests, analyzes them against security policies, and mediates whether to allow or block the transfer. This intermediary mechanism enables secure external sharing by filtering requests through a security layer without preventing legitimate collaboration.
Solution Approach 2:
The system performs preliminary classification and security assessment of files before they are shared externally. The CASB analyzes file contents, metadata, and context in advance of actual sharing operations, pre-determining security risks and applying appropriate controls. This preliminary action ensures that security checks are completed before data exposure, enabling both secure sharing and operational efficiency.
2Reliability
If AI classification is applied to all files for security checking, then data protection improves, but processing time and system complexity worsen
Solution Approach 1:
The patent applies different levels of security analysis to different files based on their characteristics, sensitivity, and context. Rather than uniformly analyzing all files with the same AI depth, the system adjusts the classification rigor according to local file properties such as data type, user role, destination, and historical behavior. This localized quality approach protects sensitive files more intensely while allowing faster processing of low-risk files.
Solution Approach 2:
The system performs partial AI classification on files, focusing analysis on the most critical security-relevant features rather than exhaustive examination of all file attributes. The CASB selectively applies AI models to specific aspects of file content and context that are most indicative of security risks, achieving adequate protection with reduced processing overhead compared to complete file analysis.
3Measurement precision
If remote data center analysis is used for file security, then measurement precision improves, but device complexity and processing overhead worsen
Solution Approach 1:
The cloud access security broker serves as an intermediary layer between local endpoint devices and remote data center analysis systems. The CASB performs initial filtering, preprocessing, and contextual analysis locally, then selectively forwards only the most suspicious or high-value files to the remote data center for comprehensive AI classification. This intermediary architecture enables precise remote analysis while reducing the complexity burden on endpoint devices.
Solution Approach 2:
The security analysis function is segmented into multiple distributed components: lightweight local analysis at endpoint devices, intermediate analysis at the CASB, and comprehensive AI classification at remote data centers. This segmentation allows each component to perform specialized functions with appropriate complexity levels, achieving high measurement precision through coordinated multi-level analysis while distributing system complexity across multiple nodes rather than concentrating it in a single complex system.
Data Source
AI summary
Apparatuses, methods, systems, and program products are disclosed for endpoint-based security. An apparatus includes a processor and a memory that is coupled to the processor. The memory includes instructions that are executable by the processor to determine that a file is accessible from a remote location in response to the file being flagged for external sharing, provide contents of the file to an artificial intelligence (AI) engine to determine whether the contents of the file satisfies at least one predetermined classification, and provide an indication to make the file inaccessible from the remote location in response to the contents of the file satisfying the at least one predetermined classification.


