AI-Based Cloud Access Security Broker for Sensitive File Sharing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security systems struggle to efficiently classify and control the sharing of sensitive files across remote locations using AI, leading to potential data breaches and compliance issues.

Innovation Solution

Implementing an AI-based cloud access security broker (CASB) that determines file accessibility by flagging files for external sharing, using an AI engine to classify content against predetermined criteria, and making files inaccessible if they satisfy sensitive data classifications, with features like visual indicators and user interaction for control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If files are allowed to be shared externally from remote locations, then ease of operation and collaboration improve, but security and data protection deteriorate

Engineering Contradiction:
Improvefile sharing capabilityVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a cloud access security broker (CASB) as an intermediary component that sits between the file sharing system and external access points. The CASB intercepts file access requests, analyzes them against security policies, and mediates whether to allow or block the transfer. This intermediary mechanism enables secure external sharing by filtering requests through a security layer without preventing legitimate collaboration.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary classification and security assessment of files before they are shared externally. The CASB analyzes file contents, metadata, and context in advance of actual sharing operations, pre-determining security risks and applying appropriate controls. This preliminary action ensures that security checks are completed before data exposure, enabling both secure sharing and operational efficiency.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If AI classification is applied to all files for security checking, then data protection improves, but processing time and system complexity worsen

Engineering Contradiction:
Improvedata protectionVSAvoidfile processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies different levels of security analysis to different files based on their characteristics, sensitivity, and context. Rather than uniformly analyzing all files with the same AI depth, the system adjusts the classification rigor according to local file properties such as data type, user role, destination, and historical behavior. This localized quality approach protects sensitive files more intensely while allowing faster processing of low-risk files.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system performs partial AI classification on files, focusing analysis on the most critical security-relevant features rather than exhaustive examination of all file attributes. The CASB selectively applies AI models to specific aspects of file content and context that are most indicative of security risks, achieving adequate protection with reduced processing overhead compared to complete file analysis.

Inventive Principle:
Principle #16Partial or excessive action

3Measurement precision

If remote data center analysis is used for file security, then measurement precision improves, but device complexity and processing overhead worsen

Engineering Contradiction:
Improvefile classification accuracyVSAvoidsystem architecture complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The cloud access security broker serves as an intermediary layer between local endpoint devices and remote data center analysis systems. The CASB performs initial filtering, preprocessing, and contextual analysis locally, then selectively forwards only the most suspicious or high-value files to the remote data center for comprehensive AI classification. This intermediary architecture enables precise remote analysis while reducing the complexity burden on endpoint devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security analysis function is segmented into multiple distributed components: lightweight local analysis at endpoint devices, intermediate analysis at the CASB, and comprehensive AI classification at remote data centers. This segmentation allows each component to perform specialized functions with appropriate complexity levels, achieving high measurement precision through coordinated multi-level analysis while distributing system complexity across multiple nodes rather than concentrating it in a single complex system.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20250328666A1Techniques for an artificial intelligence based cloud access security broker
Publication Date: 2025.10.23 DOPE SECURITY INC
  • US20250328666A1 patent drawing
  • US20250328666A1 patent drawing
  • US20250328666A1 patent drawing

AI summary

Apparatuses, methods, systems, and program products are disclosed for endpoint-based security. An apparatus includes a processor and a memory that is coupled to the processor. The memory includes instructions that are executable by the processor to determine that a file is accessible from a remote location in response to the file being flagged for external sharing, provide contents of the file to an artificial intelligence (AI) engine to determine whether the contents of the file satisfies at least one predetermined classification, and provide an indication to make the file inaccessible from the remote location in response to the contents of the file satisfying the at least one predetermined classification.