AI Security Label Generation for Context-Aware Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for creating sensitivity labels rely on user input, which can lead to inadequate protection, slow implementation, and generic encryption policies, leaving electronic assets vulnerable to cyberattacks and unauthorized access.

Innovation Solution

Automatically generate security labels using AI/ML models that analyze telemetry data to identify workgroups, collaboration topics, and content, generating encryption policies and labels that can be applied to electronic assets.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If user-based label generation is used, then security labels can be created with user control, but implementation is slow and protection is inadequate

Engineering Contradiction:
Improvesecurity protection adequacyVSAvoidlabel implementation speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system enables self-service by automatically generating security labels through AI/ML models that analyze telemetry data, user behaviors, and collaboration patterns without requiring manual user configuration. The automated label generation service extracts features from organizational data and publishes security labels independently, eliminating the slow manual process while maintaining appropriate security protection.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the mechanical manual process of user-based label creation with an automated AI/ML-based system. The machine learning models analyze organizational telemetry data and automatically generate security labels, substituting human effort with intelligent automation that is both faster and more accurate in identifying security requirements.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If user-based label generation is used, then users can define security labels, but the mechanism is unpredictable and assets remain vulnerable for months

Engineering Contradiction:
Improvesecurity protection consistencyVSAvoidasset vulnerability duration
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary action by automatically analyzing organizational data and generating security labels proactively before assets are exposed to risk. The automated label generation service continuously monitors telemetry data and publishes security labels in advance, ensuring assets are protected immediately rather than waiting months for manual label creation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback by continuously analyzing telemetry data from organizational devices and applications to dynamically generate and update security labels. The AI/ML models learn from ongoing data patterns and adjust label recommendations accordingly, creating a responsive feedback loop that ensures consistent and timely security protection.

Inventive Principle:
Principle #23Feedback

3Reliability

If user-based label generation is used, then security labels can be created, but generic encryption policies result that fail to provide adequate protection

Engineering Contradiction:
Improveencryption policy effectivenessVSAvoidlabel configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system applies local quality by generating customized security labels with specific encryption policies tailored to each organizational context. The AI/ML models analyze local telemetry data, user behaviors, and collaboration patterns to create locally-optimized security labels rather than applying generic policies, ensuring each label provides appropriate protection for its specific use case.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent utilizes parameter changes by dynamically adjusting encryption policy parameters based on analyzed organizational data. The system varies encryption strength, access controls, and security settings according to the specific characteristics identified in telemetry data, transforming static generic policies into dynamic context-aware security configurations.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12499250B2Automatic generation of security labels to apply encryption
Publication Date: 2025.12.16 MICROSOFT TECHNOLOGY LICENSING LLC
  • US12499250B2 patent drawing
  • US12499250B2 patent drawing
  • US12499250B2 patent drawing

AI summary

Non-limiting examples of systems, methods, and devices for automatically generating security labels are disclosed herein. In an implementation, generation of security labels is automated to enforce security policies and prevent data leaks. For example, characteristics identified in telemetry data (e.g., collaborators, workgroups, internal users, external users, file content, terms etc.) may be used to automatically generate sensitivity labels and corresponding encryption policies. In another implementation, a user interface may be rendered comprising descriptions of the generated security labels that allow for selection of the labels, which results in the implementation of the security label.