Application Wrapper for Targeted Data Loss Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional data loss prevention (DLP) systems are ineffective on unmanaged computing devices, as they require organizational control over all devices, which is not always feasible, especially when employees use personal devices to access sensitive data, leading to potential data exposure.

Innovation Solution

Implementing wrapped applications with application wrappers that intercept system calls and apply DLP policies specifically to sensitive data, rather than installing DLP endpoint agents on the entire device, thereby providing targeted protection without intrusive scans on personal data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional DLP systems are deployed on unmanaged computing devices, then data loss prevention coverage is improved, but device complexity and user acceptance deteriorate due to intrusive scanning of personal data

Engineering Contradiction:
Improvedata loss prevention coverageVSAvoidintrusiveness of DLP system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the DLP system into two distinct components: a lightweight agent installed on the unmanaged device that only monitors sensitive data, and a centralized server that processes the monitoring data. This segmentation allows the agent to remain minimal and non-intrusive while the server handles the complex DLP policy enforcement and analysis.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts the complex DLP policy processing and data analysis functions from the unmanaged device and relocates them to a centralized server. The agent on the unmanaged device only performs simple data collection and transmission, eliminating the need for complex local scanning and processing that would cause intrusion and performance issues.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If DLP endpoint agents are installed on unmanaged devices, then data protection is improved, but ease of operation deteriorates due to invasive scanning of personal data

Engineering Contradiction:
Improvedata protectionVSAvoiduser experience on personal devices
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies local quality by differentiating between personal data and sensitive organizational data. The agent selectively monitors only the sensitive data identified through file extensions, document types, and data patterns, while leaving personal data untouched and unmonitored, thus maintaining user comfort and ease of operation.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent introduces a centralized server as an intermediary between the unmanaged device and the DLP policy enforcement. The server receives data from the lightweight agent, processes it according to DLP policies, and makes determination decisions, thereby eliminating the need for complex local scanning and improving user experience.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If comprehensive DLP agents are deployed, then data exfiltration prevention is improved, but adaptability deteriorates when employees use personal devices

Engineering Contradiction:
Improvedata exfiltration preventionVSAvoidcompatibility with personal devices
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies partial action by implementing DLP monitoring only for specific sensitive data types and contexts rather than comprehensive monitoring of all data on the device. The agent monitors data based on file extensions, document types, and patterns relevant to organizational sensitivity, providing sufficient protection without the excessive intrusion of full-device scanning.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS9246948B2Systems and methods for providing targeted data loss prevention on unmanaged computing devices
Publication Date: 2016.01.26 CA TECH INC
  • US9246948B2 patent drawing
  • US9246948B2 patent drawing
  • US9246948B2 patent drawing

AI summary

A computer-implemented method for providing targeted data loss prevention on unmanaged computing devices may include (1) identifying a data loss prevention policy that defines permissible data handling within set bounds to prevent unauthorized data exfiltration from the set bounds, (2) identifying an application to install on at least one unmanaged endpoint device, where (i) the unmanaged endpoint device lacks a data loss prevention agent configured to apply the data loss prevention policy to the entire unmanaged endpoint device and (ii) the application is to be provided to the unmanaged endpoint device to operate on sensitive data from within the set bounds, and (3) wrapping the application in an application wrapper that intercepts system calls from the application and applies the data loss prevention policy to sensitive data implicated in the system calls. Various other methods, systems, and computer-readable media are also disclosed.