Application Layer Data Inspection for Sensitive Information Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional data security systems fail to identify and control the transmission of sensitive application-layer data, allowing inadvertent or intentional exposure of sensitive information outside the firewall, as they are designed to prevent external attacks rather than internal data leakage.

Innovation Solution

A method and system that identifies sensitive data at the application layer, detects packetization, inserts flags in packets to indicate sensitive data, and enforces transmission control rules and policies across network layers to prevent unauthorized data transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If firewall technology is employed to prevent external attacks and access, then external security is improved, but internal data transmission control deteriorates (sensitive data can still be transmitted outward)

Engineering Contradiction:
Improveexternal securityVSAvoidsensitive data transmission control
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent segments the network security function into two distinct components: (1) traditional firewall for external attack prevention, and (2) application-layer data inspection system for sensitive data identification and control. This segmentation allows each component to specialize in its respective function without compromising the other.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary component (application-layer gateway or proxy server) that sits between internal applications and the network. This intermediary inspects application-layer data, identifies sensitive information, and enforces transmission control policies before data leaves the network, thereby bridging the gap between external security and internal data protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If routers are designed to route communications efficiently, then network performance is improved, but data transmission control deteriorates (routers cannot prevent sensitive data transmission)

Engineering Contradiction:
Improvenetwork performanceVSAvoidsensitive data transmission control
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The patent separates routing functions from data inspection functions. Routers continue to handle efficient packet forwarding at lower layers, while a dedicated application-layer inspection system handles sensitive data identification and control. This segmentation maintains network performance while adding data protection capabilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an application-layer intermediary that inspects data content before it is routed outward. This intermediary works in conjunction with existing routers, allowing routers to maintain their efficient routing performance while the intermediary provides the additional layer of sensitive data control.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Loss of information

If application-layer data inspection is implemented to identify sensitive data, then data transmission control is improved, but system complexity increases

Engineering Contradiction:
Improvesensitive data transmission controlVSAvoidsystem complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent implements a universal data inspection framework that can identify multiple types of sensitive data (personal information, financial data, confidential business information) using a single system. This multi-functional approach reduces complexity compared to implementing separate inspection mechanisms for each data type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent uses pattern matching and signature-based identification to detect sensitive data, effectively creating simplified representations (copies) of sensitive data patterns. This allows the system to identify sensitive information without needing to deeply analyze or store the actual data, reducing computational complexity.

Inventive Principle:
Principle #26Copying

4Reliability

If transmission control policies are enforced at the application layer, then data security is improved, but processing overhead increases

Engineering Contradiction:
Improvedata securityVSAvoidprocessing overhead
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-defining sensitive data patterns, classification rules, and transmission control policies before actual data inspection occurs. This preparation work is done once and stored for rapid reference during data inspection, significantly reducing processing overhead during actual transmission control operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies different inspection and control strategies to different types of data and different transmission scenarios. Rather than applying a uniform complex inspection process to all data, the system uses local quality principles to apply appropriate-level inspection based on data type, sensitivity, and destination, reducing overall processing overhead.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS8301771B2Methods, systems, and computer program products for transmission control of sensitive application-layer data
Publication Date: 2012.10.30 DATASPHERE LLC
  • US8301771B2 patent drawing
  • US8301771B2 patent drawing
  • US8301771B2 patent drawing

AI summary

Disclosed are methods, systems, and computer program products for identifying sensitive application-layer data and controlling transmission of the data in a network. According to one method, sensitive data in a system resource is identified at an application layer. A packetization of the identified sensitive data is detected. A flag indicative of the presence of sensitive data is inserted in a packet having at least a portion of the identified sensitive data in response to identifying the sensitive data and detecting the packetization. The flag is inserted in a portion of the packet corresponding to a layer other than the application layer. Transmission of the packet is controlled in a network based on the flag.