Browser Extension for Sensitive Content Redaction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cloud services and network resources lack comprehensive security controls to restrict access to sensitive content based on user location and do not automatically detect or hide sensitive information, requiring manual configuration and potentially exposing organizations to security risks.

Innovation Solution

A method and device configuration that detects sensitive information in content accessed by a client device or gateway, using user profiles and context analysis, with machine learning models to modify content and restrict access accordingly, ensuring security policies are enforced across various network environments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If cloud services provide basic security controls for restricting access to content, then access control functionality is provided, but the security controls are not co-extensive or compatible with the full range of security policies required by organizations

Engineering Contradiction:
Improvesecurity policy compatibilityVSAvoidsecurity control effectiveness
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a browser extension as an intermediary component between the cloud service and the user's browser. This extension acts as a mediator that implements organization-specific security policies by detecting sensitive content and modifying it before transmission to the cloud service, thereby bridging the gap between basic cloud security controls and comprehensive organizational security requirements

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the security control functionality into multiple independent components: the browser extension that detects and modifies content, the cloud service that stores and serves content, and the policy configuration system that defines security rules. This segmentation allows each component to specialize in specific security tasks, improving overall adaptability and reliability

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If cloud storage service restricts access to entire documents, then security control is simplified, but the ability to provide access to non-sensitive portions while hiding sensitive information is lost

Engineering Contradiction:
Improveaccess control simplicityVSAvoidinformation accessibility
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent applies local quality by enabling differential security treatment of different portions of the same document. The browser extension analyzes content to identify sensitive portions and applies security controls only to those specific sections, while leaving non-sensitive portions accessible. This allows granular control where each portion of the document has its own access characteristics based on sensitivity

Inventive Principle:
Principle #3Local quality

3Measurement precision

If cloud services require manual configuration of security controls for individual documents, then security control precision is improved, but the complexity and time required for configuration increases

Engineering Contradiction:
Improvesecurity control precisionVSAvoidconfiguration complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent implements self-service by enabling the browser extension to automatically detect sensitive content in documents and apply appropriate security controls without requiring manual configuration. The extension uses machine learning models to identify sensitive information and automatically redacts or protects it, allowing the system to configure itself based on the content being accessed

Inventive Principle:
Principle #25Self-service

4Device complexity

If cloud services do not automatically detect sensitive content, then system complexity is reduced, but security risks increase due to manual configuration requirements

Engineering Contradiction:
Improvesystem complexityVSAvoidsecurity risk
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by having the browser extension detect and redact sensitive content from documents before they are uploaded to or accessed from the cloud service. This proactive approach prevents sensitive information from being exposed in the first place, eliminating security risks associated with manual configuration and reducing the need for complex post-upload security measures

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11539709B2Restricted access to sensitive content
Publication Date: 2022.12.27 CITRIX SYSTEMS INC
  • US11539709B2 patent drawing
  • US11539709B2 patent drawing
  • US11539709B2 patent drawing

AI summary

In one aspect, the present disclosure relates to a method including: receiving, by a client device, a request to access content stored on a remote server; determining, by the client device, that the requested content includes sensitive information based on a user profile associated with the client device; modifying, by the client device, the requested content in response to the determination that the content includes sensitive information; and providing, by client device, access to the modified content in place of the requested content that includes the sensitive information.