Clearance-Based Data Masking and Watermarking for Secure Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increased vulnerability of communications networks to cyberattacks due to the use of personal devices (BYOD) and the complexity of protecting enterprise data in cloud environments compounds the difficulty in maintaining confidentiality and integrity of industrial and business operations.

Innovation Solution

A CyberSafe system with a cloud-based data and processing security hub and a secure web browser (SWB) in an isolated environment (CISE) monitors and controls data movement, enforces security policies, and provides high-resolution visibility to protect against cyber damage and data leakage by vetting information content, masking or deleting portions of data, and watermarking based on user clearance levels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If personal devices (BYOD) are used to access enterprise resources, then accessibility and flexibility are improved, but vulnerability to cyberattacks and data leakage increases

Engineering Contradiction:
ImproveaccessibilityVSAvoidcyberattack vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a secure web browser (SWB) as an intermediary between the user device and enterprise resources. The SWB runs in an isolated container environment that mediates all communications, preventing direct access to the device's operating system and other applications. This intermediary layer allows BYOD accessibility while protecting against cyberattacks by blocking malicious code execution and data exfiltration attempts.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the device environment into isolated containers: a secure web browser container for accessing enterprise resources and the native operating system for personal use. This segmentation ensures that even if the personal OS is compromised, the enterprise resources remain protected in the isolated SWB container, resolving the contradiction between accessibility and security.

Inventive Principle:
Principle #1Segmentation

2Loss of information

If cloud-based digital resources are made widely accessible, then information availability is improved, but complexity of protecting data confidentiality and integrity increases

Engineering Contradiction:
Improveinformation availabilityVSAvoidprotection complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The secure web browser acts as an intermediary that simplifies protection complexity by centralizing security controls in one location. Rather than securing multiple access points across the cloud infrastructure, the SWB enforces security policies, monitors data movements, and prevents unauthorized access at the client endpoint, making protection manageable despite widespread cloud resource accessibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements continuous monitoring and feedback mechanisms within the SWB that track data movements, user actions, and potential security threats. This real-time feedback allows the system to dynamically adjust security measures, block suspicious activities, and maintain data confidentiality without requiring complex manual intervention, thus resolving the contradiction between information availability and protection complexity.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If remote work is enabled using personal devices, then operational flexibility is improved, but difficulty in maintaining security policies increases

Engineering Contradiction:
Improveoperational flexibilityVSAvoidsecurity policy enforcement difficulty
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic security policy enforcement within the secure web browser that adapts to different contexts. The SWB can dynamically adjust security measures based on the user's location, device state, and risk assessment, allowing remote work flexibility while automatically maintaining appropriate security policies without requiring complex manual configuration for each remote scenario.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12531862B2Partial masking, deleting, and watermarking of resources based on confidentiality and clearance levels
Publication Date: 2026.01.20 PALO ALTO NETWORKS INC
  • US12531862B2 patent drawing
  • US12531862B2 patent drawing
  • US12531862B2 patent drawing

AI summary

Based on a user request to access a resource, confidentiality scores for data of various data types associated with the resource are determined. Using these confidentiality scores and clearance scores for a corresponding user, for each of the data types, first and second criteria are applied for each data type and corresponding clearance score and confidentiality level. The first criteria is whether a difference between a figure of merit for the clearance score and a figure of merit for the confidentiality score is above a threshold and the second criteria is whether a difference between the clearance score and the confidentiality score is above a separate threshold. If any of the first criteria are satisfied for a data type, the request is blocked, whereas if any of the second criteria are satisfied for a data type, corresponding data for the resource is masked, watermarked, or deleted.