Cloud DLP System Using Split Indexing and Forward Hashing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data loss prevention solutions are inadequate for monitoring cloud-based services, particularly in multi-tenant environments, as they struggle to detect and prevent data breaches due to encrypted data flows and lack of control over public network usage, especially with mobile devices.

Innovation Solution

A cloud-based data loss prevention system employing a split computing architecture with a separate indexer and detection system, using forward hashing to create a search index of sensitive data, which is stored remotely in a multi-tenant cloud storage service, allowing for efficient monitoring and compliance with enterprise security policies without interrupting daily operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If on-premises DLP systems are deployed to monitor outgoing network traffic, then data loss prevention capability is improved, but the system cannot monitor cloud service usage due to encrypted data flows and public network usage

Engineering Contradiction:
Improvedata loss prevention capabilityVSAvoidcloud service monitoring capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a cloud-based DLP system as an intermediary between enterprises and cloud service providers. This intermediary system monitors data flows to and from cloud services by implementing agents at the enterprise endpoint and a cloud-based analysis platform that decrypts and analyzes data without requiring on-premises infrastructure. The intermediary approach enables monitoring of encrypted cloud traffic while maintaining enterprise control and compliance.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent transitions from traditional on-premises network monitoring to a multi-dimensional cloud-based monitoring architecture. Instead of monitoring only within the enterprise network boundary, the system operates in the cloud dimension, analyzing data flows after they leave the enterprise network but before they reach public cloud services. This dimensional shift enables monitoring of encrypted traffic without requiring decryption at the enterprise endpoint.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If existing DLP solutions are used to scan computers in the enterprise, then policy compliance is improved, but the solutions do not work well in multi-tenant cloud storage environments

Engineering Contradiction:
Improvepolicy complianceVSAvoidmulti-tenant cloud environment compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal DLP system that functions across multiple environments including on-premises networks, public cloud services, and multi-tenant cloud storage environments. The cloud-based architecture with standardized agents and analysis platforms provides consistent policy enforcement across diverse platforms and storage configurations, making the system adaptable to multi-tenant environments while maintaining compliance requirements.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements a virtualized monitoring approach where the DLP system creates virtual copies of data flows for analysis in the cloud without affecting the actual data transmission. This copying mechanism enables the system to analyze data in multi-tenant cloud environments where physical access to infrastructure is limited, allowing policy compliance monitoring through virtual replication rather than direct hardware intervention.

Inventive Principle:
Principle #26Copying

3Device complexity

If cloud-based services are adopted to eliminate on-premises infrastructure, then device complexity is reduced, but security control and visibility over data flows are lost

Engineering Contradiction:
Improveon-premises infrastructure requirementVSAvoiddata flow visibility
Core Design Contradiction:
Device complexityVSLoss of information

Solution Approach 1:

The patent implements a self-service DLP system where enterprises can configure and manage their own security policies through cloud-based interfaces without requiring complex on-premises infrastructure. The system automatically provisions agents, configures monitoring parameters, and enforces policies based on enterprise-defined requirements. This self-service approach maintains simplicity while preserving visibility through automated cloud-based analysis of data flows.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent establishes continuous feedback loops between the cloud-based DLP system and enterprise users. The system monitors data flows, analyzes potential policy violations, and provides real-time feedback to users about suspicious activities. This feedback mechanism maintains visibility over data flows by continuously reporting back to enterprises about cloud service usage patterns and potential security issues without requiring complex infrastructure.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10498748B1Cloud based data loss prevention system
Publication Date: 2019.12.03 SKYHIGH SECURITY LLC
  • US10498748B1 patent drawing
  • US10498748B1 patent drawing
  • US10498748B1 patent drawing

AI summary

A cloud based data loss prevention (DLP) system implements a split computing architecture using separate indexer system and detection system to perform indexing and data loss prevention monitoring. The cloud DLP system includes a computing system deployed outside of the enterprise data network and including a first computing cluster and a second computing cluster. The first computing cluster includes an indexer system to generate a search index from a pre-index containing hash values of structured data to be protected. The second computing cluster comprises a detection system configured to receive the search index and network data content, to apply a forward hash function based on a key to the network data content, and to detect in the hash values of the network data content for matching data in the search index and to generate an alert in response to matched data content being found in the network data content.