Cloud DLP System Using Split Indexing and Forward Hashing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data loss prevention solutions are inadequate for monitoring cloud-based services, particularly in multi-tenant environments, as they struggle to detect and prevent data breaches due to encrypted data flows and lack of control over public network usage, especially with mobile devices.
Innovation Solution
A cloud-based data loss prevention system employing a split computing architecture with a separate indexer and detection system, using forward hashing to create a search index of sensitive data, which is stored remotely in a multi-tenant cloud storage service, allowing for efficient monitoring and compliance with enterprise security policies without interrupting daily operations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If on-premises DLP systems are deployed to monitor outgoing network traffic, then data loss prevention capability is improved, but the system cannot monitor cloud service usage due to encrypted data flows and public network usage
Solution Approach 1:
The patent introduces a cloud-based DLP system as an intermediary between enterprises and cloud service providers. This intermediary system monitors data flows to and from cloud services by implementing agents at the enterprise endpoint and a cloud-based analysis platform that decrypts and analyzes data without requiring on-premises infrastructure. The intermediary approach enables monitoring of encrypted cloud traffic while maintaining enterprise control and compliance.
Solution Approach 2:
The patent transitions from traditional on-premises network monitoring to a multi-dimensional cloud-based monitoring architecture. Instead of monitoring only within the enterprise network boundary, the system operates in the cloud dimension, analyzing data flows after they leave the enterprise network but before they reach public cloud services. This dimensional shift enables monitoring of encrypted traffic without requiring decryption at the enterprise endpoint.
2Reliability
If existing DLP solutions are used to scan computers in the enterprise, then policy compliance is improved, but the solutions do not work well in multi-tenant cloud storage environments
Solution Approach 1:
The patent creates a universal DLP system that functions across multiple environments including on-premises networks, public cloud services, and multi-tenant cloud storage environments. The cloud-based architecture with standardized agents and analysis platforms provides consistent policy enforcement across diverse platforms and storage configurations, making the system adaptable to multi-tenant environments while maintaining compliance requirements.
Solution Approach 2:
The patent implements a virtualized monitoring approach where the DLP system creates virtual copies of data flows for analysis in the cloud without affecting the actual data transmission. This copying mechanism enables the system to analyze data in multi-tenant cloud environments where physical access to infrastructure is limited, allowing policy compliance monitoring through virtual replication rather than direct hardware intervention.
3Device complexity
If cloud-based services are adopted to eliminate on-premises infrastructure, then device complexity is reduced, but security control and visibility over data flows are lost
Solution Approach 1:
The patent implements a self-service DLP system where enterprises can configure and manage their own security policies through cloud-based interfaces without requiring complex on-premises infrastructure. The system automatically provisions agents, configures monitoring parameters, and enforces policies based on enterprise-defined requirements. This self-service approach maintains simplicity while preserving visibility through automated cloud-based analysis of data flows.
Solution Approach 2:
The patent establishes continuous feedback loops between the cloud-based DLP system and enterprise users. The system monitors data flows, analyzes potential policy violations, and provides real-time feedback to users about suspicious activities. This feedback mechanism maintains visibility over data flows by continuously reporting back to enterprises about cloud service usage patterns and potential security issues without requiring complex infrastructure.
Data Source
AI summary
A cloud based data loss prevention (DLP) system implements a split computing architecture using separate indexer system and detection system to perform indexing and data loss prevention monitoring. The cloud DLP system includes a computing system deployed outside of the enterprise data network and including a first computing cluster and a second computing cluster. The first computing cluster includes an indexer system to generate a search index from a pre-index containing hash values of structured data to be protected. The second computing cluster comprises a detection system configured to receive the search index and network data content, to apply a forward hash function based on a key to the network data content, and to detect in the hash values of the network data content for matching data in the search index and to generate an alert in response to matched data content being found in the network data content.


