Cloud-Native DLP via CASB Fingerprinting

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security enforcement points are limited in their ability to dynamically fingerprint files in cloud-native services, making data loss prevention (DLP) less effective and scalable as organizations increasingly store sensitive files in cloud environments.

Innovation Solution

A security enforcement point is enabled to obtain and utilize DLP fingerprints generated based on files stored in cloud-native services, allowing for dynamic monitoring and protection of sensitive data across cloud storage locations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional DLP fingerprinting methods are used with on-premises file shares, then DLP can effectively monitor and protect sensitive data, but the system cannot dynamically fingerprint files stored in cloud-native services

Engineering Contradiction:
Improveability to fingerprint cloud-native filesVSAvoidDLP effectiveness
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a cloud access security broker (CASB) as an intermediary component that bridges the security enforcement point and cloud-native services. The CASB dynamically generates DLP fingerprints for files stored in cloud environments and delivers them to the security enforcement point, enabling the system to monitor and protect cloud-based sensitive data without compromising DLP effectiveness

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system architecture is segmented into distinct functional components: the security enforcement point that performs DLP scanning, the CASB that generates and manages cloud file fingerprints, and the cloud-native services that store files. This segmentation allows each component to specialize in its function, with the CASB handling the complexity of cloud file access and fingerprint generation while the security enforcement point focuses on DLP policy enforcement

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If organizations migrate sensitive files to cloud-native services, then data accessibility and collaboration improve, but existing security enforcement points cannot dynamically monitor these files

Engineering Contradiction:
Improvedata accessibilityVSAvoidfile monitoring capability
Core Design Contradiction:
Ease of operationVSDifficulty of detecting and measuring

Solution Approach 1:

The system implements a feedback mechanism where the CASB continuously monitors changes in cloud-native file storage and dynamically updates DLP fingerprints in real-time. When files are added, modified, or deleted in cloud environments, the CASB detects these changes and promptly delivers updated fingerprints to the security enforcement point, ensuring continuous monitoring capability without hindering data accessibility

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The CASB proactively generates and pre-delivers DLP fingerprints for files before they are accessed or transmitted. By establishing the fingerprint database in advance and maintaining it through continuous synchronization with cloud storage changes, the system ensures that security enforcement points can immediately detect and block sensitive data exfiltration without delay

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250184360A1Performing fingerprint-based data loss prevention (DLP) using information obtained from cloud-native services
Publication Date: 2025.06.05 FORTINET INC
  • US20250184360A1 patent drawing
  • US20250184360A1 patent drawing
  • US20250184360A1 patent drawing

AI summary

Systems and methods for performing fingerprint-based data loss prevention (DLP) using information obtained from a cloud-native service are provided. In one example, DLP fingerprints are obtained by a security enforcement system (e.g., a network security appliance, a secure access service edge (SASE) platform, or a security service edge (SSE)). The DLP fingerprints may be generated locally by the security enforcement system or generated remotely from the security service edge based on a set of files stored in a cloud-native service, representing, for example, infrastructure-as-a-service (IaaS) (e.g., an object storage service) or Software-as-a-service (SaaS) (e.g., a file hosting service or a productivity platform). Based at least in part on the DLP fingerprints, DLP is performed on a file by a DLP service of the security enforcement system, in which the file is at rest on an endpoint protected by the security enforcement system or in transit through the security enforcement point.