Cloud Platform for Securing Organizational Assets on Private Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current information security and data protection systems are inadequate for managing mixed-use devices used by transient employees and consultants, as they lack support for private devices, depend on network services, and are costly to deploy and manage, leading to unsecured access and usage of organizational assets outside the network perimeter.

Innovation Solution

A platform that transparently isolates and governs secured organizational assets on private devices by employing data-type and origin-based classification, encryption, and monitoring, creating a 'virtual Chinese wall' to maintain security and compliance without burdening the endpoint with extensive software stacks or resource usage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional information security systems are deployed to protect organizational assets, then data security is improved, but device complexity and deployment cost increase significantly

Engineering Contradiction:
Improvedata securityVSAvoidsoftware stack complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the security governance function from the endpoint device and relocates it to the cloud platform. The endpoint agent becomes minimal, while the complex security policies, classification rules, and monitoring logic reside in the cloud, reducing endpoint complexity while maintaining security effectiveness.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a cloud-based platform as an intermediary between organizational assets and private devices. This platform mediates security governance, asset classification, and compliance monitoring, eliminating the need for complex local security infrastructure on endpoint devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If comprehensive security monitoring is implemented on private devices, then data protection is improved, but user privacy and productivity are compromised

Engineering Contradiction:
Improvedata protectionVSAvoiduser privacy and productivity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies different levels of monitoring and governance to different data types and locations. Organizational assets receive strict security governance and monitoring, while personal data on the same device is left untouched, allowing users to maintain privacy and productivity for personal activities while ensuring security for organizational assets.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent segments the computing environment into organizational asset spaces and personal spaces. Security monitoring is applied selectively to organizational assets through cloud-based tracking of file access, modification, and sharing events, while personal data remains outside the monitoring scope, preserving user privacy and productivity.

Inventive Principle:
Principle #1Segmentation

3Reliability

If network-based security systems are used, then security control is improved, but accessibility to organizational assets from remote devices is restricted

Engineering Contradiction:
Improvesecurity controlVSAvoiddevice accessibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal cloud-based platform that can govern organizational assets across multiple device types and operating systems. The endpoint agent is designed to be lightweight and compatible with various platforms (Windows, macOS, Linux, mobile), enabling broad device accessibility while maintaining consistent security control through cloud-based policies.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The cloud platform acts as an intermediary that enables secure access to organizational assets from any device. Instead of requiring devices to connect to the corporate network, the platform mediates access requests, enforcing security policies while allowing remote and private device access to organizational assets.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If extensive security software is deployed on endpoints, then security monitoring is improved, but system resources and performance are consumed

Engineering Contradiction:
Improvesecurity monitoringVSAvoidendpoint system resources
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts complex security monitoring and analysis functions from the endpoint device and relocates them to the cloud platform. The endpoint agent performs only lightweight functions such as file metadata collection and event reporting, while the cloud platform handles sophisticated analysis, classification, and threat detection, significantly reducing endpoint resource consumption.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements partial monitoring at the endpoint level, focusing only on essential security events and file metadata. Comprehensive security analysis, classification, and response actions are performed partially or excessively in the cloud, allowing the endpoint to maintain minimal resource usage while still achieving thorough security monitoring through cloud-based processing.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11336628B2Methods and systems for securing organizational assets in a shared computing environment
Publication Date: 2022.05.17 ACTIFILE LTD
  • US11336628B2 patent drawing
  • US11336628B2 patent drawing
  • US11336628B2 patent drawing

AI summary

Embodiments of the present disclosure provide methods and systems that configured to, generally, and in no particular order, perform one or more of the following functions: distinguish and identify secured assets that are permitted to an end-point to employ within a shared computing environment; monitor the end-point for certain triggering events, such as data creation, reception, manipulation, storage, or extraction associated with a secured asset; upon detection of a triggering event, monitor at least one unsecured container in order to determine if at least a portion of the secured asset has been otherwise transferred to an unsecured container; and encrypt the unsecured container in order to secure the otherwise unsecured asset.