Cloud Platform for Securing Organizational Assets on Private Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current information security and data protection systems are inadequate for managing mixed-use devices used by transient employees and consultants, as they lack support for private devices, depend on network services, and are costly to deploy and manage, leading to unsecured access and usage of organizational assets outside the network perimeter.
Innovation Solution
A platform that transparently isolates and governs secured organizational assets on private devices by employing data-type and origin-based classification, encryption, and monitoring, creating a 'virtual Chinese wall' to maintain security and compliance without burdening the endpoint with extensive software stacks or resource usage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional information security systems are deployed to protect organizational assets, then data security is improved, but device complexity and deployment cost increase significantly
Solution Approach 1:
The patent extracts the security governance function from the endpoint device and relocates it to the cloud platform. The endpoint agent becomes minimal, while the complex security policies, classification rules, and monitoring logic reside in the cloud, reducing endpoint complexity while maintaining security effectiveness.
Solution Approach 2:
The patent introduces a cloud-based platform as an intermediary between organizational assets and private devices. This platform mediates security governance, asset classification, and compliance monitoring, eliminating the need for complex local security infrastructure on endpoint devices.
2Reliability
If comprehensive security monitoring is implemented on private devices, then data protection is improved, but user privacy and productivity are compromised
Solution Approach 1:
The patent applies different levels of monitoring and governance to different data types and locations. Organizational assets receive strict security governance and monitoring, while personal data on the same device is left untouched, allowing users to maintain privacy and productivity for personal activities while ensuring security for organizational assets.
Solution Approach 2:
The patent segments the computing environment into organizational asset spaces and personal spaces. Security monitoring is applied selectively to organizational assets through cloud-based tracking of file access, modification, and sharing events, while personal data remains outside the monitoring scope, preserving user privacy and productivity.
3Reliability
If network-based security systems are used, then security control is improved, but accessibility to organizational assets from remote devices is restricted
Solution Approach 1:
The patent creates a universal cloud-based platform that can govern organizational assets across multiple device types and operating systems. The endpoint agent is designed to be lightweight and compatible with various platforms (Windows, macOS, Linux, mobile), enabling broad device accessibility while maintaining consistent security control through cloud-based policies.
Solution Approach 2:
The cloud platform acts as an intermediary that enables secure access to organizational assets from any device. Instead of requiring devices to connect to the corporate network, the platform mediates access requests, enforcing security policies while allowing remote and private device access to organizational assets.
4Reliability
If extensive security software is deployed on endpoints, then security monitoring is improved, but system resources and performance are consumed
Solution Approach 1:
The patent extracts complex security monitoring and analysis functions from the endpoint device and relocates them to the cloud platform. The endpoint agent performs only lightweight functions such as file metadata collection and event reporting, while the cloud platform handles sophisticated analysis, classification, and threat detection, significantly reducing endpoint resource consumption.
Solution Approach 2:
The patent implements partial monitoring at the endpoint level, focusing only on essential security events and file metadata. Comprehensive security analysis, classification, and response actions are performed partially or excessively in the cloud, allowing the endpoint to maintain minimal resource usage while still achieving thorough security monitoring through cloud-based processing.
Data Source
AI summary
Embodiments of the present disclosure provide methods and systems that configured to, generally, and in no particular order, perform one or more of the following functions: distinguish and identify secured assets that are permitted to an end-point to employ within a shared computing environment; monitor the end-point for certain triggering events, such as data creation, reception, manipulation, storage, or extraction associated with a secured asset; upon detection of a triggering event, monitor at least one unsecured container in order to determine if at least a portion of the secured asset has been otherwise transferred to an unsecured container; and encrypt the unsecured container in order to secure the otherwise unsecured asset.


