Cloud Document Threat Detection and Redaction System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud-based storage services lack effective mechanisms to identify and protect personal threat data, such as social security numbers and credit card numbers, from unauthorized access, especially since users often share documents without encryption, exposing sensitive information to hackers.

Innovation Solution

A threat detection system that scans documents stored in cloud-based services for personal threat data, using APIs and scanners to identify and redact sensitive information without storing it, presenting the results through a Web-based interface, allowing users to access and edit documents to remove threats without logging into the storage service.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If documents are shared via cloud-based storage services with local synchronization, then universal access and collaboration are improved, but security against unauthorized access and data breaches deteriorates

Engineering Contradiction:
Improveuniversal accessVSAvoidunauthorized access
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary scanning of documents stored in cloud-based services to identify personal threat data before it can be accessed by unauthorized users. The scanner proactively detects sensitive information such as social security numbers, credit card numbers, and other personally identifiable information, allowing users to take preventive action before data breaches occur.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary threat detection system that sits between the cloud storage service and the user's local access. This intermediary scanner acts as a security layer that monitors and identifies sensitive data in shared documents without interfering with the universal access functionality, thereby mediating between collaboration needs and security concerns.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If users share documents without encryption for ease of access, then ease of operation is improved, but security and protection of sensitive information deteriorates

Engineering Contradiction:
Improveease of accessVSAvoidexposure to hackers
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The threat detection system operates autonomously to scan and identify personal threat data in shared documents without requiring user intervention. The scanner automatically processes documents, detects sensitive information, and provides notifications to users, enabling them to take protective actions without needing to manually encrypt or review each document.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual encryption mechanisms with an automated threat detection and notification system. Instead of requiring users to manually encrypt documents before sharing, the system uses automated scanning and pattern recognition to identify sensitive data and alert users to potential security risks.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Productivity

If cloud-based storage services are used for document sharing, then productivity and collaboration are improved, but the ability to detect and control personal threat data deteriorates

Engineering Contradiction:
Improvecollaboration efficiencyVSAvoiddetection of personal threat data
Core Design Contradiction:
ProductivityVSDifficulty of detecting and measuring

Solution Approach 1:

The threat detection system is designed to work with multiple cloud-based storage services and various document formats simultaneously. The scanner can identify personal threat data across different platforms and file types, providing universal protection that maintains collaboration efficiency while detecting sensitive information regardless of the specific cloud service or document format being used.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system changes the detection parameters by using pattern recognition and regular expressions to identify personal threat data based on specific formats and characteristics. By transforming the detection approach from manual review to automated pattern matching, the system makes it easier to detect and control sensitive information in cloud-based documents.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10726154B2Detecting personal threat data in documents stored in the cloud
Publication Date: 2020.07.28 ONEHUB
  • US10726154B2 patent drawing
  • US10726154B2 patent drawing
  • US10726154B2 patent drawing

AI summary

Methods, systems, and software for identifying threat data in documents stored in cloud-based storage services. A service is provided that enables users who store documents on cloud-based storage services to have their documents scanned for threat data comprising personal and/or confidential data such as social security numbers, credit card numbers, e-mail addresses, and phone numbers. The documents are streamed from the storage services and scanned to detect one or more types of personal threat data. The detected personal threat data are then presented to users in redacted form. Detecting and presentation of personal threat data is performed in a manner under which threat data is never stored in non-volatile storage in an un-redacted form. A Web service seamlessly enables users to request their documents to be scanned for personal threat data, view detected personal threat data in redacted forms, and access documents identified as containing personal threat data.