Compliance Controller for Secure Cross-Network File Exchange

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional systems lack the ability to control and monitor data access and movement when network devices exchange files across different networks, leading to vulnerabilities in data leakage and unauthorized access.

Innovation Solution

A system employing a compliance controller and virtual machine to monitor and control file access, ensuring that files exchanged between networks comply with set compliance rules, thereby preventing unauthorized data transfer.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If full permission is given to network devices to exchange files across networks, then file exchange capability is improved, but data security and control over data access deteriorates

Engineering Contradiction:
Improvefile exchange capabilityVSAvoiddata security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a compliance controller as an intermediary component between network devices that enables file exchange while maintaining security control. The compliance controller mediates data access by evaluating compliance rules before allowing file transfers, thus resolving the contradiction between enabling file exchange and maintaining data security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the data access control function by introducing a compliance controller that operates independently from the network devices. This segmentation allows the system to maintain full file exchange capability while separately enforcing security policies through the compliance controller's compliance rule evaluation mechanism.

Inventive Principle:
Principle #1Segmentation

2Device complexity

If conventional all-or-nothing access control is used, then system simplicity is maintained, but flexibility in controlling data access deteriorates

Engineering Contradiction:
Improveaccess control system simplicityVSAvoidflexibility in data access control
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic access control by allowing the compliance controller to evaluate compliance rules and make real-time decisions about data access. This dynamic mechanism provides flexibility in controlling data access while maintaining relative system simplicity through automated rule-based decision-making.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent enables flexible data access control by allowing dynamic changes in access parameters through compliance rules. The system can modify access permissions based on varying conditions and policies, providing adaptability without requiring complex manual configuration of each access scenario.

Inventive Principle:
Principle #35Parameter changes

3Productivity

If network devices are given full permission to exchange data, then data exchange efficiency is improved, but ability to monitor and control data movement deteriorates

Engineering Contradiction:
Improvedata exchange efficiencyVSAvoiddata movement monitoring capability
Core Design Contradiction:
ProductivityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent implements feedback mechanisms through the compliance controller that monitors and evaluates data access requests in real-time. The system provides feedback by evaluating compliance rules and controlling data movement based on monitored conditions, thus maintaining data exchange efficiency while enabling monitoring and control capabilities.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10965677B2Data leakage and information security using access control
Publication Date: 2021.03.30 BANK OF AMERICA CORP
  • US10965677B2 patent drawing
  • US10965677B2 patent drawing
  • US10965677B2 patent drawing

AI summary

A system that includes a first network device in a first network configured to send a file from a plurality of files to a compliance controller in the first network. The compliance controller is configured to determine whether the file satisfies a set of compliance rules and to send the file to the virtual machine in the first network in response to determining that the file satisfies the set of compliance rules. The virtual machine is configured to send the file to a second network device in a second network via a network interface. The network interface is configured to block the first network device from sending the file from the first memory to the second network device in the second network. The network interface is also configured to send the file from the virtual machine to the second network device in the second network.