Conditional Information Barriers for Cloud Data Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data protection solutions in cloud environments lack flexibility, often requiring an 'all or nothing' approach to information barriers, which is inadequate for managing sensitive information transmission between accounts or groups, and struggle to effectively identify sensitive data as enterprise data migrates to cloud storage.
Innovation Solution
Implementing a nuanced information barrier policy that allows selective communication based on content classification, with on-premises heuristic analysis and off-premises data matching services to identify sensitive information, and configuring static segments and policies for efficient execution, ensuring secure data transfer and access control.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If an all or nothing approach to information barriers is used, then implementation is simple, but flexibility in managing sensitive information transmission is lost
Solution Approach 1:
The information barrier system segments communication control into granular policies that can be applied selectively to different accounts, groups, and content types. Instead of a monolithic all-or-nothing barrier, the system divides communication rules into manageable segments that allow flexible control over sensitive information transmission while maintaining simplicity through automated policy enforcement.
2Ease of operation
If cloud-based data storage is used, then data accessibility is improved, but effective identification of sensitive enterprise data becomes difficult
Solution Approach 1:
The system introduces an intermediary data matching service that acts as a mediator between cloud storage and the information barrier enforcement point. This intermediary service receives data samples, compares them against enterprise data stores, and provides classification results back to the barrier system, enabling effective sensitive data identification in cloud environments without compromising data accessibility.
3Adaptability or versatility
If selective communication based on content classification is implemented, then data protection flexibility is improved, but system complexity increases
Solution Approach 1:
The information barrier system implements self-service through automated policy evaluation and enforcement. When data transmission is intercepted, the system automatically classifies the content, determines the applicable barrier policy, and enforces the decision without manual intervention. This self-service mechanism handles the complexity internally while presenting a simple, flexible interface for data protection management.
Data Source
AI summary
Disclosed are embodiments for information barriers that are conditional on the type of information being communicated. Information barrier polices provided by the disclosed embodiments selectively allow communication between accounts or groups based on characteristics of the content of the communication. For example, communication between a marketing department and an engineering department may be conditional on the communication not including any sensitive information. The determination of whether the communication includes sensitive information is further designed to provide good performance even in environments that maintain substantial portions of data in an offsite or cloud environment, where latencies associated with searching large datastores can be prohibitive.


