Conditional Information Barriers for Cloud Data Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data protection solutions in cloud environments lack flexibility, often requiring an 'all or nothing' approach to information barriers, which is inadequate for managing sensitive information transmission between accounts or groups, and struggle to effectively identify sensitive data as enterprise data migrates to cloud storage.

Innovation Solution

Implementing a nuanced information barrier policy that allows selective communication based on content classification, with on-premises heuristic analysis and off-premises data matching services to identify sensitive information, and configuring static segments and policies for efficient execution, ensuring secure data transfer and access control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If an all or nothing approach to information barriers is used, then implementation is simple, but flexibility in managing sensitive information transmission is lost

Engineering Contradiction:
Improveimplementation simplicityVSAvoidflexibility in managing sensitive information
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The information barrier system segments communication control into granular policies that can be applied selectively to different accounts, groups, and content types. Instead of a monolithic all-or-nothing barrier, the system divides communication rules into manageable segments that allow flexible control over sensitive information transmission while maintaining simplicity through automated policy enforcement.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If cloud-based data storage is used, then data accessibility is improved, but effective identification of sensitive enterprise data becomes difficult

Engineering Contradiction:
Improvedata accessibilityVSAvoididentification of sensitive enterprise data
Core Design Contradiction:
Ease of operationVSDifficulty of detecting and measuring

Solution Approach 1:

The system introduces an intermediary data matching service that acts as a mediator between cloud storage and the information barrier enforcement point. This intermediary service receives data samples, compares them against enterprise data stores, and provides classification results back to the barrier system, enabling effective sensitive data identification in cloud environments without compromising data accessibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If selective communication based on content classification is implemented, then data protection flexibility is improved, but system complexity increases

Engineering Contradiction:
Improvedata protection flexibilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The information barrier system implements self-service through automated policy evaluation and enforcement. When data transmission is intercepted, the system automatically classifies the content, determines the applicable barrier policy, and enforces the decision without manual intervention. This self-service mechanism handles the complexity internally while presenting a simple, flexible interface for data protection management.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11341271B2Information barriers for sensitive information
Publication Date: 2022.05.24 MICROSOFT TECHNOLOGY LICENSING LLC
  • US11341271B2 patent drawing
  • US11341271B2 patent drawing
  • US11341271B2 patent drawing

AI summary

Disclosed are embodiments for information barriers that are conditional on the type of information being communicated. Information barrier polices provided by the disclosed embodiments selectively allow communication between accounts or groups based on characteristics of the content of the communication. For example, communication between a marketing department and an engineering department may be conditional on the communication not including any sensitive information. The determination of whether the communication includes sensitive information is further designed to provide good performance even in environments that maintain substantial portions of data in an offsite or cloud environment, where latencies associated with searching large datastores can be prohibitive.