Confidential Data Protection via Usage Scoping and Website Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods are ineffective in preventing the transmission of confidential information to illicit destinations during phishing attacks, as they lack the ability to automatically adjust protection levels based on the usage of such information and fail to recognize attempted transmissions in real-time.

Innovation Solution

A method that monitors data transmissions, identifies confidential information, categorizes it based on usage scope, examines the website characteristics, and compares them to ensure secure transmission, using a white-list and black-list system to alert users of potential threats and adjust protection protocols accordingly.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If current email authentication techniques and user notification systems are used, then user awareness of confidential data transmission is improved, but phishing attacks still succeed because users believe they are transmitting to reputable websites

Engineering Contradiction:
Improveconfidential information protectionVSAvoiduser trust in transmission destination
Core Design Contradiction:
Loss of informationVSReliability

Solution Approach 1:

The system performs preliminary analysis of the destination website's characteristics and compares them against the expected profile before allowing confidential information transmission. This pre-verification prevents phishing attacks by blocking transmissions to fraudulent sites before the user completes the action, rather than relying on post-hoc user notification.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system introduces an intermediary verification layer between the user and the destination website. This intermediary automatically validates the website's authenticity by examining its characteristics and comparing them against expected profiles, eliminating the need for users to manually verify website legitimacy.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If manual user verification is required for confidential data transmission, then security control is improved, but user convenience deteriorates and phishing users can circumvent by believing the site is legitimate

Engineering Contradiction:
Improvesecurity controlVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs automatic verification of destination website characteristics without requiring user intervention. The system self-evaluates whether the transmission destination matches the expected profile for the type of confidential information being sent, eliminating manual user verification while maintaining security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system provides automatic feedback to the user about the safety of the transmission destination based on its analysis of website characteristics. This feedback mechanism allows the system to maintain security controls while improving user convenience by eliminating the need for manual verification steps.

Inventive Principle:
Principle #23Feedback

3Reliability

If uniform protection protocols are applied to all confidential information, then security consistency is improved, but adaptability to different usage scenarios deteriorates

Engineering Contradiction:
Improvesecurity consistencyVSAvoidprotection level adjustment
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system applies different protection protocols and verification strictness levels based on the specific type of confidential information being transmitted and the characteristics of the destination website. For example, financial data may require more stringent verification than other types of confidential information, allowing tailored security measures for different usage scenarios.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically adjusts the level of protection and verification required based on real-time analysis of the transmission context, including the type of confidential information, the destination website's characteristics, and the expected usage pattern. This allows the system to adapt security measures to match the specific risks and requirements of each transmission scenario.

Inventive Principle:
Principle #15Dynamics

4Measurement precision

If real-time monitoring and analysis of data transmissions are implemented, then detection of phishing attempts is improved, but system complexity and processing time increase

Engineering Contradiction:
Improvephishing detection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments the phishing detection process into distinct modules: monitoring data transmissions, identifying confidential information, analyzing destination website characteristics, comparing against expected profiles, and making blocking decisions. This segmentation allows each module to be optimized independently and reduces overall system complexity by dividing the complex task into manageable components.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system changes key parameters such as the strictness of verification, the types of website characteristics analyzed, and the threshold for blocking transmissions based on the specific context of each data transmission. This allows the system to maintain high detection accuracy while reducing processing time and complexity by adjusting parameters to match the risk level of each scenario.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS7818809B1Confidential data protection through usage scoping
Publication Date: 2010.10.19 GEN DIGITAL INC
  • US7818809B1 patent drawing
  • US7818809B1 patent drawing
  • US7818809B1 patent drawing

AI summary

Methods, apparatuses, and computer-readable media for protecting confidential data on a network. An embodiment of the inventive method comprises the steps of: monitoring 110 data directed to a website; identifying 120 a data string having at least one confidential characteristic; categorizing the data string with a categorization level; examining 140 the website for at least one characteristic consistent with confidential data; creating 155 a website characteristic profile; comparing 170 the website characteristic profile with the data string's categorization level for compatibility; and determining 180 whether the data string can be communicated to the website.