Automated Content Protection Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data protection methods are often manual and inefficient, lacking automated mechanisms to enforce usage policies across systems and networks, which can lead to unprotected data transfer and misuse.

Innovation Solution

Implementing a system that monitors content transfer through pre-defined policy application points, accesses content classification rules, and automatically applies usage policies based on content, classification rules, and system state, ensuring transparent and secure data protection without user interaction.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If manual data protection methods are used (users manually determine and protect content), then users have control over their content, but the process is inefficient and time-consuming

Engineering Contradiction:
Improvedata protection efficiencyVSAvoidautomatic policy application
Core Design Contradiction:
ProductivityVSExtent of automation

Solution Approach 1:

The system enables self-service by automatically monitoring content transfer through policy application points, classifying content based on pre-defined rules, and applying appropriate usage policies without requiring user intervention. The enforcement mechanism autonomously protects content by evaluating classification rules and system state, eliminating the need for manual user determination while maintaining control.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements preliminary action by pre-defining content classification rules and usage policies before content transfer occurs. The enforcement mechanism has pre-established criteria for identifying protected content and predetermined policies to apply, enabling automatic and consistent protection decisions without requiring real-time user input or manual policy selection.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If no automated enforcement mechanism is implemented, then system complexity is low, but data protection reliability is compromised

Engineering Contradiction:
Improvedata protection enforcementVSAvoidpolicy enforcement system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The enforcement mechanism serves as an intermediary between content transfer operations and usage policy application. It monitors content passing through policy application points, evaluates classification rules, and automatically applies appropriate policies. This intermediary layer ensures reliable enforcement of data protection without requiring complex user-facing interfaces or manual intervention systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments the data protection process into distinct functional components: content monitoring at policy application points, classification rule evaluation, system state assessment, and policy application. This segmentation allows each component to perform its specific function independently, improving reliability through modular design while managing overall system complexity through clear separation of concerns.

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If content classification rules are maintained in a centralized repository, then any enforcement mechanism can access the rules, but system complexity increases

Engineering Contradiction:
Improvepolicy access flexibilityVSAvoidrule repository infrastructure
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The centralized repository provides universal access to content classification rules for any enforcement mechanism in the system. Multiple enforcement mechanisms can retrieve and apply the same classification rules and usage policies, enabling consistent data protection across different locations and contexts. This multi-functional approach allows a single repository to serve numerous enforcement points, improving adaptability while avoiding duplication of rule storage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS7987496B2Automatic application of information protection policies
Publication Date: 2011.07.26 MICROSOFT TECHNOLOGY LICENSING LLC
  • US7987496B2 patent drawing
  • US7987496B2 patent drawing
  • US7987496B2 patent drawing

AI summary

The secure application of content protection policies to content. The secure application of content protection polices is accomplished by having an enforcement mechanism monitor policy application points to detect the transfer of content. The enforcement mechanism accesses the content and a determination is made to protect the content. A usage policy is then identified by the enforcement mechanism to apply to the content and the usage policy is then applied to the content, resulting in a usage policy for the content.