Context-Aware Data Protection via Dynamic Policy Adjustment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data security methods are static and unable to account for access contexts, leading to infrequent and manual policy changes that do not dynamically adjust security measures in response to changing access conditions, thus failing to provide real-time data protection.

Innovation Solution

A context-aware data protection system that identifies access contexts and changes, dynamically adjusting security policies and rules to manage access and manipulate data in real-time without requiring code changes or interrupting operations, by separating policy enforcement from applications and repositories.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If static security policies are used in prior art systems, then system simplicity is maintained, but real-time data protection capability is lost

Engineering Contradiction:
Improvedata protection capabilityVSAvoiddynamic policy adjustment
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic security policies that automatically adjust based on access context changes. The system monitors access contexts in real-time and modifies security rules dynamically without requiring manual intervention, transforming static security into a dynamic, adaptive system that responds to changing conditions.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system incorporates feedback mechanisms by continuously monitoring access contexts and using this information to automatically adjust security policies. The policy management application receives feedback about access conditions and modifies rules accordingly, creating a closed-loop system that adapts to changing security requirements.

Inventive Principle:
Principle #23Feedback

2Reliability

If manual policy changes are implemented, then policy control is maintained, but real-time responsiveness is lost

Engineering Contradiction:
Improvesecurity controlVSAvoidpolicy update delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables self-service by automatically detecting access context changes and adjusting security policies without requiring manual administrator intervention. The policy management application autonomously monitors conditions and implements policy changes, eliminating the time delay associated with manual policy updates while maintaining security control.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary actions by pre-configuring the policy management application to automatically respond to specific access context changes. Security rules are prepared in advance with defined triggers, enabling immediate automated response when conditions are met, thus eliminating manual response time delays.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If security policies are embedded in applications and repositories, then enforcement is direct, but system flexibility is reduced

Engineering Contradiction:
Improvepolicy enforcementVSAvoidpolicy management flexibility
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent extracts security policy management from individual applications and repositories, centralizing it in a dedicated policy management application. This separation allows policies to be defined and modified centrally without requiring code changes in applications or repositories, enhancing flexibility while maintaining direct enforcement through the centralized policy management system.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The policy management application serves as an intermediary between security requirements and applications/repositories. It receives access requests, evaluates them against current policies, and enforces decisions without requiring security logic to be embedded in applications or repositories, thus maintaining enforcement effectiveness while improving flexibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9767301B2Context aware data protection
Publication Date: 2017.09.19 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US9767301B2 patent drawing
  • US9767301B2 patent drawing
  • US9767301B2 patent drawing

AI summary

A method, system, and computer usable program product-for context aware data protection are provided. Information about an access context is received in a data processing system. A resource affected by the access context is identified. The identification of the resource may include deriving knowledge about resource by making an inference from a portion of contents of the resource that the access context affects the resource, making an inference that the access context affects a second resource thereby inferring that the resource has to be modified, determining that the access context is relevant to the resource, or a combination thereof. The resource is received. A policy that is applicable to the access context is identified. A part of the resource to modify according to the policy is determined. The part is modified according to the policy and the access context to form a modified resource. The modified resource is transmitted.