Context-Based Security Policy for Data Visibility

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional data security methods fail to prevent sensitive information from being physically viewed by unauthorized observers when data is displayed in public locations, as they rely on binary decision-making logic that either blurs or hides data based on the presence of observers, leading to insecure data exposure.

Innovation Solution

A context-based security policy that employs facial recognition to determine the identity of observers and selectively control data visibility on a per-transaction basis, applying granular security policies based on contextual attributes such as time, location, and user identity to prevent unauthorized access and caching of sensitive data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional binary decision-making logic is used to blur or hide data based on observer presence, then data visibility is controlled, but data security deteriorates because authorized users cannot access data and unauthorized users can still view displayed data

Engineering Contradiction:
Improvedata securityVSAvoiddata accessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies different security policies to different data based on their sensitivity levels. High-sensitivity data requires strict access control and facial recognition, while low-sensitivity data can be accessed more freely. This local differentiation resolves the contradiction by allowing authorized users to access appropriate data while preventing unauthorized access to sensitive information.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically adjusts data visibility and access policies based on real-time contextual factors including user identity verification, location, time, and environmental conditions. This dynamic adaptation allows the system to maintain security while enabling legitimate access, resolving the binary limitation of conventional static policies.

Inventive Principle:
Principle #15Dynamics

2Ease of operation

If data is displayed in public locations to improve accessibility, then ease of operation improves, but data security deteriorates due to shoulder surfing and unauthorized viewing

Engineering Contradiction:
Improvedata accessibilityVSAvoidunauthorized viewing
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system continuously monitors the environment using cameras and sensors to detect unauthorized observers, then provides feedback to adjust data visibility in real-time. When unauthorized individuals are detected, the system automatically blurs or hides sensitive data, creating a dynamic feedback loop that maintains security while allowing legitimate access.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent changes physical parameters of data display such as brightness, contrast, and pixelation levels based on detected environmental conditions and observer presence. By dynamically adjusting these visual parameters, the system can maintain readability for authorized users while preventing unauthorized viewing in public settings.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If facial recognition and context-based policies are implemented to improve data security, then data security improves, but device complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidsecurity system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal security framework that handles multiple security functions through a single integrated system. The same facial recognition and context-based policy engine manages access control, data visibility, caching decisions, and environmental monitoring, reducing overall system complexity compared to separate dedicated systems for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system performs preliminary actions by pre-establishing security policies, user authentication protocols, and environmental safety rules before actual data access occurs. By preparing and validating these parameters in advance, the system reduces runtime complexity and enables faster, more secure decision-making during actual data access operations.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11818137B2Context-based security policy for data access and visibility
Publication Date: 2023.11.14 CISCO TECHNOLOGY INC
  • US11818137B2 patent drawing
  • US11818137B2 patent drawing
  • US11818137B2 patent drawing

AI summary

A method, computer system, and computer program product are provided for controlling data access and visibility using a context-based security policy. A request from an endpoint device to receive data is received at a server, wherein the request includes one or more contextual attributes of the endpoint device including an identity of a user of the endpoint device. The one or more contextual attributes are processed to determine that the endpoint device is authorized to receive the data. A security policy is determined for the data based on the one or more contextual attributes. The data is transmitted, including the security policy, to the endpoint device, wherein the endpoint devices enforces the security policy to selectively permit access to the data by preventing the endpoint device from displaying the data to an unauthorized individual.