Context-Based Security Policy for Data Visibility
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional data security methods fail to prevent sensitive information from being physically viewed by unauthorized observers when data is displayed in public locations, as they rely on binary decision-making logic that either blurs or hides data based on the presence of observers, leading to insecure data exposure.
Innovation Solution
A context-based security policy that employs facial recognition to determine the identity of observers and selectively control data visibility on a per-transaction basis, applying granular security policies based on contextual attributes such as time, location, and user identity to prevent unauthorized access and caching of sensitive data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional binary decision-making logic is used to blur or hide data based on observer presence, then data visibility is controlled, but data security deteriorates because authorized users cannot access data and unauthorized users can still view displayed data
Solution Approach 1:
The patent applies different security policies to different data based on their sensitivity levels. High-sensitivity data requires strict access control and facial recognition, while low-sensitivity data can be accessed more freely. This local differentiation resolves the contradiction by allowing authorized users to access appropriate data while preventing unauthorized access to sensitive information.
Solution Approach 2:
The system dynamically adjusts data visibility and access policies based on real-time contextual factors including user identity verification, location, time, and environmental conditions. This dynamic adaptation allows the system to maintain security while enabling legitimate access, resolving the binary limitation of conventional static policies.
2Ease of operation
If data is displayed in public locations to improve accessibility, then ease of operation improves, but data security deteriorates due to shoulder surfing and unauthorized viewing
Solution Approach 1:
The system continuously monitors the environment using cameras and sensors to detect unauthorized observers, then provides feedback to adjust data visibility in real-time. When unauthorized individuals are detected, the system automatically blurs or hides sensitive data, creating a dynamic feedback loop that maintains security while allowing legitimate access.
Solution Approach 2:
The patent changes physical parameters of data display such as brightness, contrast, and pixelation levels based on detected environmental conditions and observer presence. By dynamically adjusting these visual parameters, the system can maintain readability for authorized users while preventing unauthorized viewing in public settings.
3Reliability
If facial recognition and context-based policies are implemented to improve data security, then data security improves, but device complexity increases
Solution Approach 1:
The patent implements a universal security framework that handles multiple security functions through a single integrated system. The same facial recognition and context-based policy engine manages access control, data visibility, caching decisions, and environmental monitoring, reducing overall system complexity compared to separate dedicated systems for each function.
Solution Approach 2:
The system performs preliminary actions by pre-establishing security policies, user authentication protocols, and environmental safety rules before actual data access occurs. By preparing and validating these parameters in advance, the system reduces runtime complexity and enables faster, more secure decision-making during actual data access operations.
Data Source
AI summary
A method, computer system, and computer program product are provided for controlling data access and visibility using a context-based security policy. A request from an endpoint device to receive data is received at a server, wherein the request includes one or more contextual attributes of the endpoint device including an identity of a user of the endpoint device. The one or more contextual attributes are processed to determine that the endpoint device is authorized to receive the data. A security policy is determined for the data based on the one or more contextual attributes. The data is transmitted, including the security policy, to the endpoint device, wherein the endpoint devices enforces the security policy to selectively permit access to the data by preventing the endpoint device from displaying the data to an unauthorized individual.


