Cross Domain Data Protection Intermediary for Network Level Routing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computer platforms struggle to route data loss prevention (DLP) events across different network levels, particularly from high to low classification levels, requiring costly multiple solutions and lacking the ability to pair destination and source files or gather information about them efficiently.

Innovation Solution

A method and system that utilize a transformation platform to process and classify DLP events, including entity risk levels and certificates, allowing command signals for dynamic data protection to be routed from high to low network classification levels, with an edge device supporting functional behavior assessment and decoupling control and repository processes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a computer platform relies on command signals to operate between different network classification levels, then it can provide data protection and monitor user activities, but it cannot support command signals from high network classification level down to low or unclassified network level

Engineering Contradiction:
Improvedata protection capabilityVSAvoidcross-level command signal support
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces an intermediary component that sits between high and low network classification levels to translate and relay command signals. This intermediary enables bidirectional communication across classification boundaries without compromising security, allowing the system to maintain reliable data protection while gaining adaptability to support cross-level operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments the network architecture into distinct classification levels with dedicated communication channels and translation layers. By dividing the monolithic command signal path into segmented, level-specific segments with controlled interfaces, the system enables high-to-low classification signal flow while maintaining the integrity and security requirements of each level.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If multiple computer platform solutions are implemented to support different network classification levels, then command signal support is improved, but cost increases significantly

Engineering Contradiction:
Improvemulti-level network supportVSAvoidnumber of computer platforms required
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The patent implements a universal computer platform capable of operating across multiple network classification levels through software-based classification management and configurable security policies. This single multi-functional platform replaces the need for separate dedicated platforms for each classification level, reducing system complexity and cost while maintaining full adaptability to handle diverse network security requirements.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If certain methods monitor activity between destination and source files, then security monitoring is provided, but the ability to pair destination and source files or gather information about them is lacking

Engineering Contradiction:
Improvesecurity monitoring capabilityVSAvoidfile pairing and contextual information
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system implements feedback mechanisms that track and correlate file operations between source and destination files across network boundaries. By continuously monitoring and recording file metadata, access patterns, and transformation operations, the system provides comprehensive security monitoring while preserving complete contextual information about file relationships, enabling auditable security analysis.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11431743B2Cross domain dynamic data protection intermediary message transform platform
Publication Date: 2022.08.30 EVERFOX HOLDINGS LLC
  • US11431743B2 patent drawing
  • US11431743B2 patent drawing
  • US11431743B2 patent drawing

AI summary

A method, system and computer-usable medium for routing data loss prevention (DLP) events across different network levels. A determination is made as to a number of DLP networks. The classification and data as to a DLP network is determined. Certain data is processed, including an entity risk level and certain data is held, such as certificates. The held data is processed by a computing platform. Processed entity risk levels are returned to the DLP networks. When all networks are processed, processed and held data are sent to the computing platform.