Local Data Protection Agent for Secure Storage and Leakage Prevention
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data protection systems for local computing devices face challenges in accurately securing data and preventing leakage, loss, and theft due to high computational requirements and poor security accuracy.
Innovation Solution
A local data protection system that includes a data protection agent program installed on local computing devices, which guides users to store data files in secure areas based on a preset security policy and performs data protection functions to prevent data breaches.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional endpoint protection software or network firewalls are used for data protection, then data security coverage is improved, but computational power requirements increase and security accuracy deteriorates
Solution Approach 1:
The patent extracts the data protection function from traditional endpoint protection software and network firewalls, creating a dedicated data protection module that operates independently. This module specifically monitors and controls data access, transfer, and storage operations, separating these critical functions from general system protection mechanisms to reduce overall computational overhead while maintaining focused security coverage
Solution Approach 2:
The patent introduces an intermediary data protection module that sits between the operating system and application programs. This intermediary layer intercepts and monitors data operations without requiring full system-wide scanning, acting as a mediator that provides security checks only when data operations occur, thereby reducing continuous computational power requirements while maintaining security coverage
2Reliability
If traditional endpoint protection software or network firewalls are used for data protection, then data security coverage is improved, but security accuracy deteriorates
Solution Approach 1:
The patent applies local quality by implementing fine-grained access control policies that are specifically tailored to different data types, users, and operations. Instead of uniform protection mechanisms, the system applies customized security rules to specific data operations, improving security accuracy by addressing the unique characteristics of each data access scenario rather than using blanket protection approaches
Solution Approach 2:
The patent incorporates feedback mechanisms that continuously monitor data operations and adjust protection measures based on detected patterns and threats. The system analyzes data access behaviors in real-time and dynamically modifies security responses, improving security accuracy by learning from observed patterns and adapting protection strategies to actual threat scenarios rather than relying on static rules
3Ease of operation
If data is stored in multiple locations for accessibility, then ease of operation is improved, but data leakage risk increases
Solution Approach 1:
The patent segments data storage into multiple controlled locations with hierarchical access permissions. Data is divided into segments that can be stored across different locations, but access to each segment is independently controlled through fine-grained policies. This allows users to access data from multiple locations while maintaining security control over each access point, reducing leakage risk through segmented access management
Solution Approach 2:
The patent implements dynamic access control that adjusts permissions based on context such as user identity, location, time, and operation type. Access controls are not static but dynamically evaluated for each data access request, allowing flexible accessibility while maintaining security. The system can dynamically grant or deny access based on real-time conditions, enabling multi-location accessibility without compromising security
Data Source
AI summary
According to one aspect of the present invention, there is provided a local data protection system including a data protection agent program installed on a local computing device, which, in accordance with a preset security policy, directs storage of data files stored on the local computing device to a security area, and performs predetermined data protection functions to prevent data in storage from being leaked, lost, stolen or otherwise compromised.

