Data Protection Server Containerizes Sensitive Information

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Companies face security risks when allowing remote access to corporate IT networks, as unauthorized individuals can access sensitive customer data, and employees' laptops with stolen credentials can compromise security.

Innovation Solution

Implementing a corporate data protection server that containerizes sensitive information and access control lists, using authentication and access preferences to authorize access, and adding watermarks to track and deter unauthorized access, while providing secure access based on user permissions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If remote access to corporate IT networks is allowed, then employee flexibility and productivity are improved, but security risks and unauthorized access increase

Engineering Contradiction:
Improveemployee flexibilityVSAvoidunauthorized access
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

A data protection server is introduced as an intermediary between employees and sensitive customer information. The server containerizes sensitive data and manages access control lists, acting as a mediator that enables remote access while maintaining security boundaries. This intermediary prevents direct access to sensitive data, thereby reducing security risks while preserving employee flexibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments access control by implementing access control lists that divide permission management into discrete units. Each employee receives specific access permissions to particular sensitive information based on their role, rather than providing blanket access. This segmentation allows flexible remote access for authorized personnel while restricting unauthorized access to specific data segments.

Inventive Principle:
Principle #1Segmentation

2Reliability

If access control lists are implemented to restrict data access, then security is improved, but access management complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidaccess management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The data protection server automatically manages access control lists and authentication processes without requiring manual intervention for each access request. The system self-services by containerizing sensitive information, automatically verifying credentials, and granting or denying access based on pre-configured permission sets. This automation maintains high security while reducing the operational complexity of access management.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Access control permissions are pre-configured in access control lists before employees need to access sensitive data. The system performs preliminary authentication and authorization checks, establishing security rules in advance rather than managing them in real-time during each access event. This preliminary setup simplifies ongoing access management while maintaining strict security controls.

Inventive Principle:
Principle #10Preliminary action

3Object-affected harmful factors

If watermarking is added to sensitive information, then deterrence against unauthorized copying is improved, but data processing overhead increases

Engineering Contradiction:
Improveunauthorized copyingVSAvoiddata processing overhead
Core Design Contradiction:
Object-affected harmful factorsVSLoss of energy

Solution Approach 1:

The system uses watermarking technology that embeds invisible or visible identifiers into sensitive information displayed to authorized employees. These watermarks serve as copies or traces that can be detected if unauthorized copying occurs. The watermarking process adds minimal processing overhead while providing strong deterrence and tracking capability against unauthorized data copying.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11803658B1Data access control
Publication Date: 2023.10.31 UNITED SERVICES AUTOMOBILE ASSOCIATION (USAA)
  • US11803658B1 patent drawing
  • US11803658B1 patent drawing
  • US11803658B1 patent drawing

AI summary

A corporate information technology (IT) network can protect sensitive data sent to computers located outside of the IT network. For example, a customer of a company may control who can access his or her sensitive personal information by identifying his or her access preference included in an access control list, where the access preference describes a level of access that at least one remote employee or person may have to the customer's sensitive personal information. A data protection server may containerize the sensitive personal information and the access control list of the person in a data protection container. If a remote employee or a person requests access the customer's sensitive personal information, the data protection server may perform data protection related operations to provide the sensitive personal information to the remote employee or person.