Data Protection Server Containerizes Sensitive Information
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Companies face security risks when allowing remote access to corporate IT networks, as unauthorized individuals can access sensitive customer data, and employees' laptops with stolen credentials can compromise security.
Innovation Solution
Implementing a corporate data protection server that containerizes sensitive information and access control lists, using authentication and access preferences to authorize access, and adding watermarks to track and deter unauthorized access, while providing secure access based on user permissions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If remote access to corporate IT networks is allowed, then employee flexibility and productivity are improved, but security risks and unauthorized access increase
Solution Approach 1:
A data protection server is introduced as an intermediary between employees and sensitive customer information. The server containerizes sensitive data and manages access control lists, acting as a mediator that enables remote access while maintaining security boundaries. This intermediary prevents direct access to sensitive data, thereby reducing security risks while preserving employee flexibility.
Solution Approach 2:
The system segments access control by implementing access control lists that divide permission management into discrete units. Each employee receives specific access permissions to particular sensitive information based on their role, rather than providing blanket access. This segmentation allows flexible remote access for authorized personnel while restricting unauthorized access to specific data segments.
2Reliability
If access control lists are implemented to restrict data access, then security is improved, but access management complexity increases
Solution Approach 1:
The data protection server automatically manages access control lists and authentication processes without requiring manual intervention for each access request. The system self-services by containerizing sensitive information, automatically verifying credentials, and granting or denying access based on pre-configured permission sets. This automation maintains high security while reducing the operational complexity of access management.
Solution Approach 2:
Access control permissions are pre-configured in access control lists before employees need to access sensitive data. The system performs preliminary authentication and authorization checks, establishing security rules in advance rather than managing them in real-time during each access event. This preliminary setup simplifies ongoing access management while maintaining strict security controls.
3Object-affected harmful factors
If watermarking is added to sensitive information, then deterrence against unauthorized copying is improved, but data processing overhead increases
Solution Approach 1:
The system uses watermarking technology that embeds invisible or visible identifiers into sensitive information displayed to authorized employees. These watermarks serve as copies or traces that can be detected if unauthorized copying occurs. The watermarking process adds minimal processing overhead while providing strong deterrence and tracking capability against unauthorized data copying.
Data Source
AI summary
A corporate information technology (IT) network can protect sensitive data sent to computers located outside of the IT network. For example, a customer of a company may control who can access his or her sensitive personal information by identifying his or her access preference included in an access control list, where the access preference describes a level of access that at least one remote employee or person may have to the customer's sensitive personal information. A data protection server may containerize the sensitive personal information and the access control list of the person in a data protection container. If a remote employee or a person requests access the customer's sensitive personal information, the data protection server may perform data protection related operations to provide the sensitive personal information to the remote employee or person.


