Distributed Data Protection for Disconnected Environments

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data protection systems are inadequate for disconnected environments, as they rely on networked security devices and fail to prevent unauthorized access by authorized users, and introduce points of failure, especially in situations like traveling employees or network disruptions.

Innovation Solution

A method for data protection that involves receiving requests encrypted with an encryption key, modifying an indicator value based on access control instructions, and denying requests if access rules are violated, using intrusion detection profiles and inference patterns to prevent unauthorized access, even in disconnected environments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Difficulty of detecting and measuring

If networked security devices are used for data protection, then detection capability is improved, but system reliability deteriorates due to points of failure and network dependency

Engineering Contradiction:
Improvedetection capabilityVSAvoidsystem reliability
Core Design Contradiction:
Difficulty of detecting and measuringVSReliability

Solution Approach 1:

The patent segments the security system into distributed security modules deployed across multiple servers rather than relying on centralized networked security devices. Each server runs local security software that independently monitors and protects data, eliminating the single point of failure represented by centralized network security appliances.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The security system enables servers to autonomously detect and respond to security threats without requiring constant communication with external security devices. The local security modules perform self-monitoring, self-protection, and automatic response actions, making the system self-sufficient even when network connectivity is lost.

Inventive Principle:
Principle #25Self-service

2Difficulty of detecting and measuring

If centralized security monitoring is implemented, then security oversight is improved, but adaptability to disconnected environments deteriorates

Engineering Contradiction:
Improvesecurity oversightVSAvoidadaptability to disconnected environments
Core Design Contradiction:
Difficulty of detecting and measuringVSAdaptability or versatility

Solution Approach 1:

The centralized security monitoring function is segmented into distributed security agents on each server. These agents locally perform security monitoring and enforcement, allowing the system to maintain security oversight capabilities even when disconnected from central management infrastructure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Security policies, detection rules, and response procedures are pre-configured and cached on local servers before disconnection occurs. This preliminary action ensures that security monitoring and enforcement can continue uninterrupted during network outages, adapting seamlessly to disconnected environments.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If normal access control systems are used, then ease of operation is improved, but security against authorized user attacks deteriorates

Engineering Contradiction:
Improveease of accessVSAvoidunauthorized access by authorized users
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The security system implements continuous feedback monitoring of user access patterns, data query behaviors, and operation sequences. By analyzing these feedback signals in real-time, the system can detect anomalies indicative of authorized user attacks and automatically respond by blocking suspicious activities while maintaining normal access for legitimate operations.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system pre-establishes detection rules and response mechanisms for common authorized user attack patterns. When suspicious behaviors are detected, preliminary countermeasures are automatically triggered to prevent potential data breaches before they can occur, while still allowing normal user operations to proceed uninterrupted.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS10211978B2Data security in a disconnected environment
Publication Date: 2019.02.19 PROTEGRITY US HLDG LLC
  • US10211978B2 patent drawing
  • US10211978B2 patent drawing
  • US10211978B2 patent drawing

AI summary

Systems and methods are provided for the detection and prevention of intrusions in data at rest systems such as file systems and web servers. The systems and methods regulate access to sensitive data with minimal dependency on a communications network. Data access is quantitatively limited to minimize the data breaches resulting from, e.g., a stolen laptop or hard drive.