Distributed Data Protection for Disconnected Environments
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data protection systems are inadequate for disconnected environments, as they rely on networked security devices and fail to prevent unauthorized access by authorized users, and introduce points of failure, especially in situations like traveling employees or network disruptions.
Innovation Solution
A method for data protection that involves receiving requests encrypted with an encryption key, modifying an indicator value based on access control instructions, and denying requests if access rules are violated, using intrusion detection profiles and inference patterns to prevent unauthorized access, even in disconnected environments.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Difficulty of detecting and measuring
If networked security devices are used for data protection, then detection capability is improved, but system reliability deteriorates due to points of failure and network dependency
Solution Approach 1:
The patent segments the security system into distributed security modules deployed across multiple servers rather than relying on centralized networked security devices. Each server runs local security software that independently monitors and protects data, eliminating the single point of failure represented by centralized network security appliances.
Solution Approach 2:
The security system enables servers to autonomously detect and respond to security threats without requiring constant communication with external security devices. The local security modules perform self-monitoring, self-protection, and automatic response actions, making the system self-sufficient even when network connectivity is lost.
2Difficulty of detecting and measuring
If centralized security monitoring is implemented, then security oversight is improved, but adaptability to disconnected environments deteriorates
Solution Approach 1:
The centralized security monitoring function is segmented into distributed security agents on each server. These agents locally perform security monitoring and enforcement, allowing the system to maintain security oversight capabilities even when disconnected from central management infrastructure.
Solution Approach 2:
Security policies, detection rules, and response procedures are pre-configured and cached on local servers before disconnection occurs. This preliminary action ensures that security monitoring and enforcement can continue uninterrupted during network outages, adapting seamlessly to disconnected environments.
3Ease of operation
If normal access control systems are used, then ease of operation is improved, but security against authorized user attacks deteriorates
Solution Approach 1:
The security system implements continuous feedback monitoring of user access patterns, data query behaviors, and operation sequences. By analyzing these feedback signals in real-time, the system can detect anomalies indicative of authorized user attacks and automatically respond by blocking suspicious activities while maintaining normal access for legitimate operations.
Solution Approach 2:
The system pre-establishes detection rules and response mechanisms for common authorized user attack patterns. When suspicious behaviors are detected, preliminary countermeasures are automatically triggered to prevent potential data breaches before they can occur, while still allowing normal user operations to proceed uninterrupted.
Data Source
AI summary
Systems and methods are provided for the detection and prevention of intrusions in data at rest systems such as file systems and web servers. The systems and methods regulate access to sensitive data with minimal dependency on a communications network. Data access is quantitatively limited to minimize the data breaches resulting from, e.g., a stolen laptop or hard drive.


