DLP Manager Routing Queue for Automated Authorization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity measures lack an efficient mechanism for automatically routing data loss prevention (DLP) events across multiple stakeholders within an organization to confirm authorization and enforce security policies, leading to potential violations and delays in incident investigation.

Innovation Solution

A DLP manager system that utilizes a routing queue to automatically transmit requests for feedback through a graphical user interface (GUI), selecting parties based on a predetermined sequence to expedite the review of DLP events and initiate appropriate security actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual review of DLP events is performed by security investigators, then authorization accuracy is improved, but investigation time and operational efficiency deteriorate

Engineering Contradiction:
Improveauthorization accuracyVSAvoidinvestigation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments the DLP event review process into multiple independent stages, assigning different types of parties (authorized parties, predetermined parties, routing queue parties) to different segmentation levels. This allows parallel processing of review tasks while maintaining comprehensive authorization checks, thereby reducing total investigation time without compromising accuracy.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces automated intermediaries including the DLP manager system, routing queue mechanism, and notification system that mediate between DLP events and final authorization decisions. These intermediaries automatically filter, route, and coordinate review requests, reducing manual operational time while preserving authorization reliability through structured multi-party validation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple parties review DLP events to confirm authorization, then security policy enforcement is improved, but process complexity and coordination overhead worsen

Engineering Contradiction:
Improvesecurity policy enforcementVSAvoidprocess complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates universal review mechanisms where parties can serve multiple functions across different DLP event types and organizational contexts. The routing queue system and notification mechanisms are designed to handle various event scenarios through standardized processes, reducing coordination complexity while maintaining comprehensive security policy enforcement across diverse situations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system implements self-service capabilities where the DLP manager automatically identifies relevant parties, routes review requests through the routing queue, sends notifications, and coordinates the review process without requiring manual intervention for each step. This automation reduces process complexity while ensuring consistent multi-party review for security policy enforcement.

Inventive Principle:
Principle #25Self-service

3Productivity

If automated routing queue selects parties for feedback, then operational efficiency is improved, but system complexity and automation extent worsen

Engineering Contradiction:
Improveoperational efficiencyVSAvoidsystem automation
Core Design Contradiction:
ProductivityVSExtent of automation

Solution Approach 1:

The patent implements preliminary action by pre-configuring the routing queue with predetermined parties and selection criteria before DLP events occur. The system pre-establishes notification rules, party hierarchies, and routing logic, allowing automated efficient party selection when events occur without requiring complex real-time decision-making, thus balancing operational efficiency with manageable automation complexity.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11477244B2Method and system for data loss prevention management
Publication Date: 2022.10.18 SAUDI ARABIAN OIL CO
  • US11477244B2 patent drawing
  • US11477244B2 patent drawing
  • US11477244B2 patent drawing

AI summary

A method may include obtaining, from a user device, a first feedback from a first predetermined party regarding a data loss prevention (DLP) event through a graphical user interface (GUI). The method may further include determining whether the DLP event is authorized using the first feedback. The method may further include transmitting, automatically in response to determining that the DLP event is not authorized, a request for a second feedback by a second predetermined party using the GUI. The second predetermined party may be selected for the request automatically according to a routing queue. The method may further include obtaining, in response to transmitting the request for the second feedback, a selection of a security action regarding the DLP event using the GUI. The method may further include transmitting, automatically in response to the selection of the security action, a command that initiates the security action.