Automated DLP Policy Deployment via Identity Service Synchronization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data-loss-prevention (DLP) policies are cumbersome for enterprise administrators to implement and manage across user groups, as existing systems lack efficient methods for automatically deploying DLP policies to user devices based on specific user groups within an enterprise.

Innovation Solution

A system and method for deploying DLP policies to user devices, where an enterprise administrator configures policies on a management server, which communicates with a third-party server to implement these policies across user devices, utilizing an identity service for user authentication and group management, allowing for granular control and automation of DLP policy deployment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If DLP policies are configured manually for each application through web interfaces, then policy implementation is possible, but the process becomes cumbersome and time-consuming for enterprise administrators

Engineering Contradiction:
Improveease of DLP policy configurationVSAvoidtime required to configure DLP policies
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent combines multiple DLP policy configurations for different applications into a single centralized console interface. Administrators can configure policies for multiple applications simultaneously through one unified system, eliminating the need to visit separate web locations for each application and significantly reducing configuration time.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces a third-party application provider as an intermediary that bridges enterprise administrators and multiple applications. This intermediary provides a centralized management console that allows administrators to deploy DLP policies across multiple applications without needing to access each application's individual configuration interface.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If DLP policies are configured without user group segmentation, then simple policy deployment is possible, but efficient management of different user groups with differing policies is not achieved

Engineering Contradiction:
Improveefficiency of DLP policy managementVSAvoidability to apply different policies to different user groups
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The patent segments users into different user groups within the enterprise system and allows administrators to assign specific DLP policies to each group. This segmentation enables differentiated policy management where different groups can have different policy sets, improving both efficiency and adaptability of DLP policy management.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies the principle of local quality by allowing different DLP policies to be applied to different user groups based on their specific needs and security requirements. Each user group can have customized policy settings tailored to their role and data access needs, rather than applying a uniform policy across all users.

Inventive Principle:
Principle #3Local quality

3Adaptability or versatility

If third-party application providers are unaware of enterprise user groups, then application functionality is maintained, but convenient DLP policy definition for particular groups is not provided

Engineering Contradiction:
ImproveDLP policy assignment capabilityVSAvoidsystem integration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent makes the third-party application provider's system universal by enabling it to work with multiple enterprise user groups through a standardized interface. The provider's application can receive and enforce DLP policies for different user groups without requiring custom integration for each enterprise, maintaining functionality while adding policy assignment capability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11743124B2Deploying data-loss-prevention policies to user devices
Publication Date: 2023.08.29 OMNISSA LLC
  • US11743124B2 patent drawing
  • US11743124B2 patent drawing
  • US11743124B2 patent drawing

AI summary

Examples described herein include systems and methods for deploying Data Loss Prevention (DLP) policies to user devices. An example method can include receiving a configuration specifying at least one DLP policy applicable to an application, along with an indication of an assignment group specifying users, or user devices, to which the DLP policy should apply. Information regarding the DLP policy and assignment group can be provided to an identity service and then synchronized with a second server that manages the application. The method can further include provisioning the application to a user device and instructing the user device to retrieve the DLP policy from the second server and implement it when executing the provisioned application.