Identity-Centric DLP Policy Distribution for Endpoint Bandwidth Optimization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing Data Loss Prevention (DLP) systems face challenges in efficiently associating data loss protection policies with endpoints, particularly in diverse enterprise environments with varying user roles and geographically dispersed workforces, as current methods either distribute policies broadly, selectively based on endpoint characteristics, or are limited to server-based enforcement.

Innovation Solution

An identity-centric method for associating DLP policies with endpoints, where policies are determined based on a combination of user identity and endpoint characteristics, using a policy model that links users with roles or groups to define applicable policies and distribute them to relevant endpoints, enabling dynamic policy application and compliance tracking.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If policies are distributed to all endpoints, then policy coverage is complete, but network bandwidth consumption increases and policy management complexity increases

Engineering Contradiction:
Improvepolicy coverageVSAvoidnetwork bandwidth
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent applies local quality by customizing policy distributions to specific endpoint characteristics rather than applying uniform policies to all endpoints. The system determines applicable policies based on endpoint attributes such as operating system, hardware architecture, and organizational assignment, thereby transmitting only relevant policies to each endpoint. This reduces unnecessary network bandwidth consumption while maintaining comprehensive policy coverage for relevant endpoints.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent segments the policy distribution process by dividing policies into distinct categories based on endpoint characteristics and organizational roles. Instead of distributing all policies to all endpoints, the system segments policies into role-based groups (e.g., developer policies, HR policies) and distributes only the appropriate segments to endpoints matching those characteristics, reducing network bandwidth while ensuring complete coverage for relevant segments.

Inventive Principle:
Principle #1Segmentation

2Loss of energy

If policies are selectively distributed based on endpoint characteristics, then network bandwidth is reduced, but adaptability to mobile workforce and geographically dispersed users decreases

Engineering Contradiction:
Improvenetwork bandwidthVSAvoidadaptability to mobile workforce
Core Design Contradiction:
Loss of energyVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamics by making policy assignments flexible and adaptable rather than static. The system allows dynamic assignment of policies to endpoints based on user roles, organizational assignments, and endpoint characteristics. This enables the same endpoint to receive different policies at different times based on changing user roles or organizational needs, maintaining adaptability to mobile and geographically dispersed workforces while reducing network bandwidth through selective distribution.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent applies universality through a multi-functional policy assignment mechanism that can handle various distribution scenarios simultaneously. The same policy management system handles role-based assignments, location-based assignments, and characteristic-based assignments through a unified approach. This multi-functional capability ensures adaptability to diverse workforce scenarios while maintaining efficient selective distribution to reduce network bandwidth.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If policies are distributed based on role or group assignments, then policy relevance to user identity improves, but system complexity increases

Engineering Contradiction:
Improvepolicy relevance to user identityVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary policy management system that mediates between user identity/role information and policy distribution. This intermediary layer receives role and group assignment information, determines applicable policies, and handles the distribution logic. By centralizing this mediation function, the system improves policy relevance to user identity while containing complexity in a dedicated management layer rather than distributing complexity across all endpoints and systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10432666B2Method and apparatus for associating data loss protection (DLP) policies with endpoints
Publication Date: 2019.10.01 SAILPOINT TECHNOLOGIES HOLDINGS INC
  • US10432666B2 patent drawing
  • US10432666B2 patent drawing
  • US10432666B2 patent drawing

AI summary

A method of policy management in a Data Loss Prevention (DLP) system uses a policy model that associates a user with one or more DLP endpoints. When an endpoint is added to the system, a set of policies for that endpoint are determined using an identity of the user that is associated with the endpoint and a list of roles or groups for that user. At policy distribution time, the method determines a set of endpoints to which the policy is to be distributed.