Data Loss Prevention Policy Override via One-Time Passwords

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data loss prevention (DLP) systems face challenges in enforcing policies, particularly when users need to perform legitimate actions that violate strict policy restrictions, especially in scenarios where communication with the authentication server is unavailable, leading to potential interference with legitimate business operations.

Innovation Solution

A method is implemented to provide one-time passwords (OTPs) for DLP policy exceptions, allowing users to override policies temporarily by using a challenge-response mechanism or tokens that do not require connectivity, incorporating location-based authentication for enhanced security, ensuring that sensitive data is protected against illicit dissemination.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If strict DLP policies are enforced to prevent data loss, then data security is improved, but legitimate business operations are hindered when users need to perform actions that violate policy restrictions

Engineering Contradiction:
Improvedata securityVSAvoidlegitimate business operations
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system dynamically changes the state of policy enforcement from strict blocking to temporary override by introducing time-limited exception tokens. These tokens modify the enforcement parameter temporarily, allowing legitimate operations while maintaining overall security posture.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces an intermediary authentication mechanism (exception tokens, override codes, or one-time passwords) that mediates between strict policy enforcement and legitimate business needs. This intermediary allows temporary policy violations without compromising overall data security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If DLP policies are enforced without server connectivity, then operational independence is improved, but security verification becomes unreliable when the authentication server is unavailable

Engineering Contradiction:
Improveoperational independenceVSAvoidsecurity verification
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system performs preliminary authentication actions by obtaining exception tokens or override codes from the authentication server before connectivity is lost. These pre-obtained credentials enable offline policy overrides without requiring real-time server verification.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses disposable one-time passwords or single-use override codes that are valid only once or for a limited time. These short-living authentication objects provide secure offline verification without requiring ongoing server connectivity.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Adaptability or versatility

If override mechanisms are provided for policy exceptions, then operational flexibility is improved, but system complexity increases due to additional authentication requirements

Engineering Contradiction:
Improveoperational flexibilityVSAvoidauthentication system
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system uses universal authentication mechanisms (exception tokens, override codes, or one-time passwords) that can serve multiple functions: policy override authorization, offline verification, and time-limited access control. This multi-functionality reduces the need for separate complex systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The override mechanism enables users to self-service policy exceptions by presenting override codes or one-time passwords without requiring manual administrator intervention. This automated self-service approach reduces operational complexity while maintaining flexibility.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8656455B1Managing data loss prevention policies
Publication Date: 2014.02.18 EMC IP HLDG CO LLC
  • US8656455B1 patent drawing
  • US8656455B1 patent drawing
  • US8656455B1 patent drawing

AI summary

A method is used in managing data loss prevention policies. A device having data loss prevention (DLP) logic based on policies is provided. An attempt to perform an action that is prohibited by the DLP logic is performed at the device. An override code to allow performance of the action is determined at the device.