Data Loss Prevention Policy Override via One-Time Passwords
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data loss prevention (DLP) systems face challenges in enforcing policies, particularly when users need to perform legitimate actions that violate strict policy restrictions, especially in scenarios where communication with the authentication server is unavailable, leading to potential interference with legitimate business operations.
Innovation Solution
A method is implemented to provide one-time passwords (OTPs) for DLP policy exceptions, allowing users to override policies temporarily by using a challenge-response mechanism or tokens that do not require connectivity, incorporating location-based authentication for enhanced security, ensuring that sensitive data is protected against illicit dissemination.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If strict DLP policies are enforced to prevent data loss, then data security is improved, but legitimate business operations are hindered when users need to perform actions that violate policy restrictions
Solution Approach 1:
The system dynamically changes the state of policy enforcement from strict blocking to temporary override by introducing time-limited exception tokens. These tokens modify the enforcement parameter temporarily, allowing legitimate operations while maintaining overall security posture.
Solution Approach 2:
The patent introduces an intermediary authentication mechanism (exception tokens, override codes, or one-time passwords) that mediates between strict policy enforcement and legitimate business needs. This intermediary allows temporary policy violations without compromising overall data security.
2Productivity
If DLP policies are enforced without server connectivity, then operational independence is improved, but security verification becomes unreliable when the authentication server is unavailable
Solution Approach 1:
The system performs preliminary authentication actions by obtaining exception tokens or override codes from the authentication server before connectivity is lost. These pre-obtained credentials enable offline policy overrides without requiring real-time server verification.
Solution Approach 2:
The patent uses disposable one-time passwords or single-use override codes that are valid only once or for a limited time. These short-living authentication objects provide secure offline verification without requiring ongoing server connectivity.
3Adaptability or versatility
If override mechanisms are provided for policy exceptions, then operational flexibility is improved, but system complexity increases due to additional authentication requirements
Solution Approach 1:
The system uses universal authentication mechanisms (exception tokens, override codes, or one-time passwords) that can serve multiple functions: policy override authorization, offline verification, and time-limited access control. This multi-functionality reduces the need for separate complex systems.
Solution Approach 2:
The override mechanism enables users to self-service policy exceptions by presenting override codes or one-time passwords without requiring manual administrator intervention. This automated self-service approach reduces operational complexity while maintaining flexibility.
Data Source
AI summary
A method is used in managing data loss prevention policies. A device having data loss prevention (DLP) logic based on policies is provided. An attempt to perform an action that is prohibited by the DLP logic is performed at the device. An override code to allow performance of the action is determined at the device.


