Data Loss Prevention System Using User Credit Grading

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data loss prevention (DLP) systems experience significant security inspection delays due to uniform inspection processes for all users, affecting data sending efficiency and user experience.

Innovation Solution

Implementing a method where outgoing data from user terminals carries a unique identifier, allowing a credit server to assign user grades and credit values based on historical data inspection records, which are then used by a DLP server to select appropriate inspection algorithms, thereby reducing inspection delays and improving efficiency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a uniform inspection process is executed for all users, then security inspection thoroughness is improved, but security inspection delay increases

Engineering Contradiction:
Improvesecurity inspection thoroughnessVSAvoidsecurity inspection delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies local quality by implementing differentiated inspection policies based on user grades. High-credit users receive simplified inspection with lower thoroughness but faster processing, while low-credit users undergo comprehensive inspection. This resolves the contradiction by making inspection quality local to each user's credit level rather than uniformly high for all users.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent changes the inspection parameter (thoroughness level) based on user credit values. The DLP server dynamically adjusts inspection depth and algorithm selection according to user grade, transforming the fixed uniform inspection into a variable parameter system that adapts to user credibility, thereby reducing overall inspection delay while maintaining security.

Inventive Principle:
Principle #35Parameter changes

2Stability of the object's composition

If a uniform inspection process is executed for all users, then security policy consistency is improved, but data sending efficiency deteriorates

Engineering Contradiction:
Improvesecurity policy consistencyVSAvoiddata sending efficiency
Core Design Contradiction:
Stability of the object's compositionVSProductivity

Solution Approach 1:

The patent introduces dynamics by making the inspection process adaptive rather than static. User grades and credit values dynamically determine inspection intensity, allowing the system to flexibly adjust security measures based on user behavior history. This resolves the contradiction by replacing rigid uniform inspection with a dynamic graded approach that maintains policy consistency through structured differentiation.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent segments the user base into different grades (high-credit, medium-credit, low-credit) and applies tailored inspection policies to each segment. This segmentation allows high-credit users to experience faster data sending efficiency while low-credit users receive more thorough inspection, overall improving system productivity while maintaining security through structured policy consistency across segments.

Inventive Principle:
Principle #1Segmentation

3Reliability

If comprehensive security inspection algorithms are applied to all users, then data security is improved, but system resource consumption increases

Engineering Contradiction:
Improvedata securityVSAvoidsystem resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent applies partial action by implementing graduated inspection intensity. High-credit users receive minimal or spot-check inspection (partial action), while low-credit users receive comprehensive inspection (excessive action). This resolves the contradiction by applying resource-intensive security measures only where necessary, reducing overall system resource consumption while maintaining data security through targeted comprehensive inspection of risky users.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS9984241B2Method, apparatus, and system for data protection
Publication Date: 2018.05.29 HUAWEI TECH CO LTD
  • US9984241B2 patent drawing
  • US9984241B2 patent drawing
  • US9984241B2 patent drawing

AI summary

A method, an apparatus, and a system for data protection. A specific solution is: a proxy server receives outgoing data from a user terminal, where the outgoing data carries an identifier of a user; acquires a user grade and a credit value of the user from a credit server according to the identifier, where the credit value is a violation percentage of historical outgoing data of the user; sends the outgoing data, the user grade, and the credit value to a DLP server so that the DLP server inspects security of the outgoing data according to the user grade and the credit value, and further generates a message including an inspection result; and receives, from the DLP server, the message including the inspection result and uses a policy corresponding to the inspection result to process the outgoing data. The present invention is used during a protection process of outgoing data.