Data Loss Prevention System Using User Credit Grading
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data loss prevention (DLP) systems experience significant security inspection delays due to uniform inspection processes for all users, affecting data sending efficiency and user experience.
Innovation Solution
Implementing a method where outgoing data from user terminals carries a unique identifier, allowing a credit server to assign user grades and credit values based on historical data inspection records, which are then used by a DLP server to select appropriate inspection algorithms, thereby reducing inspection delays and improving efficiency.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a uniform inspection process is executed for all users, then security inspection thoroughness is improved, but security inspection delay increases
Solution Approach 1:
The patent applies local quality by implementing differentiated inspection policies based on user grades. High-credit users receive simplified inspection with lower thoroughness but faster processing, while low-credit users undergo comprehensive inspection. This resolves the contradiction by making inspection quality local to each user's credit level rather than uniformly high for all users.
Solution Approach 2:
The patent changes the inspection parameter (thoroughness level) based on user credit values. The DLP server dynamically adjusts inspection depth and algorithm selection according to user grade, transforming the fixed uniform inspection into a variable parameter system that adapts to user credibility, thereby reducing overall inspection delay while maintaining security.
2Stability of the object's composition
If a uniform inspection process is executed for all users, then security policy consistency is improved, but data sending efficiency deteriorates
Solution Approach 1:
The patent introduces dynamics by making the inspection process adaptive rather than static. User grades and credit values dynamically determine inspection intensity, allowing the system to flexibly adjust security measures based on user behavior history. This resolves the contradiction by replacing rigid uniform inspection with a dynamic graded approach that maintains policy consistency through structured differentiation.
Solution Approach 2:
The patent segments the user base into different grades (high-credit, medium-credit, low-credit) and applies tailored inspection policies to each segment. This segmentation allows high-credit users to experience faster data sending efficiency while low-credit users receive more thorough inspection, overall improving system productivity while maintaining security through structured policy consistency across segments.
3Reliability
If comprehensive security inspection algorithms are applied to all users, then data security is improved, but system resource consumption increases
Solution Approach 1:
The patent applies partial action by implementing graduated inspection intensity. High-credit users receive minimal or spot-check inspection (partial action), while low-credit users receive comprehensive inspection (excessive action). This resolves the contradiction by applying resource-intensive security measures only where necessary, reducing overall system resource consumption while maintaining data security through targeted comprehensive inspection of risky users.
Data Source
AI summary
A method, an apparatus, and a system for data protection. A specific solution is: a proxy server receives outgoing data from a user terminal, where the outgoing data carries an identifier of a user; acquires a user grade and a credit value of the user from a credit server according to the identifier, where the credit value is a violation percentage of historical outgoing data of the user; sends the outgoing data, the user grade, and the credit value to a DLP server so that the DLP server inspects security of the outgoing data according to the user grade and the credit value, and further generates a message including an inspection result; and receives, from the DLP server, the message including the inspection result and uses a policy corresponding to the inspection result to process the outgoing data. The present invention is used during a protection process of outgoing data.


