Dynamic Access Rules for Secure File Transmission

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data encryption systems for corporate networks face challenges in securely transmitting files between computers without significantly increasing computing burdens on user devices and lack effective trust verification for access to sensitive files.

Innovation Solution

A method and system that determine access rules based on parameters of the requested file, remote computer, and user, applying encryption requirements to ensure secure file access, including the use of encryption engines and access policy databases to manage and enforce access permissions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing data encryption systems are used to securely transmit files between computers, then data transmission security is improved, but computing burden on the processor of the user device increases

Engineering Contradiction:
Improvedata transmission securityVSAvoidcomputing burden on processor
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system divides encryption responsibilities between two segments: the initiating computer applies encryption to files before transmission, and the receiving computer verifies digital signatures without performing full decryption. This segmentation reduces the computational burden on both devices while maintaining security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces digital certificates and signatures as an intermediary mechanism. Instead of requiring the receiving computer to perform complex decryption operations, the system uses digital signatures to verify the authenticity and integrity of transmitted files, reducing processing requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If existing data encryption systems are used to encrypt files for transmission, then data security is improved, but proper checking of the level of trust of the requesting party is lacking

Engineering Contradiction:
Improvedata securityVSAvoidtrust verification mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary trust verification by checking digital certificates and signatures before processing file transmission. The receiving computer verifies the sender's digital signature and certificate validity in advance, ensuring trust assessment occurs before any file operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms where the system continuously verifies digital signatures and certificates during file transmission operations. Access rules are dynamically applied based on verified trust levels, creating a feedback loop that ensures ongoing security validation.

Inventive Principle:
Principle #23Feedback

3Ease of operation

If files are transmitted in unencrypted form between computers on a network, then ease of data exchange is improved, but vulnerability to unauthorized access increases

Engineering Contradiction:
Improveease of data exchangeVSAvoidvulnerability to unauthorized access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system dynamically changes the encryption parameter based on the sensitivity of the file and the trust level of the receiving party. For sensitive files, encryption is applied; for less sensitive files or trusted recipients, transmission may occur with reduced or no encryption, balancing ease of exchange with security requirements.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent implements dynamic access rules that adjust encryption requirements based on real-time parameters such as file sensitivity, user trust levels, and security policies. This dynamic approach allows the system to optimize between ease of data exchange and security protection on a per-file basis.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS9058472B1System and method of applying access rules to files transmitted between computers
Publication Date: 2015.06.16 AO KASPERSKY LAB
  • US9058472B1 patent drawing
  • US9058472B1 patent drawing
  • US9058472B1 patent drawing

AI summary

Disclosed are systems and methods for providing access to computer files, including receiving, by a hardware processor, from a remote computer, a request to access a file; determining one or more parameters of at least one of the requested file, the remote computer and a user of the remote computer; determining, based on the one or more parameters, access rules for the requested file, wherein the access rules specify at least encryption requirements for the requested file, and applying, by the hardware processor, the access rules to the requested file.