Dynamic Data Protection via Classification and Lifecycle Adaptation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Corporate data protection in modern computer networks is inadequate due to the increased risk of information leakage through personal devices and external networks, as existing solutions like network sniffers, agent programs, and digital rights management systems face limitations in detecting and preventing unauthorized access and data transfer, especially when data is copied to removable media or accessed externally.

Innovation Solution

A system and method for automatically classifying data items based on their profiles, applying dynamic protection rules that adapt throughout the data's lifecycle, including encryption and access controls, using a protection management server and agent application to enforce policies across various locations and devices, ensuring secure access and preventing unauthorized duplication or transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If network sniffers are installed to monitor data transmission, then information leakage detection capability is improved, but the system cannot detect leaks through removable media or external email accounts, and can be easily overcome by encryption

Engineering Contradiction:
Improveinformation leakage detection capabilityVSAvoidcoverage of detection methods
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The protection system is divided into multiple independent components: network sniffers for network monitoring, agents on individual computers for local control, and policies for different data types. Each component handles specific leakage vectors, providing comprehensive coverage without requiring a single solution to address all scenarios.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The agent program serves multiple functions: it controls data access, monitors removable media usage, restricts external email communications, and enforces security policies locally. This multi-functional approach allows a single component to address various leakage vectors that network sniffers alone cannot detect.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If agent programs are installed on employee computers to monitor and control data usage, then local data access control is improved, but the agent can be circumvented by booting from a different operating system, and protection is lost once data leaves the employee station

Engineering Contradiction:
Improvelocal data access controlVSAvoidprotection consistency
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system applies protection measures in advance by encrypting data at rest on employee computers and binding it to specific hardware or user credentials. This preliminary encryption ensures that even if an attacker boots from a different operating system, the data remains protected because the decryption keys are not available without proper authentication.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The system creates secure copies of data with embedded protection metadata and digital rights management information. When data is copied to removable media or sent externally, the protection information travels with the data, ensuring continuous protection regardless of location or device.

Inventive Principle:
Principle #26Copying

3Reliability

If enterprise digital rights management system is implemented with persistent encryption, then access control after data delivery is improved, but implementation complexity increases and external partners face burden

Engineering Contradiction:
Improveaccess control enforcementVSAvoidsystem implementation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system introduces a digital rights management intermediary layer that sits between the data and access control mechanisms. This intermediary automatically enforces policies, manages encryption keys, and handles authentication without requiring external partners to implement complex systems. The intermediary translates security policies into automatic enforcement actions, reducing implementation burden.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If centralized mainframe computers with complete access control are used, then data security is improved, but the system lacks flexibility for modern personal computer networks with external connections

Engineering Contradiction:
Improvedata security controlVSAvoidnetwork flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

Instead of uniform centralized control, the system applies different security measures to different locations and data types. Network sniffers monitor specific network segments, agents on employee computers enforce local policies, and different protection levels are applied to different data categories. This localized approach maintains security while adapting to the distributed nature of modern networks.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The security system dynamically adapts to changing conditions by adjusting protection measures based on data sensitivity, user credentials, device security posture, and location. Policies are not static but can be modified in real-time, allowing the system to maintain security while accommodating the flexibility needed for modern personal computer networks with external connections.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10367851B2System and method for automatic data protection in a computer network
Publication Date: 2019.07.30 MICROSOFT TECHNOLOGY LICENSING LLC
  • US10367851B2 patent drawing
  • US10367851B2 patent drawing
  • US10367851B2 patent drawing

AI summary

A method of protecting data items in an organizational computer network, including, defining multiple information profiles for classifying the data item, defining rules for protecting the data item belonging to a specific information profile, classifying the data item according to the defined information profiles, applying a protection method to the data item responsive to the classification and the defined rules, automatically updating the classification of the data item responsive to a change in the content or location of the data item; and automatically transforming the applied protection method, throughout the lifecycle of the data item, responsive to a change in classification or location of the data item, according to the defined rules.