Dynamic Data Protection via Classification and Lifecycle Adaptation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Corporate data protection in modern computer networks is inadequate due to the increased risk of information leakage through personal devices and external networks, as existing solutions like network sniffers, agent programs, and digital rights management systems face limitations in detecting and preventing unauthorized access and data transfer, especially when data is copied to removable media or accessed externally.
Innovation Solution
A system and method for automatically classifying data items based on their profiles, applying dynamic protection rules that adapt throughout the data's lifecycle, including encryption and access controls, using a protection management server and agent application to enforce policies across various locations and devices, ensuring secure access and preventing unauthorized duplication or transmission.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If network sniffers are installed to monitor data transmission, then information leakage detection capability is improved, but the system cannot detect leaks through removable media or external email accounts, and can be easily overcome by encryption
Solution Approach 1:
The protection system is divided into multiple independent components: network sniffers for network monitoring, agents on individual computers for local control, and policies for different data types. Each component handles specific leakage vectors, providing comprehensive coverage without requiring a single solution to address all scenarios.
Solution Approach 2:
The agent program serves multiple functions: it controls data access, monitors removable media usage, restricts external email communications, and enforces security policies locally. This multi-functional approach allows a single component to address various leakage vectors that network sniffers alone cannot detect.
2Ease of operation
If agent programs are installed on employee computers to monitor and control data usage, then local data access control is improved, but the agent can be circumvented by booting from a different operating system, and protection is lost once data leaves the employee station
Solution Approach 1:
The system applies protection measures in advance by encrypting data at rest on employee computers and binding it to specific hardware or user credentials. This preliminary encryption ensures that even if an attacker boots from a different operating system, the data remains protected because the decryption keys are not available without proper authentication.
Solution Approach 2:
The system creates secure copies of data with embedded protection metadata and digital rights management information. When data is copied to removable media or sent externally, the protection information travels with the data, ensuring continuous protection regardless of location or device.
3Reliability
If enterprise digital rights management system is implemented with persistent encryption, then access control after data delivery is improved, but implementation complexity increases and external partners face burden
Solution Approach 1:
The system introduces a digital rights management intermediary layer that sits between the data and access control mechanisms. This intermediary automatically enforces policies, manages encryption keys, and handles authentication without requiring external partners to implement complex systems. The intermediary translates security policies into automatic enforcement actions, reducing implementation burden.
4Reliability
If centralized mainframe computers with complete access control are used, then data security is improved, but the system lacks flexibility for modern personal computer networks with external connections
Solution Approach 1:
Instead of uniform centralized control, the system applies different security measures to different locations and data types. Network sniffers monitor specific network segments, agents on employee computers enforce local policies, and different protection levels are applied to different data categories. This localized approach maintains security while adapting to the distributed nature of modern networks.
Solution Approach 2:
The security system dynamically adapts to changing conditions by adjusting protection measures based on data sensitivity, user credentials, device security posture, and location. Policies are not static but can be modified in real-time, allowing the system to maintain security while accommodating the flexibility needed for modern personal computer networks with external connections.
Data Source
AI summary
A method of protecting data items in an organizational computer network, including, defining multiple information profiles for classifying the data item, defining rules for protecting the data item belonging to a specific information profile, classifying the data item according to the defined information profiles, applying a protection method to the data item responsive to the classification and the defined rules, automatically updating the classification of the data item responsive to a change in the content or location of the data item; and automatically transforming the applied protection method, throughout the lifecycle of the data item, responsive to a change in classification or location of the data item, according to the defined rules.


