Endpoint Compliance Assessment for Secure Data Dissemination

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Secure data stores face challenges in protecting sensitive information once data is extracted, as existing systems struggle to control and regulate access and dissemination effectively, leading to potential leaks and security breaches.

Innovation Solution

A computer-implemented system assesses endpoints for compliance with security policies, implementing actions such as disabling network communications or preventing further data dissemination if non-compliant, to ensure secure handling of sensitive data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If data is extracted from secure data store for shared access, then data usability and accessibility are improved, but data security and control are worsened

Engineering Contradiction:
Improvedata accessibilityVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an intermediary system that sits between the secure data store and endpoints. This intermediary monitors data extraction, assesses endpoint compliance with security policies, and controls data dissemination. The intermediary acts as a mediator that enables data access while maintaining security through continuous compliance verification and automated response actions.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If access restrictions are implemented in secure data store, then data security is improved, but data sharing capability is worsened

Engineering Contradiction:
Improvedata securityVSAvoiddata sharing capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic access control where security restrictions are not static but adapt based on real-time endpoint compliance assessments. The system continuously monitors endpoints and dynamically adjusts data sharing capabilities - allowing access when compliant, restricting when non-compliant. This dynamic approach enables flexible data sharing while maintaining security adaptability.

Inventive Principle:
Principle #15Dynamics

3Reliability

If endpoint compliance monitoring is implemented, then data security control is improved, but system complexity is worsened

Engineering Contradiction:
Improvesecurity controlVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service mechanisms where endpoints automatically assess their own compliance status with security policies and report back to the monitoring system. The system provides self-service compliance verification, reducing the need for complex manual monitoring infrastructure. Endpoints autonomously determine their compliance state, simplifying the overall system architecture while maintaining rigorous security control.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11763019B2Protecting sensitive information from a secure data store
Publication Date: 2023.09.19 SOPHOS LTD
  • US11763019B2 patent drawing
  • US11763019B2 patent drawing

AI summary

In embodiments of the present invention improved capabilities are described for the steps of receiving an indication that a computer facility has access to a secure data store, causing a security parameter of a storage medium local to the computer facility to be assessed, determining if the security parameter is compliant with a security policy relating to computer access of the remote secure data store, and in response to an indication that the security parameter is non-compliant, cause the computer facility to implement an action to prevent further dissemination of information, to disable access to network communications, to implement an action to prevent further dissemination of information, and the like.