Enterprise Data Security via Interception and Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprise networks face challenges in securing and controlling data when using external storage providers, as they risk exposing sensitive data to untrusted third parties and lack granular access control, leading to potential unauthorized access and data exposure.

Innovation Solution

Implementing a method where a security agent intercepts requests to access files, encrypts them with a unique key, and manages access permissions through a centralized service, ensuring only authorized users can decrypt and access the files, even when transmitted to external storage providers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If data is transmitted to external storage providers, then storage capacity and accessibility are improved, but data security and control are worsened

Engineering Contradiction:
Improvestorage accessibilityVSAvoiddata security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system performs preliminary encryption of data before transmission to external storage providers. Security agents on client computers encrypt files using encryption keys managed by a centralized service before the files are uploaded to external storage, ensuring data is protected in advance rather than relying on post-transmission security measures.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

A centralized service acts as an intermediary between clients and external storage providers for key management. The centralized service distributes encryption keys to authorized users and revokes access when needed, mediating the security control without requiring direct trust between clients and external storage providers.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If external storage providers are used, then storage flexibility is improved, but access control granularity is worsened

Engineering Contradiction:
Improvestorage flexibilityVSAvoidaccess control
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The system segments access control by organizing users into groups and assigning different encryption keys to different groups. This allows fine-grained control where specific groups can access specific files, maintaining the flexibility of external storage while implementing detailed access control policies similar to enterprise networks.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements dynamic access control where encryption keys can be distributed or revoked by the centralized service at any time. This allows access permissions to be changed dynamically without requiring changes to the external storage provider's infrastructure, enabling flexible authorization policies to be applied and modified as needed.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP2712477B1Systems and methods for secure handling of data
Publication Date: 2020.05.06 CITRIX SYSTEMS INC
  • EP2712477B1 patent drawingFigure 1A
  • EP2712477B1 patent drawingFigure 1B
  • EP2712477B1 patent drawingFigure 1C

AI summary

The methods and systems described herein provide for secure implementation of external storage providers in an enterprise setting. Specifically, the present invention provides for allowing the secure use of processes that may transmit files to external storage providers or access files from an external storage provider. In some arrangements, process, such as an untrusted process, may request access to a file. A security agent may intercept the request and encrypt the file. The file can then be transmitted to the external storage provider. A user may subsequently request access to the file. A security agent may intercept a message in connection with this request, determine whether the user is authorized to access the file, and decrypt the file.