Enterprise DLP Mediation for AI Service Data Exposure

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for managing enterprise data risks in network traffic, particularly with AI and ML services, are inadequate as they fail to consider the full context of interactions, leading to ineffective prevention of sensitive data disclosure or corruption.

Innovation Solution

A system that intercepts network traffic, generates vector embeddings, compares them to stored data elements, and applies sensitivity policies to ensure secure interactions with network services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If access blocking methods are used to prevent sensitive data disclosure, then data security is improved, but network service accessibility deteriorates

Engineering Contradiction:
Improvedata securityVSAvoidnetwork service accessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces an intermediary system that sits between users and network services, automatically analyzing requests and responses to identify and protect sensitive data. This intermediary performs vector embedding comparisons and policy enforcement without requiring users to manually block services, thus maintaining data security while preserving service accessibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces manual mechanical blocking methods with an automated AI-based system that uses vector embeddings, machine learning models, and automated policy enforcement. This substitution eliminates the need for users to manually block services while maintaining robust data protection through automated sensitive data identification and filtering.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If user training methods are used to control data use, then data security awareness is improved, but operational efficiency deteriorates

Engineering Contradiction:
Improvedata security awarenessVSAvoidoperational efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements a self-service system where the automated data loss prevention infrastructure performs sensitive data identification, policy enforcement, and security monitoring without requiring user intervention or training. The system automatically conforms user interactions to approved uses through backend processing, eliminating the need for ongoing user education while maintaining security standards.

Inventive Principle:
Principle #25Self-service

3Difficulty of detecting and measuring

If comprehensive monitoring is implemented to understand full context of interactions, then data security detection capability is improved, but system complexity increases

Engineering Contradiction:
Improvedetection capabilityVSAvoidsystem complexity
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The patent creates a universal data loss prevention system that handles multiple functions including network traffic monitoring, vector embedding generation, sensitive data identification, policy enforcement, and AI service management through a single integrated platform. This multi-functional approach consolidates complexity into one system rather than requiring separate tools for each function, making the comprehensive monitoring more manageable.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent transforms complex monitoring data into simplified vector embeddings that capture essential characteristics of data and interactions. By converting raw network traffic and data elements into standardized vector representations, the system can efficiently compare and analyze information without being overwhelmed by the complexity of raw data, thus improving detection capability while managing system complexity.

Inventive Principle:
Principle #35Parameter changes

4Measurement precision

If vector embedding comparison is used to identify sensitive data, then data identification accuracy is improved, but processing time increases

Engineering Contradiction:
Improvedata identification accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent applies partial action by performing vector embedding comparisons selectively based on risk assessment and context analysis. The system identifies and focuses computational resources on evaluating data elements that are most likely to be sensitive based on initial filtering, rather than performing exhaustive comparisons on all data. This approach maintains high identification accuracy for critical data while reducing overall processing time through intelligent prioritization.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20260058993A1Data Loss Prevention in an Enterprise Data Management and Monitoring System
Publication Date: 2026.02.26 SUREPATH AI INC
  • US20260058993A1 patent drawing
  • US20260058993A1 patent drawing
  • US20260058993A1 patent drawing

AI summary

Data loss prevention systems and methods in an enterprise data management and monitoring system may intercept a request to a network service, e.g., a service using an artificial intelligence and/or machine learning model. The systems and methods may represent contents of the request via one or more vector embeddings, which may be compared to vector embeddings corresponding to respective ones of a plurality of sensitive data elements in the enterprise. The data loss prevention system and methods may apply various data sensitivity policies based on determinations of whether sensitive data of the enterprise is included in the request to the network service, e.g., by blocking or redacting the request to prevent exposure of the sensitive data to the network service.