Selective File Protection via Policy Scanning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing encryption systems cause computational overhead and fail to ensure continuous protection of sensitive information on portable devices, as files may be inadvertently or intentionally moved out of protected directories, leaving them unprotected and at risk of data compromise.
Innovation Solution
A remote device receives a policy definition, scans the file system to identify and protect files based on keywords, directory paths, and metadata, applying actions like encryption, rights management, or deletion to ensure continuous protection and generate reports for compliance verification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If encryption systems are applied to the entire data storage system, then data protection is improved, but computational overhead increases
Solution Approach 1:
The patent applies encryption selectively to specific files or directories containing sensitive information rather than encrypting the entire data storage system. This local approach protects critical data while avoiding the computational overhead of encrypting all files, thus resolving the contradiction between data protection and computational resource consumption.
2Use of energy by moving object
If encryption is applied to limited files in specific folders, then computational overhead is reduced, but files may be left unprotected when moved outside protected directories
Solution Approach 1:
The patent implements a monitoring mechanism that tracks file movements and automatically applies encryption to files that leave protected directories. This feedback loop ensures continuous protection of sensitive files regardless of their location, resolving the contradiction by maintaining data protection while avoiding unnecessary encryption of non-sensitive files.
Solution Approach 2:
The system pre-identifies files containing sensitive information using keywords, metadata, or file type analysis before they are moved. By preparing protection measures in advance and automatically applying encryption when files are detected outside protected directories, the system maintains continuous protection without requiring full system encryption.
3Speed
If users move files out of protected directories intentionally, then access speed is improved, but data protection is compromised
Solution Approach 1:
The patent implements dynamic encryption that automatically adjusts based on file location and sensitivity. Files containing sensitive information maintain encryption status regardless of whether they are in protected or unprotected directories, while non-sensitive files can be accessed without encryption. This dynamic approach allows fast access to non-sensitive files while maintaining protection of sensitive data, resolving the contradiction between access speed and data protection.
Data Source
AI summary
A remote device may receive a policy definition, search a file system for files that are to be protected, and disposition identified files to protect the files. After completing the protection, a report is generated and transmitted to a centralized location. The policy definition may include keywords, directory paths, metadata, or other information that may be used to identify files for protection. After identification, the files may be dispositioned by removal, tagging, encrypting, applying rights management, or other actions.


