Gateway Information Protection for External Data Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Internal networks face security risks when users access sensitive information via external networks, as data downloaded or uploaded can be disclosed to unauthorized parties.

Innovation Solution

A gateway with an information protection component is used to apply selective information protection based on user identity, device health, data classification, and location, ensuring persistent protection even after data is sent to an external destination device.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users are allowed to access internal network data via external networks, then user mobility and data accessibility are improved, but security risk increases

Engineering Contradiction:
Improvedata accessibilityVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The gateway applies information protection to data before sending it to external destination devices. This preliminary protection ensures that even if data is accessed from external networks, the security risk is mitigated because the protection is already in place before the data leaves the internal network.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The gateway acts as an intermediary device between the internal network and external networks. It evaluates information about the destination device, data, and user, then selectively applies information protection based on security policies. This intermediary role allows the system to maintain security while enabling external access.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If data is downloaded to external devices, then user mobility is improved, but information disclosure risk increases

Engineering Contradiction:
Improveuser mobilityVSAvoidinformation disclosure
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The gateway applies information protection to data before it is downloaded to external devices. This ensures that even when data is accessed from external networks, the protection persists and prevents information disclosure to unauthorized parties.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system changes the state of the data by applying information protection based on evaluated parameters such as destination device information, data classification, and user identity. This parameter-based approach ensures that protection is applied appropriately while allowing legitimate access.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If information protection is applied to data, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidgateway complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The gateway serves as an intermediary that centralizes the information protection logic. By evaluating information about destination devices, data, and users at a single point, the system manages security complexity in one location rather than distributing it across multiple devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The gateway uses parameter-based evaluation (destination device information, data classification, user identity) to determine whether to apply protection. This approach allows the system to maintain security while avoiding unnecessary complexity by only applying protection when needed based on the evaluated parameters.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8341720B2Information protection applied by an intermediary device
Publication Date: 2012.12.25 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8341720B2 patent drawing
  • US8341720B2 patent drawing
  • US8341720B2 patent drawing

AI summary

Methods, systems, and computer-readable media are disclosed for applying information protection. A particular method includes receiving a data file at a gateway coupled to a network. The data file is to be sent to a destination device that is external to the network. The method also includes selectively applying information protection to the data file at the gateway prior to sending the data file to the destination device. The information protection is selectively applied based on information associated with the destination device, information associated with the data file, and information associated with a user of the destination device.