GUI Sensitive Information Management System
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for protecting sensitive information in enterprise networks are inadequate, as they are difficult to manage, costly, and ineffective in monitoring encrypted network traffic, leading to potential data leakage and theft, which poses a significant security threat.
Innovation Solution
A graphical user interface (GUI) based system that monitors and manages sensitive information within an enterprise network by providing static and dynamic views of sensitive document locations, security policies, and information flow, allowing users to visualize and manage sensitive information, detect leaks, and identify involved parties.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional secure computer approach is used to store and manage sensitive information, then security protection is improved, but ease of operation deteriorates due to cumbersome procedures and difficulty in document access and modification
Solution Approach 1:
The patent introduces a secure document server as an intermediary between users and sensitive documents. The server implements automated security policies, digital rights management, and access control mechanisms that protect sensitive information without requiring users to physically access secured computers. This mediator handles security enforcement transparently, allowing users to access and modify documents through standard network protocols while maintaining security protections.
Solution Approach 2:
The patent replaces the mechanical approach of physically securing documents in controlled-access computer rooms with an electronic/digital security system. Instead of requiring physical presence and manual authorization procedures, the system uses digital certificates, encrypted communications, and automated policy enforcement to protect sensitive documents. This substitution eliminates the need for users to visit secured locations while maintaining or enhancing security.
2Difficulty of detecting and measuring
If network sniffer approach is used to monitor network traffic for sensitive information, then detection capability is improved, but network performance deteriorates due to traffic analysis overhead and encrypted traffic cannot be analyzed
Solution Approach 1:
The patent implements watermarks and digital signatures on sensitive documents before they are transmitted over the network. These preliminary markers are embedded in the document content or metadata, allowing the system to identify sensitive information without analyzing the actual document content during transmission. This approach enables detection of sensitive information flow while avoiding the need to decrypt or deeply inspect encrypted traffic, thus maintaining network performance.
Solution Approach 2:
The patent introduces a document management server as an intermediary that monitors and tracks sensitive document transmissions. Instead of using network sniffers to analyze encrypted traffic, the server receives notifications from client applications about document access and transmission events. This mediator approach allows the system to detect sensitive information flow through application-layer events rather than network-layer packet analysis, avoiding performance degradation and working around encryption limitations.
Data Source
AI summary
A system and method provides a graphical user interface (GUI) for users to monitor and manage sensitive information within an enterprise network. The GUI can provide users with information, such as the presence of input/output devices (I/O device), the location of documents containing sensitive information (sensitive documents), and the status of local security policy. The GUI can also provide users with real-time information, such as the occurrence of local security policy violations, the life-cycle of sensitive documents, and the sensitive information dynamic flow within the enterprise network.


