Indexed Document Matching for Cloud DLP
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional Data Loss Prevention (DLP) systems struggle with unstructured documents and encrypted data, leading to blind spots in data security, especially as users access cloud-based applications directly from various locations, increasing the risk of unintentional or malicious data loss due to lack of visibility and control.
Innovation Solution
The implementation of Indexed Document Matching (IDM) technology within a cloud-based system, which identifies and protects content by matching whole or partial documents through cryptographic hashes, allowing for exact, subset, and similar text detection, providing a scoring system for data leak protection across multiple user-defined profiles.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional DLP approaches use software agents and physical appliances, then data protection is provided within the network perimeter, but users accessing cloud applications directly create blind spots and bypass security controls
Solution Approach 1:
The patent introduces a cloud-based DLP service as an intermediary between users and data resources. This service intercepts and inspects data in motion through SSL/TLS decryption and inspection, allowing security controls to be applied even when users access cloud applications directly. The service acts as a mediator that maintains security visibility without preventing cloud access flexibility.
Solution Approach 2:
The patent moves DLP security controls from the traditional network perimeter dimension to a cloud-based dimension. By deploying DLP services in the cloud, the system extends security coverage to remote users and cloud applications, creating a new dimensional layer of protection that follows users regardless of location or access method.
2Reliability
If SSL/TLS encryption is used to protect data in transit, then data confidentiality is improved, but inspection capability deteriorates due to difficulty and cost
Solution Approach 1:
The patent introduces a trusted intermediary that performs SSL/TLS inspection by acting as a man-in-the-middle proxy. The system uses certificate-based authentication and controlled decryption to inspect encrypted traffic while maintaining security. This intermediary approach allows inspection capability without completely breaking the encryption protection, as the system selectively decrypts and re-encrypts traffic under controlled conditions.
Solution Approach 2:
The patent changes the encryption parameter state by using selective decryption and re-encryption. The system maintains encryption for most traffic but temporarily changes the encrypted state to decrypted state for inspection purposes, then restores encryption. This parameter change allows inspection while preserving overall data confidentiality.
3Measurement precision
If DLP systems focus on structured documents with specific formats, then detection accuracy for exact data matching is improved, but unstructured document analysis capability deteriorates
Solution Approach 1:
The patent creates a universal DLP system that handles multiple document types through a single platform. The cloud-based service provides multi-functional capabilities to detect and protect both structured documents (with exact data matching for formats like SSN, credit cards) and unstructured documents (free-form text, emails, chat messages). This universal approach eliminates the need for separate specialized systems.
Solution Approach 2:
The patent implements dynamic detection capabilities that adapt to different document structures. The system uses machine learning and contextual analysis to dynamically adjust detection methods based on the document type being analyzed. For structured documents, it applies rigid format-based rules; for unstructured documents, it employs flexible semantic analysis and pattern recognition.
4Reliability
If cloud-based DLP service inspects all data traffic, then data loss protection is improved, but processing capability and latency increase
Solution Approach 1:
The patent applies partial inspection rather than inspecting all data traffic equally. The system uses intelligent filtering to identify and prioritize inspection of sensitive data types and high-risk transactions. Not all traffic receives the same level of inspection depth, allowing the system to protect against data loss while reducing overall processing burden and latency for non-critical traffic.
Data Source
AI summary
Systems and methods include obtaining a file to be checked for Data Loss Prevention (DLP); determining a cryptographic hash of the file and comparing the cryptographic hash to corresponding cryptographic hashes of indexed files; responsive to a match between the cryptographic hash and one of the corresponding cryptographic hashes, determining a DLP match and performing an action based thereon; responsive to no match, extracting text from the file and creating an ordered sequence of hashes of variable length chunks of the extracted text; and determining the DLP match with one of the indexed files based on comparing the ordered sequence of hashes with corresponding ordered sequence of hashes of the indexed files.


