Intermediary System for Detailed Data Access Auditing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems face challenges in identifying the source of unauthorized data leaks from corporate networks, as they typically only record basic access logs without detailed interaction data, making it difficult to track and audit user interactions with sensitive information.

Innovation Solution

An intermediary system is introduced that captures detailed user interaction data, such as scroll requests and text highlighting, and stores it for auditing purposes, allowing administrators to track which users accessed specific information within documents and ensuring sensitive content is not sent to users who did not view it, while also providing a secure and compliant data handling solution.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If basic access logs are recorded without detailed interaction data, then system complexity is reduced and ease of operation is improved, but the ability to identify data leak sources and audit user interactions is insufficient

Engineering Contradiction:
Improveaudit trail detailVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

An intermediary system is introduced between the content delivery system and users. This intermediary captures detailed user interaction data (scroll requests, text highlighting, time spent viewing) without requiring changes to the existing content delivery infrastructure. The intermediary acts as a mediator that transparently logs interactions while maintaining the original system's simplicity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system separates the auditing function from the content delivery function. The intermediary system handles detailed interaction tracking and audit trail generation, while the original content delivery system continues to operate independently. This segmentation allows detailed auditing without complicating the core content delivery system.

Inventive Principle:
Principle #1Segmentation

2Reliability

If detailed user interaction data is captured and stored, then data security and audit capability are improved, but data storage requirements and processing overhead increase

Engineering Contradiction:
Improvedata securityVSAvoiddata storage volume
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent extracts only the most relevant interaction data for security auditing purposes, such as scroll requests, text highlighting actions, and time spent viewing specific portions. Rather than storing all possible interaction data, the system selectively captures data that is most indicative of potential data leaks or policy violations, reducing storage requirements while maintaining security effectiveness.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If content is delivered directly to users without intermediary processing, then delivery speed is improved, but the ability to track and control sensitive information distribution is reduced

Engineering Contradiction:
Improveinformation controlVSAvoidcontent delivery speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The intermediary system is designed to minimize impact on content delivery speed while enabling detailed tracking. It captures interaction data in real-time without blocking or significantly delaying content transmission. The intermediary processes and logs user interactions asynchronously where possible, maintaining near-real-time content delivery while enabling comprehensive audit trails.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10664538B1Data security and data access auditing for network accessible content
Publication Date: 2020.05.26 AMAZON TECH INC
  • US10664538B1 patent drawing
  • US10664538B1 patent drawing
  • US10664538B1 patent drawing

AI summary

Systems, methods, and computer-readable media are described for capturing detailed data access audit trails identifying the portions of pages or other files accessed by users from a specific network content source. A graphical representation of a page or file may be rendered by an intermediary system, and an initial portion of the graphical representation may be sent to a user device along with control data. The user device may send interaction data to the intermediary system as the user interacts with the page or file, which may result in additional graphical content being delivered to the user device by the intermediary system. In the event of a corporate data leak or for other data access audit purposes, a system administrator may search stored interaction data to identify which users accessed or viewed specific information within one or more pages or files.