Isolated Processing Environment for Secure Data Filtering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current data security solutions fail to effectively prevent information leakage from authorized users and malicious code exploiting access privileges, especially in day-to-day communication channels essential for business operations, and often require separate secure environments that limit network infrastructure usage.
Innovation Solution
An apparatus and method that create an isolated processing environment on an endpoint computer with defined boundaries and channels for data passage, incorporating filters and restrictors to control data output and input according to predefined policies, ensuring secure data handling within and outside the secure environment.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If device control methods are used to eliminate user ability to write information to outgoing data channels, then information leakage is prevented, but protection against transfer via day-to-day communication channels such as e-mail, web, instant messaging is lost
Solution Approach 1:
The patent segments the outgoing data channels into two categories: controlled channels (portable memory devices, modems, Bluetooth, WiFi, CD writers, floppy discs) and uncontrolled channels (e-mail, web, instant messaging). Device control methods are applied selectively to segmented channels based on their security requirements and business essentiality.
Solution Approach 2:
Different security control qualities are applied to different communication channels. High-security control is applied to local devices where information leakage risk is high, while allowing free flow on network communication channels that are essential for business operations.
2Reliability
If pattern based blocking is used to analyze and block information transport, then unauthorized information transfer is prevented, but legitimate business communication may be restricted
Solution Approach 1:
The patent introduces an intermediary classification mechanism that categorizes information into confidential and non-confidential types. This intermediary classification layer sits between the pattern-based blocking system and the actual data flow, allowing legitimate business communication to pass through while blocking only classified confidential information.
Solution Approach 2:
Information is classified and marked as confidential before it enters the communication channel. This preliminary classification action enables downstream systems to automatically identify and block only the classified information without interfering with unclassified legitimate business communication.
3Reliability
If authentication and content encryption are used to allow only authorized users to access confidential data, then unauthorized access is prevented, but authorized users or malicious code can still exploit access privileges to leak data
Solution Approach 1:
The patent segments the security control into two layers: access control (authentication and encryption) and transmission control (output blocking). While authentication and encryption prevent unauthorized access, a separate output blocking mechanism is introduced to prevent authorized users or malicious code from leaking data through classified information markers.
Solution Approach 2:
The patent converts the potential harm of authorized users having access to confidential data into a benefit by using the same classification markers that identify confidential information for access control purposes. These markers then serve a dual function: enabling authorized access while simultaneously triggering output blocking mechanisms to prevent data leakage.
4Reliability
If classification of organizational data and restricting operations of users is implemented, then confidential data protection is improved, but tradeoffs between protection and usability are created
Solution Approach 1:
The patent implements automatic classification and marking of confidential information without requiring manual user intervention. The system self-services by identifying confidential data, applying classification markers, and enforcing output restrictions automatically, thereby maintaining protection while minimizing impact on user operation flexibility.
Data Source
AI summary
Apparatus for securing data, comprising: an isolated processing environment having a boundary across which data cannot cross and a channel for allowing data to cross the boundary. A filter restricts data passage across the channel. Protected data is initially located in a secure area and is only released to such a secure processing environment so that access for authorized users to the secure data is available, but subsequent release of the secure data by the authorized users to the outside world is controlled.


