Lightweight Fingerprint Database for Offline DLP

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions for protecting digital information from unauthorized disclosure at egress points face challenges such as high costs and inefficiencies with local fingerprint databases and scalability and latency issues with remote fingerprint servers, especially in environments with numerous egress points and offline scenarios.

Innovation Solution

Implementing locally stored lightweight fingerprint databases at egress points, which are compressed and updated via a remote server, allowing for efficient monitoring and protection even when disconnected from the network, and using a combined approach for fingerprint lookups that reduces network requests and latency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If local fingerprint databases are maintained at every egress point, then protection coverage is improved, but storage cost and maintenance complexity increase prohibitively

Engineering Contradiction:
Improveprotection coverageVSAvoiddatabase maintenance complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the fingerprint database into two parts: a complete master database maintained centrally at the fingerprint server, and a lightweight local cache stored at each protect agent. This segmentation allows each component to have optimized characteristics - the central server holds comprehensive data while agents hold only essential lookup information, resolving the contradiction between complete protection coverage and manageable maintenance complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Instead of maintaining full fingerprint databases at each egress point, the system creates simplified copies (lightweight fingerprint databases) that contain only the essential lookup functionality. These copies are generated from the master database and maintained automatically, providing protection coverage without the burden of managing large databases at every location.

Inventive Principle:
Principle #26Copying

2Quantity of substance

If remote fingerprint servers are used for fingerprint lookups, then storage requirements are reduced, but network latency and scalability issues arise

Engineering Contradiction:
Improvestorage requirementsVSAvoidlookup latency
Core Design Contradiction:
Quantity of substanceVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-computing and caching lightweight fingerprint databases at each protect agent before actual fingerprint lookups are needed. This preliminary local preparation eliminates the need for real-time network communication during lookup operations, significantly reducing latency while maintaining minimal storage requirements at agents.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements local quality by giving each protect agent its own optimized lightweight fingerprint database tailored for rapid local lookups. This local optimization reduces dependency on remote servers for routine operations, minimizing network latency while the central server maintains the complete database for updates and offline verification.

Inventive Principle:
Principle #3Local quality

3Measurement precision

If fingerprint databases include metadata for location and origin information, then verification accuracy is improved, but database size increases

Engineering Contradiction:
Improveverification accuracyVSAvoiddatabase size
Core Design Contradiction:
Measurement precisionVSVolume of stationary object

Solution Approach 1:

The system extracts only the essential elements needed for fingerprint verification from the complete fingerprint data structure. The lightweight fingerprint database contains minimal necessary information for accurate matching, while comprehensive metadata (location, origin, etc.) is maintained separately in the central master database. This extraction allows accurate verification with minimal local storage requirements.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system applies partial action by including only the subset of metadata that is absolutely necessary for fingerprint lookup and verification in the local lightweight database. Full metadata completeness is achieved through selective inclusion - enough information is present locally to perform accurate verification, while excess metadata is handled by the central server.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS8555080B2Methods and systems for protect agents using distributed lightweight fingerprints
Publication Date: 2013.10.08 FREEDOM SOLUTIONS GROUP LLC
  • US8555080B2 patent drawing
  • US8555080B2 patent drawing
  • US8555080B2 patent drawing

AI summary

The present invention provides methods and systems to protect an organization's secure information from unauthorized disclosure. The present system uses protect agents installed across various egress points (e.g., email server, user's computer, etc.) to monitor information disclosed by a user. The present system also provides the use of lightweight fingerprint databases (LFD) to maintain a database of fingerprints associated with the organization's secure data. In one embodiment, the LFD is stored locally at the site of each protect agent such that the organization's secure information can be protected even when a protect agent is disconnected from the network. Methods and systems to compress fingerprints to achieve the lightweight fingerprint databases are also provided. In one embodiment, a combined approach, utilizing both the local lightweight fingerprint database and a remote fingerprint server comprising registered fingerprints is used to achieve overall protection of the organization's secure information.