Mid-Link Forensic Inspection With Unique Markers for Cloud Data Leaks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cloud-based systems face challenges in controlling user activities on computing devices, particularly with bring your own device (BYOD) policies, leading to data leaks and security threats due to unsecured networks and limited data protection capabilities, with conventional security systems struggling to handle continuous synchronization between endpoints and cloud services.

Innovation Solution

An electronic inspection system comprising user endpoints, end-link servers, and a mid-link server that models interactions using an application layer model, differentiates data objects, and analyzes them based on policies to enforce security measures, including embedding unique markers for data tracking and threat detection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional security systems are used to control user activities on computing devices, then data protection is provided, but control over data protection is limited and devices cannot be effectively locked down

Engineering Contradiction:
Improvedata protectionVSAvoidcontrol over data protection
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a mid-link server as an intermediary component positioned between user endpoints and end-link servers. This mid-link server acts as a mediator that intercepts and inspects data objects in transit, enabling centralized security control without requiring direct modification of endpoint devices. The mid-link server differentiates data objects, analyzes them against policies, and determines context, thereby providing effective data protection control in BYOD environments where traditional device locking is problematic.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If cloud services are used for data creation, editing, and storage, then business functionality is improved, but data leak risks increase through unauthorized file attachments, cloud-based storage, or improper collaboration

Engineering Contradiction:
Improvebusiness functionalityVSAvoiddata leak risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary action by embedding unique markers into data objects before they are transmitted through the cloud services infrastructure. The mid-link server proactively inspects data objects as they move between endpoints and cloud services, differentiating them and analyzing their context against security policies. This preliminary marking and inspection approach enables tracking and protection of data throughout its lifecycle in cloud environments, preventing unauthorized attachments, improper storage, and collaborative data leaks before they occur.

Inventive Principle:
Principle #10Preliminary action

3Speed

If continuous synchronization occurs between endpoints and cloud services, then data accessibility is improved, but security oversight is lost and data loss prevention becomes difficult

Engineering Contradiction:
Improvedata accessibilityVSAvoidsecurity oversight
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent maintains continuous security oversight through the mid-link server that continuously intercepts and inspects data objects during synchronization operations. Rather than interrupting the continuous synchronization between endpoints and cloud services, the mid-link server operates in parallel, continuously differentiating data objects, analyzing their context, and applying security policies in real-time. This enables both rapid data accessibility through uninterrupted synchronization and continuous security monitoring through persistent mid-link inspection.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS20250260740A1Mid-link forensic system for remote application environment based on unique markers
Publication Date: 2025.08.14 NETSKOPE INC
  • US20250260740A1 patent drawing
  • US20250260740A1 patent drawing
  • US20250260740A1 patent drawing

AI summary

The present disclosure provides an electronic inspection method and system comprising user endpoints, end-link servers belonging to a tenant, and a mid-link server. The mid-link server connects the user endpoints with an end-link server through tunnels. The mid-link server receives communication from the user endpoints through the tunnels, embeds a unique marker in data objects, store meta data of the unique markers in the meta database, match unique markers of the leaked data objects with unique markers stored in the database to identify the source of the leaked data objects and block the tunnel of user endpoint with leaked data objects.