Mitigating Data Leakage in Multi-Site File Sharing via Segmented Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cloud computing environments face challenges in preventing data leakage due to inappropriate file sharing, particularly in dynamic collaboration systems where user roles and access controls are constantly changing, leading to security concerns and potential unauthorized access.
Innovation Solution
Implementing a method that employs mandatory access control policies with a flexible discretionary control mechanism, attribute-based recipient recommendations, and dynamic profile updates to mitigate data leakage by restricting sharing scopes and suggesting appropriate recipients based on past collaboration activities and security protocols.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If mandatory access control policies are implemented to restrict file sharing scope, then data leakage is reduced, but sharing flexibility is limited
Solution Approach 1:
The patent segments access control into two distinct layers: mandatory access control (MAC) policies that define security boundaries and discretionary access control (DAC) policies that enable flexible sharing within those boundaries. This segmentation allows the system to simultaneously enforce security restrictions while permitting authorized users to share files freely within approved scopes, thus resolving the contradiction between data leakage prevention and sharing flexibility.
Solution Approach 2:
The patent implements dynamic profile updates that automatically adjust user attributes and sharing permissions based on real-time collaboration activities and organizational changes. This dynamic adaptation allows the system to maintain security policies while automatically adjusting sharing flexibility to match current organizational needs and user roles, preventing data leakage while preserving necessary sharing capabilities.
2Reliability
If organizational boundaries are enforced to prevent inappropriate file sharing, then security is improved, but collaboration across boundaries is hindered
Solution Approach 1:
The patent introduces an intermediary layer of attribute-based access control that mediates between organizational security boundaries and user collaboration needs. This intermediary system evaluates user attributes, file properties, and contextual information to automatically determine appropriate access decisions, enabling secure cross-organizational collaboration without requiring manual security approvals for each sharing action.
Solution Approach 2:
The patent changes the parameters of access control from static organizational boundaries to dynamic attribute-based permissions. By transforming security enforcement from a rigid boundary-based system to a flexible attribute-based system, the patent enables seamless collaboration across organizational boundaries while maintaining security through continuous evaluation of user attributes and contextual factors.
3Adaptability or versatility
If discretionary sharing decisions are allowed for flexibility, then sharing capability is improved, but data leakage risk increases
Solution Approach 1:
The patent applies preliminary action by establishing mandatory access control policies and security boundaries before discretionary sharing decisions are made. User profiles are pre-configured with security attributes and permission levels, and file metadata is pre-marked with classification information. This preliminary setup enables users to share files discretionarily while automatically enforcing security constraints, thus maintaining sharing capability while preventing data leakage through pre-established security frameworks.
Data Source
AI summary
Embodiments of the invention relate to a method, system, and computer program product to dynamically mitigate data leakage in a file sharing environment. Mandatory access control policies are provided to address and maintain restrictions on file sharing both with respect to security rules of an organization and restrictions pertaining to discretionary sharing decisions. In addition, suggestions for potential recipients for file sharing are supported, as well as examination of abnormal recipients in response to the discretionary sharing decisions.


