Mitigating Data Leakage in Multi-Site File Sharing via Segmented Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud computing environments face challenges in preventing data leakage due to inappropriate file sharing, particularly in dynamic collaboration systems where user roles and access controls are constantly changing, leading to security concerns and potential unauthorized access.

Innovation Solution

Implementing a method that employs mandatory access control policies with a flexible discretionary control mechanism, attribute-based recipient recommendations, and dynamic profile updates to mitigate data leakage by restricting sharing scopes and suggesting appropriate recipients based on past collaboration activities and security protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If mandatory access control policies are implemented to restrict file sharing scope, then data leakage is reduced, but sharing flexibility is limited

Engineering Contradiction:
Improvedata leakage preventionVSAvoidsharing flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments access control into two distinct layers: mandatory access control (MAC) policies that define security boundaries and discretionary access control (DAC) policies that enable flexible sharing within those boundaries. This segmentation allows the system to simultaneously enforce security restrictions while permitting authorized users to share files freely within approved scopes, thus resolving the contradiction between data leakage prevention and sharing flexibility.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic profile updates that automatically adjust user attributes and sharing permissions based on real-time collaboration activities and organizational changes. This dynamic adaptation allows the system to maintain security policies while automatically adjusting sharing flexibility to match current organizational needs and user roles, preventing data leakage while preserving necessary sharing capabilities.

Inventive Principle:
Principle #15Dynamics

2Reliability

If organizational boundaries are enforced to prevent inappropriate file sharing, then security is improved, but collaboration across boundaries is hindered

Engineering Contradiction:
ImprovesecurityVSAvoidcollaboration ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces an intermediary layer of attribute-based access control that mediates between organizational security boundaries and user collaboration needs. This intermediary system evaluates user attributes, file properties, and contextual information to automatically determine appropriate access decisions, enabling secure cross-organizational collaboration without requiring manual security approvals for each sharing action.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the parameters of access control from static organizational boundaries to dynamic attribute-based permissions. By transforming security enforcement from a rigid boundary-based system to a flexible attribute-based system, the patent enables seamless collaboration across organizational boundaries while maintaining security through continuous evaluation of user attributes and contextual factors.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If discretionary sharing decisions are allowed for flexibility, then sharing capability is improved, but data leakage risk increases

Engineering Contradiction:
Improvesharing capabilityVSAvoiddata leakage risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by establishing mandatory access control policies and security boundaries before discretionary sharing decisions are made. User profiles are pre-configured with security attributes and permission levels, and file metadata is pre-marked with classification information. This preliminary setup enables users to share files discretionarily while automatically enforcing security constraints, thus maintaining sharing capability while preventing data leakage through pre-established security frameworks.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9928375B2Mitigation of data leakage in a multi-site computing infrastructure
Publication Date: 2018.03.27 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US9928375B2 patent drawing
  • US9928375B2 patent drawing
  • US9928375B2 patent drawing

AI summary

Embodiments of the invention relate to a method, system, and computer program product to dynamically mitigate data leakage in a file sharing environment. Mandatory access control policies are provided to address and maintain restrictions on file sharing both with respect to security rules of an organization and restrictions pertaining to discretionary sharing decisions. In addition, suggestions for potential recipients for file sharing are supported, as well as examination of abnormal recipients in response to the discretionary sharing decisions.