Local Signature Database for Mobile Data Leakage Prevention
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Resource-limited mobile devices face challenges in implementing traditional data leakage prevention due to memory and processing constraints, making it difficult to store and execute global signature databases required for effective data protection.
Innovation Solution
A local signature approach is implemented on mobile devices, where digital signatures are calculated and compared against a global database on an enterprise computer, with only sensitive signatures returned to the device for storage and policy enforcement, reducing the burden on the device's resources and enabling efficient data leakage prevention.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a global signature database is loaded onto mobile devices for data leakage prevention, then data protection effectiveness is improved, but memory capacity requirements increase significantly
Solution Approach 1:
The patent divides the global signature database into two parts: a server-side global database and device-side local signature databases. Each mobile device maintains only a local copy of signatures relevant to its data, segmenting the large global database into manageable portions that fit within limited device memory while maintaining effective protection.
Solution Approach 2:
The patent extracts only the necessary signature information from the global database and stores it locally on mobile devices. By taking out only the essential signature data rather than the entire global database, the system reduces memory requirements on devices while maintaining the ability to detect sensitive information leakage.
2Reliability
If a global signature database is executed on mobile devices, then data leakage prevention capability is improved, but processing speed requirements increase significantly
Solution Approach 1:
The patent segments the data leakage prevention process into server-side processing (where heavy computational tasks are performed) and device-side processing (where only lightweight signature comparison occurs). This segmentation allows mobile devices to maintain prevention capability without requiring high processing speeds for database operations.
Solution Approach 2:
The patent introduces a server as an intermediary that handles computationally intensive tasks such as generating and maintaining the global signature database. Mobile devices only perform simple local comparisons using cached signatures, eliminating the need for high processing speeds on the devices themselves while maintaining effective prevention capability.
3Reliability
If traditional DLP products are deployed on mobile devices, then data protection coverage is improved, but device complexity increases
Solution Approach 1:
The patent segments the DLP system into a server component and a mobile device component, each with distinct responsibilities. The server handles complex database operations while mobile devices perform simple local checks. This segmentation maintains comprehensive protection coverage while keeping individual device complexity low and manageable.
Data Source
AI summary
When a resource-limited device (such as a mobile telephone) joins a network associated with an enterprise, the agent in the device generates digital signatures for all the files in the device and sends them to an enterprise controller. The controller compares them to the global signature database; it filters out the sensitive digital signatures and feeds them back to the agent in the device. The agent receives the feedback of digital signatures and consolidates them into its own local signature database. The agent analyzes each file that is attempting to be output from the device according to the local signature database and DLP policy. If the signature of the file is present in the local database then the action to output file is blocked. If a new file is created on the device, the agent generates and sends its digital signature to the controller for inspection. If the signature is sensitive, this new digital signature will be placed into the local signature database. If the DLP controller updates the global signature database, the device will send its signatures once again for comparison.


