Local Signature Database for Mobile Data Leakage Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Resource-limited mobile devices face challenges in implementing traditional data leakage prevention due to memory and processing constraints, making it difficult to store and execute global signature databases required for effective data protection.

Innovation Solution

A local signature approach is implemented on mobile devices, where digital signatures are calculated and compared against a global database on an enterprise computer, with only sensitive signatures returned to the device for storage and policy enforcement, reducing the burden on the device's resources and enabling efficient data leakage prevention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a global signature database is loaded onto mobile devices for data leakage prevention, then data protection effectiveness is improved, but memory capacity requirements increase significantly

Engineering Contradiction:
Improvedata protection effectivenessVSAvoidmemory capacity requirement
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent divides the global signature database into two parts: a server-side global database and device-side local signature databases. Each mobile device maintains only a local copy of signatures relevant to its data, segmenting the large global database into manageable portions that fit within limited device memory while maintaining effective protection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts only the necessary signature information from the global database and stores it locally on mobile devices. By taking out only the essential signature data rather than the entire global database, the system reduces memory requirements on devices while maintaining the ability to detect sensitive information leakage.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If a global signature database is executed on mobile devices, then data leakage prevention capability is improved, but processing speed requirements increase significantly

Engineering Contradiction:
Improvedata leakage prevention capabilityVSAvoidprocessing speed requirement
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent segments the data leakage prevention process into server-side processing (where heavy computational tasks are performed) and device-side processing (where only lightweight signature comparison occurs). This segmentation allows mobile devices to maintain prevention capability without requiring high processing speeds for database operations.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a server as an intermediary that handles computationally intensive tasks such as generating and maintaining the global signature database. Mobile devices only perform simple local comparisons using cached signatures, eliminating the need for high processing speeds on the devices themselves while maintaining effective prevention capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If traditional DLP products are deployed on mobile devices, then data protection coverage is improved, but device complexity increases

Engineering Contradiction:
Improvedata protection coverageVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the DLP system into a server component and a mobile device component, each with distinct responsibilities. The server handles complex database operations while mobile devices perform simple local checks. This segmentation maintains comprehensive protection coverage while keeping individual device complexity low and manageable.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8286253B1Data leakage prevention for resource limited device
Publication Date: 2012.10.09 TREND MICRO INC
  • US8286253B1 patent drawing
  • US8286253B1 patent drawing
  • US8286253B1 patent drawing

AI summary

When a resource-limited device (such as a mobile telephone) joins a network associated with an enterprise, the agent in the device generates digital signatures for all the files in the device and sends them to an enterprise controller. The controller compares them to the global signature database; it filters out the sensitive digital signatures and feeds them back to the agent in the device. The agent receives the feedback of digital signatures and consolidates them into its own local signature database. The agent analyzes each file that is attempting to be output from the device according to the local signature database and DLP policy. If the signature of the file is present in the local database then the action to output file is blocked. If a new file is created on the device, the agent generates and sends its digital signature to the controller for inspection. If the signature is sensitive, this new digital signature will be placed into the local signature database. If the DLP controller updates the global signature database, the device will send its signatures once again for comparison.