Policy Enforcement Server for Mixed Media Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security solutions for enterprise networks, such as VPNs and DLP systems, fail to provide comprehensive control over sensitive communications traffic and content, especially in complex, multi-media, and multi-modal environments, and do not effectively integrate with emerging technologies like SOA and collaboration platforms like Google Wave, leading to disjointed security systems.

Innovation Solution

A policy enforcement server and distributed policy agents monitor and enforce policies across enterprise networks, using policy tags to assess and manage communications security, ensuring compliance by implementing appropriate measures such as encryption, access control, and secure routing, even outside the VPN trust circle, while integrating with diverse security schemes and media types.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If full encryption is applied across the enterprise (as in Sophos SafeGuard), then data security is improved, but processing burden and system overhead increase substantially

Engineering Contradiction:
Improvedata securityVSAvoidprocessing burden
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts the encryption function from a centralized enterprise-wide system and places it only at the communication endpoints where it is actually needed. This selective deployment eliminates the processing burden of encrypting all enterprise data while maintaining security for sensitive communications.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies encryption locally at communication endpoints rather than uniformly across the entire enterprise. This local quality approach ensures that only the specific data requiring security (communications between authorized parties) is encrypted, reducing overall processing overhead while maintaining necessary security.

Inventive Principle:
Principle #3Local quality

2Reliability

If VPNs are used for secure communications, then access control is improved, but the system does not extend easily to external parties without additional security risks

Engineering Contradiction:
Improveaccess controlVSAvoidextensibility to external parties
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent creates a communication security system that universally applies to both internal and external communications. The same endpoint encryption and policy enforcement mechanisms work for VPN-protected internal communications and for external communications, eliminating the need for separate security systems and reducing overall complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If document control systems are implemented, then documentation compliance is improved, but tracking of documents once copied from the system is not achieved

Engineering Contradiction:
Improvedocumentation complianceVSAvoidtracking capability
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent implements feedback mechanisms through policy agents that continuously monitor and report on document usage and communication activities. These agents provide real-time feedback about document copies, transmissions, and access, enabling continuous tracking and enforcement of compliance policies throughout the enterprise.

Inventive Principle:
Principle #23Feedback

4Reliability

If multiple separate security systems are deployed for different communications media, then specific security requirements are met, but the systems become disjointed and difficult to manage

Engineering Contradiction:
Improvesecurity coverageVSAvoidsystem integration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple separate security functions into a unified communication security system. Policy agents, encryption mechanisms, and enforcement rules are integrated across email, instant messaging, voice, video, and collaboration platforms, providing comprehensive security coverage while simplifying management through a single coordinated framework.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS10015169B2Node-based policy-enforcement across mixed media, mixed-communications modalities and extensible to cloud computing such as SOA
Publication Date: 2018.07.03 AVAYA INC
  • US10015169B2 patent drawing
  • US10015169B2 patent drawing
  • US10015169B2 patent drawing

AI summary

A system and method are provided to monitor and prevent potential enterprise policy and/or rule violations by subscribers.