Program Agent Data Access Control via Policy Enforcement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data loss prevention solutions fail to effectively control data dissemination outside trusted networks, particularly due to the lack of control over encrypted data when accessed by users or spy programs, leading to potential unauthorized access and distribution.
Innovation Solution
A method involving a program agent that checks actions on data against an action policy, allowing or disallowing actions based on policy compliance, ensuring data protection by intercepting and managing access requests, especially for encrypted data on portable devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If user-based rules are used to control data access, then access control within trusted networks is simplified, but control over data dissemination outside trusted networks is lost
Solution Approach 1:
The patent introduces a program agent as an intermediary component that mediates between the data and the external environment. This agent actively monitors and controls all actions performed on data, including copying, printing, and transmission, regardless of whether the user is authorized. The program agent serves as a mediator that extends control boundaries beyond the trusted network into untrusted environments.
Solution Approach 2:
The patent implements preliminary action by requiring explicit user authorization before any data action can be performed. The system checks for user rights and obtains explicit permission (e.g., through prompts or confirmation mechanisms) before allowing data to be copied, printed, or transmitted. This preliminary verification ensures that data protection measures are in place before any potential data loss can occur.
2Reliability
If encryption technology is used to protect data on portable devices, then data security is improved, but control over decrypted data access is lost
Solution Approach 1:
The program agent acts as an intermediary between the encrypted data and any potential spy programs or unauthorized access attempts. Even when data is decrypted, the agent continues to monitor and control access, preventing spy programs from intercepting or reading decrypted data. The agent creates a protective layer that remains active throughout the data lifecycle.
Solution Approach 2:
The patent applies preliminary anti-action by proactively preventing unauthorized data access before it can occur. The program agent continuously monitors data actions and blocks unauthorized operations, including attempts by spy programs to read decrypted data. This preemptive protection counteracts potential harmful actions before they can succeed.
3Reliability
If DLP solutions control data copying within networks, then data loss prevention is improved, but mobility and data accessibility are restricted
Solution Approach 1:
The patent applies local quality by implementing different control strategies for different data actions and environments. The program agent allows certain actions (e.g., viewing data) while blocking others (e.g., copying, printing, transmitting), and adapts its behavior based on the specific context, user rights, and destination. This differentiated control enables data mobility where appropriate while preventing loss where risky.
Solution Approach 2:
The system implements dynamic control by continuously adapting data protection measures based on real-time conditions. The program agent monitors user rights, data characteristics, and environmental factors, adjusting its control behavior accordingly. This dynamic approach allows flexible data access when safe and blocks access when risky, balancing mobility and security.
Data Source
Figure 1~2
Figure 3
Figure 4a
AI summary
The present invention relates to a method comprising checking whether an action involving data violates an action policy; allowing the action if it does not violate the action policy, and preventing the action if it does violate the action policy, wherein the method is executed by a program agent running on a data processing system and associated with the data.