Security Agent Sensitive Data Marking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security systems lack an effective mechanism to identify and protect sensitive data in transit between clients and servers, exposing confidential information to potential unauthorized access and compromising security.

Innovation Solution

A security system agent installed on the server intercepts requests and responses, applies predefined sensitive data pattern rules to identify sensitive data, and modifies the request to prevent access to sensitive data, ensuring it is not transmitted to the security system for processing, thereby creating an additional security layer to reduce the risk of data exposure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the security system processes all data transmitted between clients and servers, then comprehensive security monitoring is achieved, but sensitive data is exposed to potential unauthorized access

Engineering Contradiction:
Improvesecurity monitoring effectivenessVSAvoidsensitive data exposure risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The security system agent performs preliminary identification and marking of sensitive data in requests before they are transmitted to the security system. This advance action allows the security system to later process requests without actually accessing the sensitive data, thus maintaining monitoring effectiveness while preventing data exposure

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary mechanism (the security system agent and marking system) that sits between the client-server communication and the security system processing. This intermediary marks sensitive data accesses without transmitting the actual sensitive data to the security system, thus enabling monitoring while protecting the data

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If sensitive data is transmitted to the security system for processing, then security analysis is improved, but data protection is compromised

Engineering Contradiction:
Improvesecurity analysis capabilityVSAvoiddata confidentiality
Core Design Contradiction:
ReliabilityVSLoss of substance

Solution Approach 1:

The patent extracts only the necessary metadata about sensitive data accesses (the marking information) from the original request and transmits this extracted information to the security system, while leaving the actual sensitive data behind on the client side. This allows security analysis without compromising data confidentiality

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Instead of transmitting the actual sensitive data, the system creates and transmits a copy or representation of the access pattern (the marked request indicating sensitive data access). This copy enables security analysis while the original sensitive data remains protected on the client side

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11481508B2Data access monitoring and control
Publication Date: 2022.10.25 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11481508B2 patent drawing
  • US11481508B2 patent drawing
  • US11481508B2 patent drawing

AI summary

A mechanism is provided for monitoring and controlling data access. Responsive to intercepting a response from a server to a request for information from a client device, a security system agent applies pattern matching using a predefined set of sensitive data pattern rules to identify at least one sensitive data access included in the response. Responsive to identifying at least one sensitive data access matching one or more of the predefined set of sensitive data pattern rules, the security system agent modifies that the request from the client by marking the at least one sensitive data access as sensitive thereby forming a modified request. The security system agent sends the modified request to the security system thereby causing the security system to process the modified request without access the sensitive data associated with the at least one marked sensitive data access.