Security Agent Sensitive Data Marking
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security systems lack an effective mechanism to identify and protect sensitive data in transit between clients and servers, exposing confidential information to potential unauthorized access and compromising security.
Innovation Solution
A security system agent installed on the server intercepts requests and responses, applies predefined sensitive data pattern rules to identify sensitive data, and modifies the request to prevent access to sensitive data, ensuring it is not transmitted to the security system for processing, thereby creating an additional security layer to reduce the risk of data exposure.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the security system processes all data transmitted between clients and servers, then comprehensive security monitoring is achieved, but sensitive data is exposed to potential unauthorized access
Solution Approach 1:
The security system agent performs preliminary identification and marking of sensitive data in requests before they are transmitted to the security system. This advance action allows the security system to later process requests without actually accessing the sensitive data, thus maintaining monitoring effectiveness while preventing data exposure
Solution Approach 2:
The patent introduces an intermediary mechanism (the security system agent and marking system) that sits between the client-server communication and the security system processing. This intermediary marks sensitive data accesses without transmitting the actual sensitive data to the security system, thus enabling monitoring while protecting the data
2Reliability
If sensitive data is transmitted to the security system for processing, then security analysis is improved, but data protection is compromised
Solution Approach 1:
The patent extracts only the necessary metadata about sensitive data accesses (the marking information) from the original request and transmits this extracted information to the security system, while leaving the actual sensitive data behind on the client side. This allows security analysis without compromising data confidentiality
Solution Approach 2:
Instead of transmitting the actual sensitive data, the system creates and transmits a copy or representation of the access pattern (the marked request indicating sensitive data access). This copy enables security analysis while the original sensitive data remains protected on the client side
Data Source
AI summary
A mechanism is provided for monitoring and controlling data access. Responsive to intercepting a response from a server to a request for information from a client device, a security system agent applies pattern matching using a predefined set of sensitive data pattern rules to identify at least one sensitive data access included in the response. Responsive to identifying at least one sensitive data access matching one or more of the predefined set of sensitive data pattern rules, the security system agent modifies that the request from the client by marking the at least one sensitive data access as sensitive thereby forming a modified request. The security system agent sends the modified request to the security system thereby causing the security system to process the modified request without access the sensitive data associated with the at least one marked sensitive data access.


