Security Application for Dynamic Data Formatting and Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current data access control systems struggle to balance security with user productivity, particularly in networked environments, as they often rely on binary access controls that restrict data access or require encryption, making it difficult to manage sensitive data transmission and access based on content, purpose, or category, leading to potential data breaches and liability issues.
Innovation Solution
A security program intercepts disk input/output operations to categorize and format data based on security rules, converting data between accessible and secure formats, allowing access only when compliance with security rules is met, and restricting unauthorized transmission, while enabling secure access and use of sensitive data across various devices and networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional encryption systems are used to control data access, then data security is improved, but employee productivity and workflow are restricted due to binary access controls and difficulty in managing sensitive data transmission
Solution Approach 1:
The patent implements dynamic access control where security tags are automatically applied to data based on its content and context. The system continuously monitors and adjusts access permissions in real-time based on user credentials, data sensitivity, and security policies, rather than using static binary encryption. This allows authorized employees to access and work with sensitive data freely while automatically restricting unauthorized access.
Solution Approach 2:
The patent introduces a security tagging system that acts as an intermediary between data and access control mechanisms. Security tags are embedded with data to mark sensitive information, and the system automatically enforces access policies based on these tags without requiring manual encryption/decryption operations. This intermediary layer enables seamless security enforcement while maintaining employee productivity.
2Reliability
If binary access controls or encryption are implemented, then unauthorized access is prevented, but it becomes difficult to track and manage what data is accessible and who should have access
Solution Approach 1:
The patent implements a comprehensive logging and monitoring system that provides continuous feedback on data access events. The system automatically tracks who accesses what data, when, and for what purpose, using the security tags embedded with sensitive information. This feedback mechanism enables real-time monitoring and auditing of data access without interfering with authorized workflows, solving the tracking problem inherent in traditional encryption systems.
3Reliability
If data transmission is prevented or encryption is required for all data, then data security is improved, but employee ability to work remotely and transmit data is obstructed
Solution Approach 1:
The patent applies security controls selectively based on the local quality or characteristics of each data item. Security tags are applied only to sensitive data identified by the system, while non-sensitive data remains freely accessible and transmissible. This granular approach allows employees to work remotely and transmit data without obstruction, while security is automatically enforced only where needed based on data sensitivity, user credentials, and security policies.
4Device complexity
If traditional access control systems are used, then security protocols are simplified, but they cannot dynamically adjust security based on data content, purpose, or category
Solution Approach 1:
The patent implements a self-service security system where the security tagging mechanism automatically analyzes data content, determines sensitivity, and applies appropriate security tags without requiring manual configuration or complex security policies. The system autonomously adjusts security based on data characteristics, user credentials, and contextual information, providing dynamic adaptability while maintaining operational simplicity for employees.
Data Source
AI summary
A security program installed or in communication with a computer is provided. The security program is configured to intercept disk (I/O) operations that read/write from/to disk. This allows the security program to confirm and control access to data based on security rules. Further, the security program can categorize data based on security rules and then format and store data on disk in a format that prevents access by application(s) of the computer. The security program is further configured to re-format data to be accessible by the application in a format accessible by the application(s) when a request to access the data complies with security rules.


