Application-Level Security Classification and Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional data security techniques are indiscriminate and ineffective in protecting sensitive information, often relying on general encryption and network-layer security, which fails to consider the specific nature of the data or application, leading to vulnerabilities and inefficiencies.

Innovation Solution

An application-level security system that classifies sensitive information and applies customizable security policies based on categories such as high, medium, or low sensitivity, using modules to determine and apply appropriate encryption and protection measures, thereby enhancing data security on a case-by-case basis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional encryption and network-layer security techniques are used, then data is protected from interception, but all data is encrypted indiscriminately including non-sensitive information, leading to increased operational burden and reduced efficiency

Engineering Contradiction:
Improvedata securityVSAvoidoperational efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies different security measures to different portions of data based on their sensitivity classification. Sensitive information fields are encrypted while non-sensitive fields are transmitted in plaintext, allowing security to be applied locally where needed rather than uniformly across all data, thus maintaining security for critical information while improving operational efficiency.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent segments data into sensitive and non-sensitive portions by classifying individual fields within messages. This segmentation allows the system to apply encryption only to classified sensitive fields rather than encrypting entire messages or all data uniformly, reducing the operational burden while maintaining security where required.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If conventional network-layer security with keyword detection is used, then enterprise-wide security is provided, but application-specific and user-specific security needs are not addressed, resulting in false positives and ineffective protection

Engineering Contradiction:
Improvesecurity policy customizationVSAvoidsecurity effectiveness
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements dynamic security policies that adapt to specific applications, users, and data types. Security policies are not static but are customized based on the particular context including the application being used, the user's role, and the sensitivity classification of the data, allowing the system to respond appropriately to different security scenarios rather than applying uniform rules.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent applies security policies at the application and user level rather than uniformly across the enterprise. Each application and user can have customized security policies tailored to their specific needs and the types of data they handle, with classification rules and security measures adapted to local requirements rather than enterprise-wide generalizations.

Inventive Principle:
Principle #3Local quality

3Ease of operation

If conventional security warnings are provided to users, then users are alerted of potential security risks, but users are only given the options to abort or proceed without remedial actions, causing delay and additional work

Engineering Contradiction:
Improveuser controlVSAvoidtime to correct security issues
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent performs preliminary classification and security policy application automatically before data transmission occurs. The system classifies sensitive information fields and applies appropriate encryption measures in advance, so when security warnings need to be presented to users, the necessary protective actions have already been taken, eliminating the need for users to perform additional remedial actions or corrections.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8561127B1Classification of security sensitive information and application of customizable security policies
Publication Date: 2013.10.15 ADOBE INC
  • US8561127B1 patent drawing
  • US8561127B1 patent drawing
  • US8561127B1 patent drawing

AI summary

Classification of security sensitive information and application of customizable security policies are described, including classifying information as security sensitive information at an application level, the security sensitive information being associated with a security sensitive category, determining a security policy for the security sensitive information, the security policy being configured to secure the security sensitive information, and applying the security policy to the security sensitive information at the application level, the policy being based on the security sensitive category.