Security Module for Cloud Data Transfer Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud storage systems lack sufficient data security mechanisms to prevent unauthorized access and transfer of decrypted data items, as the client module cannot control the transfer of decrypted data after decryption.

Innovation Solution

A security module on the computing device maintains a security status table with identifiers of protected data items, detecting and preventing unauthorized transfers by applying a security policy, using hash functions to identify protected data items and enforcing policies to restrict access and transfer.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the client module decrypts protected data items for authorized access, then authorized parties can access the data contents, but the client module cannot control transfer of the decrypted data item to non-authorized parties

Engineering Contradiction:
Improveauthorized access to dataVSAvoiddata security protection
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies preliminary action by embedding identification information (such as digital watermarks or unique identifiers) into the decrypted data items before they leave the secure environment. This allows the system to pre-mark authorized data copies so that subsequent tracking and control of transfers to non-authorized parties can be automatically detected and prevented, resolving the contradiction between enabling authorized access and maintaining security control

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms by monitoring and tracking transfers of decrypted data items. When a transfer attempt is detected, the system receives feedback about the transfer event and can automatically respond by blocking the transfer or alerting security authorities. This closed-loop feedback system enables the client module to maintain control over decrypted data transfers while still allowing legitimate authorized access

Inventive Principle:
Principle #23Feedback

2Reliability

If the client module encrypts data items for protection, then non-authorized parties cannot access the data, but the decrypted data item cannot be controlled after decryption

Engineering Contradiction:
Improvedata protectionVSAvoidcontrol over decrypted data transfer
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies the nested doll principle by embedding identification information and control mechanisms within the decrypted data items themselves. The identification information is nested inside the data content, allowing the system to maintain control over the data even after decryption and transfer. This nested structure enables the data to carry its own security metadata, providing adaptability for tracking and controlling decrypted data transfers while maintaining protection

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The patent uses an intermediary approach by introducing identification information as a mediator between the encrypted data and the decrypted data. This intermediary element serves as a bridge that allows the system to maintain control and tracking capabilities throughout the decryption and transfer process. The identification information acts as a mediator that enables the client module to adaptively control decrypted data transfers without compromising the protection of encrypted data

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9215251B2Apparatus, systems, and methods for managing data security
Publication Date: 2015.12.15 IVANTI US LLC
  • US9215251B2 patent drawing
  • US9215251B2 patent drawing
  • US9215251B2 patent drawing

AI summary

Disclosed embodiments of a data protection mechanism can provide secure data management. In particular, the disclosed embodiments provide secure data management mechanisms that can control transfer of data items so that contents of protected data items are not accessible to non-authorized parties. For example, the disclosed system can prevent an application from storing a protected file using a new file name. As another example, the disclosed system can prevent an application from sending a protected file to another computing device over a communication network.