Selective Presence Notification for Enterprise IM Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Instant messaging applications pose a risk for data leakage due to their ability to inadvertently or intentionally disclose confidential information, and existing solutions like port blocking are ineffective as they restrict all communication, impacting productivity.
Innovation Solution
Implementing a selective presence notification system that monitors and allows presence notification messages based on address information, ensuring only authorized messages are transmitted, while maintaining instant messaging functionality within enterprises.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If port blocking is used to prevent data leakage, then data security is improved, but instant messaging communication is blocked and productivity deteriorates
Solution Approach 1:
The patent segments the blocking mechanism from the communication function by introducing a proxy server that selectively filters presence notification messages while allowing instant messaging traffic to pass through. This segmentation enables security enforcement without complete communication blocking.
Solution Approach 2:
The patent introduces a proxy server as an intermediary component between users and the instant messaging network. This mediator monitors and controls presence notification messages, blocking only malicious traffic while permitting legitimate instant messaging communication to proceed uninterrupted.
2Reliability
If all instant messaging communication is blocked to prevent data leakage, then data security is improved, but the productivity benefits of instant messaging are lost
Solution Approach 1:
The patent applies local quality by implementing security controls specifically targeted at presence notification messages rather than applying blanket blocking to all instant messaging traffic. This localized approach maintains the ease of operation for legitimate communication while enforcing security where needed.
Solution Approach 2:
The patent implements partial action by selectively blocking only the harmful presence notification messages that pose data leakage risks, while allowing the majority of beneficial instant messaging communication to continue uninterrupted, thus preserving productivity benefits.
3Reliability
If presence notification messages are monitored and filtered, then data leakage is prevented, but system complexity increases
Solution Approach 1:
The patent implements self-service by enabling the proxy server to automatically analyze, evaluate, and filter presence notification messages based on predefined security criteria without requiring manual intervention. This automation reduces the operational complexity of managing security filters.
Solution Approach 2:
The patent applies universality by designing the proxy server to perform multiple functions: it acts as both a communication gateway and a security filter, evaluating presence notification messages against security policies while simultaneously routing legitimate instant messaging traffic, thereby consolidating security and communication functions in a single component.
Data Source
AI summary
Methods, systems, and apparatus, including computer program products, for selective presence notification are provided. In one general aspect, a plurality of presence notification messages are monitored. Each presence notification message may include address information identifying at least one of a recipient or a sender of the presence notification message. Based on the address information a determination is made as to whether a presence notification message is allowable. If it is determined that the presence notification message is allowable, the transmission of the presence notification message is allowed.


