Self-Destructing Document Security via Threat Pattern Matching

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Business critical documents shared over networks are vulnerable to unauthorized access, as existing security measures like IRM may not prevent unintended users from gaining access, especially when credentials are compromised or offline tools are used to bypass protections.

Innovation Solution

Implementing a self-destruction mechanism for documents marked as 'extremely confidential' based on security threat pattern matching, which can trigger local or remote inaccessibility if unauthorized access attempts are detected, such as accessing outside designated times or from unauthorized locations, using a combination of client and server-side plugins and IRM services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If IRM protection is applied to documents, then document security is improved, but unauthorized access may still occur through credential compromise or offline tools

Engineering Contradiction:
Improvedocument securityVSAvoidunauthorized access
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary actions by embedding self-destruct triggers and threat detection mechanisms into the document protection layer before unauthorized access can occur. The IRM protection is enhanced with pre-configured security policies that automatically detect and respond to threat patterns, causing the document to self-destruct before credentials can be compromised or offline tools can be applied.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements continuous feedback loops where threat detection patterns are monitored in real-time against document access attempts. When unauthorized access patterns are detected (such as credential compromise attempts or offline tool usage), the system provides immediate feedback by triggering document self-destruction, creating a closed-loop security mechanism that adapts to emerging threats.

Inventive Principle:
Principle #23Feedback

2Reliability

If self-destruction mechanism is implemented, then protection against unauthorized access is improved, but system complexity increases

Engineering Contradiction:
Improveprotection against unauthorized accessVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The self-destruction mechanism is integrated into the existing IRM service infrastructure, allowing the same IRM system to perform both traditional document protection and self-destruction functions. The threat detection patterns are implemented as extensions of existing IRM policies, enabling multi-functionality without requiring completely separate systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces an intermediary layer of threat detection patterns that sits between the document content and the IRM protection mechanism. This intermediary layer translates security threats into IRM-compatible policy violations, which then trigger self-destruction through existing IRM infrastructure, reducing overall system complexity by leveraging established components.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If threat detection patterns are monitored continuously, then security response time is improved, but computational resources are consumed

Engineering Contradiction:
Improvesecurity response timeVSAvoidcomputational resources
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system applies partial monitoring by focusing threat detection resources on specific high-risk patterns rather than continuously analyzing all document access activities. Threat detection patterns are configured to monitor only critical security events (such as unauthorized location access, abnormal time-based patterns, or suspected credential compromise), reducing computational overhead while maintaining effective security response.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system dynamically adjusts monitoring parameters based on threat levels and document sensitivity. Threat detection patterns can be configured with different monitoring intensities, time windows, and trigger thresholds, allowing the system to optimize computational resource usage by scaling monitoring effort according to the actual security risk profile of each document and access context.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS9043943B1Self-destructing content
Publication Date: 2015.05.26 EMC IP HLDG CO LLC
  • US9043943B1 patent drawing
  • US9043943B1 patent drawing
  • US9043943B1 patent drawing

AI summary

Protecting sensitive content, such as business critical documents or other computer files, is disclosed. In various embodiments, upon receiving an indication that a threat pattern associated with a content item has been matched, the protected content “self-destructs”, such as rendering the content item inaccessible, e.g., at a client and/or to a particular user or group of users.