Self-Extinction Agent for Electronic Document Outflow Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods are inadequate in preventing illegitimate outflow of electronic documents due to increasingly sophisticated hacking schemes and insider threats, as they primarily focus on system protection and data encryption rather than proactive response and source tracking.

Innovation Solution

A method and apparatus that utilize a virtual disk system with a taking-out control unit, a taking-out management server unit, and a self-response agent unit to authenticate and control the outflow of electronic documents, allowing for self-extinction and illegitimate source tracking when unauthorized attempts are detected, using information such as host name, MAC address, and IP address for authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional encryption and system protection methods are used, then data security is maintained to some extent, but the system cannot respond effectively when illegitimate outflow is attempted and cannot track the source

Engineering Contradiction:
Improveeffectiveness of preventing illegitimate outflowVSAvoidcomplexity of security system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent embeds a self-response agent unit within the electronic document that performs preliminary authentication actions before actual outflow occurs. The agent proactively communicates with the management server to verify legitimacy of transfer targets, and prepares self-extinction mechanisms in advance to activate immediately upon detecting illegitimate attempts, rather than waiting for system-level detection

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The electronic document is transformed into an autonomous entity with embedded self-response agent unit that independently performs authentication, monitors its own transfer status, and executes self-extinction without requiring external system intervention. The document serves its own security needs by maintaining authentication information and making independent decisions about legitimacy

Inventive Principle:
Principle #25Self-service

2Reliability

If explicit authentication and 2MAC are used to prevent illegitimate outflow, then internal user threats are addressed, but the system lacks self-response capability and source tracking

Engineering Contradiction:
Improveauthentication securityVSAvoidoperational simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The self-response agent unit automatically performs authentication operations without requiring user intervention. It independently manages authentication information, communicates with the management server, and executes self-extinction based on server responses, making the complex authentication process transparent to users while maintaining high security

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements continuous feedback loops where the self-response agent unit receives authentication results from the management server and adjusts its behavior accordingly. The server provides feedback about legitimacy of transfer targets, and the agent unit responds by either allowing transfer or activating self-extinction, creating a dynamic security response mechanism

Inventive Principle:
Principle #23Feedback

3Measurement precision

If machine learning and finger printing are used for prevention, then pattern recognition is improved, but the system cannot perform real-time self-response or tracking when outflow is attempted

Engineering Contradiction:
Improvedetection accuracyVSAvoidresponse time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The self-response agent unit is pre-loaded with authentication information and self-extinction capabilities before any transfer attempt occurs. This preliminary preparation eliminates processing delays during actual security events, as the agent unit can immediately activate self-extinction upon receiving illegitimate determination from the server without needing to analyze or process data in real-time

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The taking-out management server acts as an intermediary that handles complex authentication and analysis operations, while the self-response agent unit handles immediate response actions. This division allows the server to perform precise detection using machine learning and finger printing, while the agent unit provides instant self-response capability

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP2975547B1Method and apparatus for preventing illegitimate outflow of electronic document
Publication Date: 2020.09.02 ELECTRONICS & TELECOMM RES INST
  • EP2975547B1 patent drawingFigure 1
  • EP2975547B1 patent drawingFigure 2
  • EP2975547B1 patent drawingFigure 3

AI summary

An apparatus and method for preventing illegitimate outflow of an electronic document are disclosed. The apparatus includes a taking-out control unit, a taking-out management server unit, and a self-response agent unit. The taking-out control unit generates a virtual disk for storing an electronic document to be controlled, and controls the taking-out of the electronic document. The taking-out management server unit authenticates whether the taking-out of the electronic document is legitimate taking-out. The self-response agent unit performs self-extinction when a result indicating illegitimate outflow is received from the taking-out management server unit.