Self-Protecting Data Encapsulation for Enterprise Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data protection methods in electronic communications environments face challenges such as high costs and reduced effectiveness with the growth of networks, particularly with the use of firewalls, IDS/IPS devices, and encryption techniques, which can lead to performance issues and complex network administration.
Innovation Solution
A data protection system that encapsulates data with self-protection security controls, allowing it to be transmitted securely across networks without the need for external protection devices, using a data packet generator and a data broker to facilitate delivery and manage access, classification, and end-of-life controls independently of the network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional external security devices (firewalls, IDS/IPS) are used for data protection, then network security is improved, but device complexity and operational costs increase
Solution Approach 1:
The data itself carries security controls and policies embedded within it, enabling the data to protect itself during transmission and storage without requiring external security devices to continuously monitor and enforce protections. The security information travels with the data payload, allowing receiving systems to automatically apply appropriate security measures based on the embedded controls.
Solution Approach 2:
Security controls and policies are established and embedded into the data before transmission occurs. This preliminary action ensures that protection mechanisms are already in place when the data leaves the source system, eliminating the need for complex external security devices to analyze and respond to data in real-time during transmission.
2Reliability
If encryption techniques are applied to protect data, then data security is improved, but processing speed and productivity decrease
Solution Approach 1:
Instead of applying uniform encryption to all data, the system applies security controls selectively based on the specific sensitivity and requirements of each data payload. The embedded security information allows receiving systems to determine the appropriate level of protection needed, avoiding unnecessary encryption overhead for less sensitive data while maintaining strong protection for critical information.
Solution Approach 2:
The security approach changes from fixed encryption parameters to dynamic security controls that are embedded with the data. These controls can specify varying levels of protection, access requirements, and handling instructions that adapt to the specific data being transmitted, allowing processing speed to be optimized based on actual security needs rather than applying maximum encryption to all data.
3Productivity
If data is transmitted without embedded security controls, then transmission speed is improved, but data protection effectiveness decreases
Solution Approach 1:
The security controls are merged with the data payload itself, traveling together through the network. This combination allows the data to maintain its transmission efficiency while carrying embedded security instructions that enable protection measures to be applied at the destination without requiring separate security communication channels or protocols.
Solution Approach 2:
The embedded security information acts as an intermediary that carries protection instructions between the data source and destination. This intermediary contains the necessary controls and policies that enable receiving systems to automatically implement appropriate security measures without requiring complex external security devices or manual configuration.
4Reliability
If external security devices are deployed throughout the network, then security monitoring is improved, but network administration complexity increases
Solution Approach 1:
The data carries its own security controls and policy information, enabling automatic security enforcement at receiving endpoints without requiring centralized security device management. This self-service approach eliminates the need for network administrators to configure and maintain complex external security devices, as the security policies travel with the data and are automatically applied.
Solution Approach 2:
The embedded security control mechanism provides universal applicability across different data types, transmission channels, and receiving systems. A single embedded control structure can handle multiple security requirements (confidentiality, integrity, access control, retention policies) across the entire network infrastructure, replacing the need for multiple specialized external security devices and simplifying administration.
Data Source
AI summary
Provided are a system and method for protecting data in an electronic communications environment. An interested entity establishes one or more controls for a received unit of data. At a source device in the electronic communications network, the unit of data is encapsulated with self-protection security data that includes the one or more controls. The encapsulated unit of data is delivered from the source device to a destination device in the electronic communications network. A data broker facilitates the delivery of the data to the destination device according to the controls. Facilitating the delivery of the data includes: identifying for the receiving device a collection of services corresponding to the controls independently of the network.


