Self-Protecting Data Encapsulation for Enterprise Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data protection methods in electronic communications environments face challenges such as high costs and reduced effectiveness with the growth of networks, particularly with the use of firewalls, IDS/IPS devices, and encryption techniques, which can lead to performance issues and complex network administration.

Innovation Solution

A data protection system that encapsulates data with self-protection security controls, allowing it to be transmitted securely across networks without the need for external protection devices, using a data packet generator and a data broker to facilitate delivery and manage access, classification, and end-of-life controls independently of the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional external security devices (firewalls, IDS/IPS) are used for data protection, then network security is improved, but device complexity and operational costs increase

Engineering Contradiction:
Improvenetwork securityVSAvoidsecurity device complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The data itself carries security controls and policies embedded within it, enabling the data to protect itself during transmission and storage without requiring external security devices to continuously monitor and enforce protections. The security information travels with the data payload, allowing receiving systems to automatically apply appropriate security measures based on the embedded controls.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Security controls and policies are established and embedded into the data before transmission occurs. This preliminary action ensures that protection mechanisms are already in place when the data leaves the source system, eliminating the need for complex external security devices to analyze and respond to data in real-time during transmission.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If encryption techniques are applied to protect data, then data security is improved, but processing speed and productivity decrease

Engineering Contradiction:
Improvedata securityVSAvoiddata processing speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

Instead of applying uniform encryption to all data, the system applies security controls selectively based on the specific sensitivity and requirements of each data payload. The embedded security information allows receiving systems to determine the appropriate level of protection needed, avoiding unnecessary encryption overhead for less sensitive data while maintaining strong protection for critical information.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The security approach changes from fixed encryption parameters to dynamic security controls that are embedded with the data. These controls can specify varying levels of protection, access requirements, and handling instructions that adapt to the specific data being transmitted, allowing processing speed to be optimized based on actual security needs rather than applying maximum encryption to all data.

Inventive Principle:
Principle #35Parameter changes

3Productivity

If data is transmitted without embedded security controls, then transmission speed is improved, but data protection effectiveness decreases

Engineering Contradiction:
Improvedata transmission speedVSAvoiddata protection effectiveness
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The security controls are merged with the data payload itself, traveling together through the network. This combination allows the data to maintain its transmission efficiency while carrying embedded security instructions that enable protection measures to be applied at the destination without requiring separate security communication channels or protocols.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The embedded security information acts as an intermediary that carries protection instructions between the data source and destination. This intermediary contains the necessary controls and policies that enable receiving systems to automatically implement appropriate security measures without requiring complex external security devices or manual configuration.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If external security devices are deployed throughout the network, then security monitoring is improved, but network administration complexity increases

Engineering Contradiction:
Improvesecurity monitoringVSAvoidnetwork administration
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The data carries its own security controls and policy information, enabling automatic security enforcement at receiving endpoints without requiring centralized security device management. This self-service approach eliminates the need for network administrators to configure and maintain complex external security devices, as the security policies travel with the data and are automatically applied.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The embedded security control mechanism provides universal applicability across different data types, transmission channels, and receiving systems. A single embedded control structure can handle multiple security requirements (confidentiality, integrity, access control, retention policies) across the entire network infrastructure, replacing the need for multiple specialized external security devices and simplifying administration.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9043874B2System and method for protecting data in an enterprise environment
Publication Date: 2015.05.26 WALMART APOLLO LLC
  • US9043874B2 patent drawing
  • US9043874B2 patent drawing
  • US9043874B2 patent drawing

AI summary

Provided are a system and method for protecting data in an electronic communications environment. An interested entity establishes one or more controls for a received unit of data. At a source device in the electronic communications network, the unit of data is encapsulated with self-protection security data that includes the one or more controls. The encapsulated unit of data is delivered from the source device to a destination device in the electronic communications network. A data broker facilitates the delivery of the data to the destination device according to the controls. Facilitating the delivery of the data includes: identifying for the receiving device a collection of services corresponding to the controls independently of the network.