Self-Protecting Data Files With Embedded Policy Metadata

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional data security models are inadequate in controlling data access and protection in a mobile, cloud-enabled world, where data can leak beyond corporate control due to the use of personally-owned devices and cloud-based applications, leading to outdated and ineffective security measures.

Innovation Solution

The Secure Data Access System (SDAS) embeds policies within metadata, allowing files to assess their environment and apply complex access controls, encryption, and self-protection mechanisms, including encryption, access restriction, and self-destruction, independent of specific applications or platforms, ensuring data security regardless of location.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional network perimeter security models are used, then data protection within corporate networks is maintained, but data security becomes ineffective in mobile and cloud-enabled environments where data leaks beyond corporate control

Engineering Contradiction:
Improvedata securityVSAvoidadaptability to mobile and cloud environments
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements self-service by embedding security policies directly into data files themselves, allowing the data to autonomously assess its environment and enforce access controls without requiring continuous external security system intervention. The data file includes embedded metadata with policies that automatically evaluate access requests and enforce restrictions based on environmental conditions.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Instead of protecting data by controlling the network perimeter and restricting access points, the patent inverts the approach by embedding security controls within the data itself. The data file becomes the security boundary, carrying its own access control policies that travel with the data regardless of location, thereby maintaining security in mobile and cloud environments.

Inventive Principle:
Principle #13The other way round (Inversion)

2Ease of operation

If data is made accessible on multiple devices and platforms, then ease of access is improved, but control over data and ability to enforce security policies deteriorates

Engineering Contradiction:
Improvedata accessibilityVSAvoiddata control
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent achieves universality by creating a platform-agnostic data protection system where security policies are embedded in the data itself rather than being enforced by specific applications or platforms. The data file includes embedded metadata with policies that can be executed across different operating systems, devices, and applications, allowing universal access while maintaining consistent security control.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system implements feedback mechanisms where the embedded security policies continuously monitor environmental conditions and access requests, dynamically adjusting security restrictions based on real-time assessments. When policies are violated, the system can automatically respond with mitigation actions, creating a feedback loop that maintains data control regardless of accessibility location.

Inventive Principle:
Principle #23Feedback

3Reliability

If comprehensive security policies are embedded in data metadata, then data protection capability is improved, but system complexity increases

Engineering Contradiction:
Improvedata protectionVSAvoidsecurity system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies segmentation by dividing security policies into discrete, manageable components that are embedded within the data file metadata. Each policy can be independently defined, evaluated, and enforced, breaking down complex security requirements into manageable units that simplify implementation while maintaining comprehensive protection capability.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10157286B2Platform for adopting settings to secure a protected file
Publication Date: 2018.12.18 DELL PROD LP
  • US10157286B2 patent drawing
  • US10157286B2 patent drawing
  • US10157286B2 patent drawing

AI summary

Aspects of the present invention provide the ability to enforce access methods on data based upon a policy or policies identified within the metadata of a file. The data is self-protected by including or being wrapped with one or more policy/rule identifiers that act as a form of body armor to the data when in transit or in different situations. In embodiments, access is only granted upon successful authentication and compliance with the identified policy or policies. In embodiments, depending upon the conditions and policies, varying level access may be granted. In embodiments, depending upon the conditions and policies, the system may take one or more mitigations or remedial access levels, such as containerizing, sandboxing, granting limited access, or erasing the data.