Server-Based Data Security Policy Enforcement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current data security solutions are inefficient and difficult to implement across various applications and services, as they require proprietary software and manual data transfer, failing to provide effective security management on a data-by-data basis in enterprise environments.
Innovation Solution
A method and apparatus that select and protect data via a user device, apply security policies, encrypt the data, and store metadata indicating the policies, allowing secure access and management of data across different devices and services, while enforcing access controls and user privileges.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If proprietary software is installed on user devices to secure data, then data security is improved, but device complexity and ease of operation deteriorate
Solution Approach 1:
The patent introduces a server as an intermediary that centralizes security policy management. Instead of installing proprietary software on each user device, the server stores security policies and communicates with applications, acting as a mediator between security requirements and data access. This eliminates the need for complex local software installations while maintaining security controls.
Solution Approach 2:
The patent extracts security management functionality from individual user devices and consolidates it on a remote server. By taking out the security policy storage and management from local devices, the system reduces device complexity while maintaining centralized security control through server-based policy enforcement.
2Reliability
If proprietary software applications are used to secure data, then data security is improved, but ease of operation and productivity deteriorate due to manual data transfer requirements
Solution Approach 1:
The patent creates a universal security framework that works across multiple applications and services without requiring application-specific software. The server-based security policy system provides multi-functional security controls that operate uniformly across different data types and applications, eliminating the need for users to learn or install different security tools for different tasks.
Solution Approach 2:
The server acts as an intermediary that automatically handles security policy enforcement during data operations. Instead of requiring manual user actions for data transfer and security management, the server mediates between data requests and security policies, automatically applying appropriate controls and enabling seamless data access across applications.
3Reliability
If data security policies are enforced across multiple applications and services, then data security is improved, but device complexity and system complexity increase
Solution Approach 1:
The patent introduces a server as an intermediary that centralizes security policy management. Instead of installing proprietary software on each user device, the server stores security policies and communicates with applications, acting as a mediator between security requirements and data access. This eliminates the need for complex local software installations while maintaining security controls.
Solution Approach 2:
The patent extracts security management functionality from individual user devices and consolidates it on a remote server. By taking out the security policy storage and management from local devices, the system reduces device complexity while maintaining centralized security control through server-based policy enforcement.
Data Source
Figure 1A
Figure 1B
Figure 2A
AI summary
Data security access and management may require a server dedicated to monitoring document access requests and enforcing rules and policies to limit access to those who are not specifically identified as having access to the data. One example of operation may include selecting data to access via a user device, identifying a user profile associated with the user device, retrieving at least one user policy associated with the user profile, determining whether the user policy permits the user device to access the data, matching the user policy to a data policy associated with the data, receiving an encryption key at the user device, applying the encryption key to the data, and unwrapping the data from a wrapped data format to access the data.