Session-Based DRM for Secure File Transfer
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The traditional perimeter-based security model becomes increasingly difficult to maintain due to the proliferation of devices and services that facilitate data transport, leading to conflicts between convenience and security, especially with the use of un-managed cloud storage platforms.
Innovation Solution
A computerized method for encrypting electronic files during transfer to low-security storage locations, determining the desired security level of files and storage systems, and applying session-based encryption to ensure secure access, allowing files to be shared without explicit provisioning of per-file security levels or digital rights management (DRM) encapsulation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If perimeter-based security model is used to protect corporate files, then security level is improved, but ease of operation deteriorates due to restrictions on data transport
Solution Approach 1:
The security model is segmented from the perimeter structure to individual files. Each file carries its own security credentials and encryption, allowing security to be maintained at the file level rather than requiring a centralized perimeter defense. This enables files to be securely transported across any network boundary while maintaining security controls.
Solution Approach 2:
An authentication server acts as an intermediary between files and storage systems. The server verifies security credentials, manages encryption keys, and authorizes access without requiring a controlled network perimeter. This intermediary enables secure file transfers to unmanaged locations while maintaining organizational security policies.
2Reliability
If physical segregation is used to maintain perimeter model, then security level is improved, but device complexity increases due to multiple infrastructures
Solution Approach 1:
The file-based security system provides universal security protection across all storage locations and devices. A single security infrastructure protects files whether they reside on corporate servers, personal devices, or cloud storage, eliminating the need for separate secure and unsecure infrastructures.
3Reliability
If files are encrypted using traditional DRM encapsulation, then security level is improved, but device complexity increases due to explicit provisioning requirements
Solution Approach 1:
Files automatically attach security credentials and encryption to themselves without requiring manual configuration. The security system self-provisions by embedding authentication data within the file structure, eliminating the need for explicit per-file security provisioning by users or administrators.
Solution Approach 2:
Security credentials and encryption are applied to files in advance during creation or upload, before the files are transferred or stored. This preliminary security provisioning ensures files are protected from the moment they leave the creation environment, without requiring complex security configuration at each destination.
Data Source
AI summary
Systems and methods are provided for encrypting electronic files during a transfer to a low-security storage location is provided. In one embodiment, a method comprises receiving a file copy request for a file stored on a source storage system to be copied to a destination storage system; determining a desired file security level of the file based on a desired security level for the file when the file is accessed; determining a destination security level of the destination storage system; comparing the file security level and the destination security level; encrypting the file to create an encrypted file when the destination security level is less than the file security level prior to copying the file; and copying at least one of the file and the encrypted file to the destination storage system as a function of the comparison of the file security level and the destination security level.


