Session-Based DRM for Secure File Transfer

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The traditional perimeter-based security model becomes increasingly difficult to maintain due to the proliferation of devices and services that facilitate data transport, leading to conflicts between convenience and security, especially with the use of un-managed cloud storage platforms.

Innovation Solution

A computerized method for encrypting electronic files during transfer to low-security storage locations, determining the desired security level of files and storage systems, and applying session-based encryption to ensure secure access, allowing files to be shared without explicit provisioning of per-file security levels or digital rights management (DRM) encapsulation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If perimeter-based security model is used to protect corporate files, then security level is improved, but ease of operation deteriorates due to restrictions on data transport

Engineering Contradiction:
Improvesecurity levelVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The security model is segmented from the perimeter structure to individual files. Each file carries its own security credentials and encryption, allowing security to be maintained at the file level rather than requiring a centralized perimeter defense. This enables files to be securely transported across any network boundary while maintaining security controls.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

An authentication server acts as an intermediary between files and storage systems. The server verifies security credentials, manages encryption keys, and authorizes access without requiring a controlled network perimeter. This intermediary enables secure file transfers to unmanaged locations while maintaining organizational security policies.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If physical segregation is used to maintain perimeter model, then security level is improved, but device complexity increases due to multiple infrastructures

Engineering Contradiction:
Improvesecurity levelVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The file-based security system provides universal security protection across all storage locations and devices. A single security infrastructure protects files whether they reside on corporate servers, personal devices, or cloud storage, eliminating the need for separate secure and unsecure infrastructures.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If files are encrypted using traditional DRM encapsulation, then security level is improved, but device complexity increases due to explicit provisioning requirements

Engineering Contradiction:
Improvesecurity levelVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Files automatically attach security credentials and encryption to themselves without requiring manual configuration. The security system self-provisions by embedding authentication data within the file structure, eliminating the need for explicit per-file security provisioning by users or administrators.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Security credentials and encryption are applied to files in advance during creation or upload, before the files are transferred or stored. This preliminary security provisioning ensures files are protected from the moment they leave the creation environment, without requiring complex security configuration at each destination.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9202020B2File protection using session-based digital rights management
Publication Date: 2015.12.01 IVANTI US LLC
  • US9202020B2 patent drawing
  • US9202020B2 patent drawing
  • US9202020B2 patent drawing

AI summary

Systems and methods are provided for encrypting electronic files during a transfer to a low-security storage location is provided. In one embodiment, a method comprises receiving a file copy request for a file stored on a source storage system to be copied to a destination storage system; determining a desired file security level of the file based on a desired security level for the file when the file is accessed; determining a destination security level of the destination storage system; comparing the file security level and the destination security level; encrypting the file to create an encrypted file when the destination security level is less than the file security level prior to copying the file; and copying at least one of the file and the encrypted file to the destination storage system as a function of the comparison of the file security level and the destination security level.