Telephone Authentication DLP File Header for Data Leakage Tracking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional data loss prevention (DLP) systems have limitations in scope and applicability, and do not effectively secure information after leakage, particularly in managing sensitive information and preventing information leakage via telephone authentication.

Innovation Solution

A method and system that utilizes a telephone-authentication DLP file with a generated contents identification (CID) as a header for an original data file, requiring telephone authentication for reading, and includes management functions for policy verification, ARS voice-phishing prevention, and call forwarding settings, enhancing security and traceability of data leakage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional DLP systems are used to prevent information leakage, then data security is improved, but the scope and applicability are limited

Engineering Contradiction:
Improvedata securityVSAvoidscope and applicability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent integrates multiple authentication methods (telephone authentication, document code authentication, biometric authentication) into a single DLP system framework. The system can handle various file types and authentication modes through a unified architecture, making it universally applicable across different scenarios while maintaining strong security. The server can dynamically select authentication methods based on file sensitivity and user credentials.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If telephone authentication is implemented for file access, then security after data leakage is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity after data leakageVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a DLP server as an intermediary between users and files. The server handles telephone authentication, generates unique access codes, and manages file distribution. This intermediary approach centralizes the complexity in the server while keeping client devices simple - users only need to receive and enter authentication codes without complex security software installed on their devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments the authentication process into distinct steps: receiving telephone authentication request, generating verification code, sending code to user's device, and validating the code. This segmentation allows each component to be independently managed and reduces overall system complexity by breaking down the complex authentication flow into manageable, modular operations.

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If multiple authentication methods are supported, then adaptability is improved, but ease of operation deteriorates

Engineering Contradiction:
Improveauthentication methodsVSAvoiduser operation
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent implements dynamic authentication where the system automatically selects the appropriate authentication method based on the situation. For routine operations, simpler methods like document code authentication are used. For sensitive files or suspicious activities, the system dynamically escalates to more secure methods like telephone or biometric authentication. This dynamic adaptation maintains ease of operation for normal use while ensuring strong security when needed.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP3012997B1Method and system for preventing information leakage based on telephone authentication
Publication Date: 2019.08.07 THINKAT CO LTD
  • EP3012997B1 patent drawingFigure 1
  • EP3012997B1 patent drawingFigure 2(a)~2(b)
  • EP3012997B1 patent drawingFigure 3

AI summary

The present invention relates to a method and a system for preventing an information leakage based on a telephone authentication. The present invention includes a first step in which a telephone-authentication data-loss-prevention (DLP) file policy is set by a generator as a user of a user terminal assembly including a server-connection terminal through using the server-connection terminal and the server-connection terminal sends the telephone-authentication DLP file policy and requests a generation of a telephone-authentication DLP file to a DLP server assembly through an internet network; a second step in which the DLP server assembly generates a contents identification (CID) by using information including the telephone-authentication DLP file policy and stores a telephone-authentication DLP file information including the CID and the telephone-authentication DLP file policy; and a third step in which the server-connection terminal or the DLP server assembly generates the telephone-authentication DLP file, wherein the telephone-authentication DLP file including the CID as a header of an original data file that is a general file. A telephone authentication is needed when a reader reads the generated telephone-authentication DLP file. The method and the system for preventing the information leakage based on the telephone authentication according to an embodiment of the present invention, secure can be effectively enhanced by combining a DLP and a telephone authentication. Also, even though data is leaked, a location of the data can be known through the telephone authentication. Also, encryption of all kinds of data such as personal information, a general document, and so on is possible. Thus, applicable objects and scopes can be broadened.