Unified Data Classification and Protection Across Cloud and On-Premise

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current information protection solutions fail to provide a holistic approach for both on-premises and cloud environments, leading to difficulties in implementing and maintaining uniform security policies across different workload types, as on-premise and cloud-based systems use distinct classification engines and rules.

Innovation Solution

A centralized system that classifies and protects data objects based on multiple criteria, associating tags with them, allowing for uniform treatment and enforcement actions regardless of the environment, using a management service to maintain and apply policies across various computing devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate information protection solutions are used for on-premises and cloud environments, then each environment can be secured with dedicated systems, but security professionals must manage policies in multiple dashboards and maintain different classification engines and rules, increasing operational complexity

Engineering Contradiction:
Improvesecurity protectionVSAvoidpolicy management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines separate on-premises and cloud information protection systems into a unified solution that uses a single classification engine and centralized policy management. The system integrates data loss prevention (DLP) capabilities across both environments, allowing security professionals to manage policies in one interface rather than multiple dashboards, thereby reducing operational complexity while maintaining comprehensive security coverage

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent implements a universal classification engine that serves both on-premises and cloud environments with the same classification rules and criteria. This multi-functional system can classify data objects regardless of their location (on-premises or cloud) and apply appropriate protection policies, eliminating the need for separate classification engines and reducing the complexity of maintaining different rules for different environments

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If different classification engines and rules are used for on-premises and cloud-based DLP systems, then each system can be optimized for its specific environment, but the same data object may receive different classifications (e.g., level sensitivity) across environments, compromising policy consistency

Engineering Contradiction:
Improveenvironment-specific optimizationVSAvoidpolicy consistency
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent employs a homogeneous classification approach where the same classification engine and rules are applied uniformly across on-premises and cloud environments. Data objects receive consistent classification labels (such as confidentiality levels) regardless of their environment, ensuring that policy decisions are based on identical criteria and maintaining reliability and consistency across the entire system

Inventive Principle:
Principle #33Homogeneity

3Reliability

If a unified classification system is implemented across cloud and on-premises environments, then uniform treatment of data objects can be achieved, but the system complexity increases due to the need for centralized policy management and cross-environment integration

Engineering Contradiction:
Improvepolicy uniformityVSAvoidsystem integration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a centralized policy management system that acts as an intermediary between on-premises and cloud environments. This mediator handles the complexity of cross-environment integration by providing a single interface for policy definition, automatic classification, and enforcement across both environments, thereby achieving policy uniformity without proportionally increasing the complexity experienced by users

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10943022B2System for automatic classification and protection unified to both cloud and on-premise environments
Publication Date: 2021.03.09 MICROSOFT TECHNOLOGY LICENSING LLC
  • US10943022B2 patent drawing
  • US10943022B2 patent drawing
  • US10943022B2 patent drawing

AI summary

Methods, systems, and computer program products are described herein for the classification, tagging, and protection of data objects. Such techniques may be imposed on the data objects automatically regardless of whether the data objects are created/generated/interacted/downloaded/uploaded/accessed on the cloud-based environments and/or on-premises environments. The foregoing techniques are orchestrated from a centralized policy that is treated uniformly regardless of the data objects' environment. Once a data object is identified, it is classified based on multiple criteria and a tag is associated therewith. An enforcement action may be applied to the data objects based on a defined policy. The tag attached to the data object may be used to search for related audit logs that track accesses to the data object. By associating the tag and protection persistently, data object(s) are treated uniformly (i.e., in the same manner) regardless of what environment it is in.