Unified Data Classification and Protection Across Cloud and On-Premise
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current information protection solutions fail to provide a holistic approach for both on-premises and cloud environments, leading to difficulties in implementing and maintaining uniform security policies across different workload types, as on-premise and cloud-based systems use distinct classification engines and rules.
Innovation Solution
A centralized system that classifies and protects data objects based on multiple criteria, associating tags with them, allowing for uniform treatment and enforcement actions regardless of the environment, using a management service to maintain and apply policies across various computing devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If separate information protection solutions are used for on-premises and cloud environments, then each environment can be secured with dedicated systems, but security professionals must manage policies in multiple dashboards and maintain different classification engines and rules, increasing operational complexity
Solution Approach 1:
The patent combines separate on-premises and cloud information protection systems into a unified solution that uses a single classification engine and centralized policy management. The system integrates data loss prevention (DLP) capabilities across both environments, allowing security professionals to manage policies in one interface rather than multiple dashboards, thereby reducing operational complexity while maintaining comprehensive security coverage
Solution Approach 2:
The patent implements a universal classification engine that serves both on-premises and cloud environments with the same classification rules and criteria. This multi-functional system can classify data objects regardless of their location (on-premises or cloud) and apply appropriate protection policies, eliminating the need for separate classification engines and reducing the complexity of maintaining different rules for different environments
2Adaptability or versatility
If different classification engines and rules are used for on-premises and cloud-based DLP systems, then each system can be optimized for its specific environment, but the same data object may receive different classifications (e.g., level sensitivity) across environments, compromising policy consistency
Solution Approach 1:
The patent employs a homogeneous classification approach where the same classification engine and rules are applied uniformly across on-premises and cloud environments. Data objects receive consistent classification labels (such as confidentiality levels) regardless of their environment, ensuring that policy decisions are based on identical criteria and maintaining reliability and consistency across the entire system
3Reliability
If a unified classification system is implemented across cloud and on-premises environments, then uniform treatment of data objects can be achieved, but the system complexity increases due to the need for centralized policy management and cross-environment integration
Solution Approach 1:
The patent introduces a centralized policy management system that acts as an intermediary between on-premises and cloud environments. This mediator handles the complexity of cross-environment integration by providing a single interface for policy definition, automatic classification, and enforcement across both environments, thereby achieving policy uniformity without proportionally increasing the complexity experienced by users
Data Source
AI summary
Methods, systems, and computer program products are described herein for the classification, tagging, and protection of data objects. Such techniques may be imposed on the data objects automatically regardless of whether the data objects are created/generated/interacted/downloaded/uploaded/accessed on the cloud-based environments and/or on-premises environments. The foregoing techniques are orchestrated from a centralized policy that is treated uniformly regardless of the data objects' environment. Once a data object is identified, it is classified based on multiple criteria and a tag is associated therewith. An enforcement action may be applied to the data objects based on a defined policy. The tag attached to the data object may be used to search for related audit logs that track accesses to the data object. By associating the tag and protection persistently, data object(s) are treated uniformly (i.e., in the same manner) regardless of what environment it is in.


