×

System and methods for policy-based active data loss prevention

  • US 10,454,933 B2
  • Filed: 01/21/2016
  • Issued: 10/22/2019
  • Est. Priority Date: 01/21/2015
  • Status: Active Grant
First Claim
Patent Images

1. A system for active Data Loss Prevention (DLP) having a data processing agent that attempts to access an encrypted data object having encrypted metadata about the data object that may be governed by DLP policy, the system comprising:

  • a policy enforcement point (PEP) coupled with the encrypted data object for intercepting an access request attempt by the data processing agent of the encrypted data object prior to adjudication of the access request where the interception is hidden from the data processing agent;

    a policy decision server (PDP) coupled communicatively to the PEP via an encrypted backchannel to receive the intercepted access request from the data processing agent,having a processor and a persistent memory configured to process a set of policy conditions that determine whether the data processing agent is governed by DLP policy and for adjudicating access by the data processing agent to the encrypted data object based on data about the data processing agent and the encrypted data object'"'"'s metadata, where the adjudication is hidden from the data processing agent;

    a data loss preventer coupled to the PDP for decrypting the data objects metadata and for transmitting said decrypted metadata and the data about the data processing agent to the PDP for adjudication; and

    a responder coupled to the data loss preventer and to the PEP for transmitting the encryption key to the data object to the data processing agent when the adjudication of the PDP allows data access where the PEP enforces the adjudicated result of the PDP.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×