EP3210175B1

Access blocking for data loss prevention in collaborative environments

Abstract

This record has no abstract on file.

EP3210175B1, drawing sheet 1
Sheet 1 of 14

Term

9.1 yearsleft in the term

Expires 15 October 2035.

  1. Priority and filed
  2. Granted
  3. Today
  4. Expires

10 claims: 2 independent, 8 dependent

  1. 1
    A computing device to provide access blocking as part of data loss prevention, DLP, within a collaborative service environment (100), the computing device comprising:a memory configured to store instructions;a processor coupled to the memory;wherein the processor is configured to perform actions including: detect (910) an action associated with content processed by a collaborative service (120), wherein the action is detected as a part of an evaluation of the content in response to one of: an opening of the content, an editing of the content, a sharing of the content, a copying of the content, a moving of the content, a publishing of the content, a saving of the content, a printing of the content, an uploading of the content, a downloading of the content, and an expiration of a predefined time interval;determine (230;308;920) if the action matches access blocking criteria defined by one or more DLP policy rules (204;302);and in response to a determination that the action matches at least one access blocking criterion defined by the one or more DLP policy rules (204), activate (314;930) a block access tag associated with the content, ignore previously defined permissions associated with the content, and restrict access to the content to a number of predefined users, wherein a notification is provided to the predefined users through a user experience of the collaborative service to indicate the restricted access to the content, the notification comprising a link to a DLP policy document that includes the one or more DLP policy rules, a link to a location of the content, and control elements associated with one or more actions for the predefined users, wherein the one or more actions are implemented in order to deactivate the block access tag associated with the content, reinstate previously defined permissions associated with the content, and revoke the restricted access to the content.
  2. 6
    A method to provide access blocking as part of data loss prevention, DLP, within a collaborative service environment (100), the method comprising:detecting (910) sensitive information within content processed by the collaborative service (120) wherein the processing of sensitive information is detected as a part of an evaluation of the content in response to one of: an opening of the content, an editing of the content, a sharing of the content, a copying of the content, a moving of the content, a publishing of the content, a saving of the content, a printing of the content, an uploading of the content, a downloading of the content, and an expiration of a predefined time interval;determining (230;308;920) if the sensitive information matches access blocking criteria defined by one or more DLP policy rules (204;302);in response to a determination that the sensitive information matches at least one access blocking criterion defined by the one or more DLP policy rules, activating (314;930) a block access tag associated with the content, ignore previously defined permissions associated with the content, and restrict access to the content to a number of predefined users;and providing (232;316) a notification to the predefined users through a collaborative service user experience to indicate the restricted access to the content, the notification comprising a link to a DLP policy document that includes the one or more DLP policy rules, a link to a location of the content, and control elements associated with one or more actions for the predefined users, wherein the one or more actions are implemented in order to deactivate the block access tag associated with the content, reinstate previously defined permissions associated with the content, and revoke the restricted access to the content.