As technological advancement leads to more content being shared online, there is increased risk of sensitive data being intercepted, stolen or even intentionally exposed or shared by someone authorized to access it. This can lead to company secrets being leaked to competitors, intellectual property being used outside of regulations, unauthorized modification, piracy, and copyright infringement. This analysis surveys existing data protection techniques, including traditional and blockchain-based Digital Rights Management (DRM) to control content usage, encryption to keep data unreadable even if it is stolen, digital watermarking for tamper prevention and detection, and Data Loss Prevention (DLP) systems which focus on protection against insider threats. While extensive, each of these methods retain limitations and vulnerabilities. These include DRM’s susceptibility to “analog holes”, cache accessing, virtual machines and jailbroken hardware; many encryption algorithms’ vulnerability to quantum computers and side-channel attacks; watermarking’s inability to prevent leakage, only trace it, and vulnerability to attacks that degrade the watermark; and DLP’s accuracy limitations, user resistance and difficulty detecting steganography. To address some of these security gaps, three new methods are proposed. Context-Fixed Fragmented Envelope Encryption (CoFFEE) links decryption keys to specific identifiers of a device or USB plug-in and to biometric data so that only the authorized user and device can decrypt the content, even if an attacker obtains the password. Continuous Context Awareness (CoCoA) follows a similar principle regarding context verification, this time continuously monitoring the environment and computer and closing the sensitive file if any unauthorized hardware or software is in use. Finally, the “analog hole” vulnerability may be mitigated using object recognition to identify external recording devices through the webcam. These new methods, when used in tandem with existing ones, could help to close critical security gaps and strengthen the overall defense against data leakage, particularly by insider threats.
Mira Torbay (Fri,) studied this question.
Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context: