IP Library Granted Patent US 12,499,250
Granted Patent B2
US 12,499,250 · App. 17/528,801 · Granted Dec 16, 2025

Automatic generation of security labels to apply encryption

Inventor: Paras Pankaj Kapadia (Seattle, WA)
Assignee: MICROSOFT TECHNOLOGY LICENSING, LLC
G06F21/604G06F3/0482G06F21/6227G06F2221/2141
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,499,250
App. No.
17/528,801
Granted
Dec 16, 2025
Kind
B2
Abstract

Non-limiting examples of systems, methods, and devices for automatically generating security labels are disclosed herein. In an implementation, generation of security labels is automated to enforce security policies and prevent data leaks. For example, characteristics identified in telemetry data (e.g., collaborators, workgroups, internal users, external users, file content, terms etc.) may be used to automatically generate sensitivity labels and corresponding encryption policies. In another implementation, a user interface may be rendered comprising descriptions of the generated security labels that allow for selection of the labels, which results in the implementation of the security label.

Claims (49)

1 . A computing device for providing security labels, comprising:

a memory for storing executable program code;

a processor functionally coupled to the memory; and

the executable program code that, when executed by the processor, directs to the computing device to:

obtain telemetry data associated with a tenant in a multi-tenant environment, wherein the telemetry data comprises information relating to a group of users collaborating on an electronic asset of the tenant;

generate a signal based on the telemetry data associated with the tenant;

supply the signal to a machine learning environment comprising a machine learning model that generates security labels based on the telemetry data, wherein the machine learning model comprises a collaborator classifier that:

identifies, based on the signal, the group of user collaborating on the electronic access; and

determines a sensitivity level of the electronic asset based at least on the group of users collaborating on the electronic asset; and

receive, from the machine learning environment, a security label comprising a protection policy for the electronic asset of the tenant based on the telemetry data; and

render a user interface comprising at least a description of the security label and a selectable element to apply the security label.

2 . The computing device of claim 1 , wherein the executable program code further directs the computing device to:

supply the signals generated based on the telemetry data associated with a plurality of tenants within the multi-tenant environment to the machine learning environment; and

train, based on the signals, the machine learning model to generate security labels.

3 . The computing device of claim 1 , wherein the machine learning environment further comprises a content classifier that identifies, based on the signal, a content of the electronic asset and determines the sensitivity level of the electronic asset based at least on the content of the electronic asset.

4 . The computing device of claim 3 , wherein the machine learning model generates the security label based on the sensitivity level of the electronic asset.

5 . The computing device of claim 1 , wherein the executable program code further directs the computing device to publish the security label in response to a selection of the selectable element.

6 . The computing device of claim 1 , wherein the executable program code further directs the computing device to:

generate another security label comprising an encryption policy distinguished from the protection policy; and

render the user interface further comprising a description of the other security label.

7 . A computer-implemented method for providing security labels, comprising:

obtaining telemetry data associated with a tenant in a multi-tenant environment, wherein the telemetry data comprises information relating to a group of users collaborating on an electronic asset of the tenant;

generating a signal based on the telemetry data associated with the tenant;

supplying the signal to a machine learning environment, wherein the machine learning environment comprises a machine learning model generates security labels based on the telemetry data;

receiving, from the machine learning environment, a security label comprising a protection policy for the electronic asset of the tenant based on the telemetry data;

receiving, from the machine learning environment, another security label comprising an encryption policy distinguished from the protection policy; and

rendering a user interface comprising:

at least a description of the security label;

a description of the other security label; and

a selectable element to apply the security label.

8 . The computer-implemented method of claim 7 , further comprising:

training, based on the signals, the machine learning model to generate security labels.

9 . The computer-implemented method of claim 7 , wherein the machine learning environment comprises a collaborator classifier that identifies, based on the signal, a group of users collaborating on the electronic asset and determines a sensitivity level of the electronic asset based at least on the group of users collaborating on the electronic asset.

10 . The computer-implemented method of claim 9 , wherein the machine learning environment further comprises a content classifier that generates, based on the signal, a meaningful term that defines a limit of the security label.

11 . The method of claim 10 , wherein the machine learning model generates the security label based on the sensitivity level of the electronic asset and the meaningful term.

12 . The method of claim 7 , wherein the user interface further comprises at least a description of the security label and a selectable element to apply the security label.

13 . A computer readable storage device comprising executable instructions that, when executed by a processor, cause the processor to:

receive, by a machine learning environment comprising a machine learning model, a signal generated based on telemetry data associated with a tenant in a multi-tenant environment;

identify, via the machine learning environment, a group of users collaborating on an electronic asset based the telemetry data, wherein the telemetry data comprises information relating to the group of users collaborating on the electronic assets of the tenant;

determine a sensitivity level of the electronic asset based at least on the group of users collaborating on the electronic asset; and

generate, by the machine learning model, based on the signal and by the machine learning environment, a security label based on the telemetry data, wherein the telemetry data comprises a protection policy for the electronic asset of the tenant.

14 . The computer readable storage device of claim 13 , wherein the executable instructions further cause the processor to:

create a training set of labels comprising signals generated from the telemetry data associated with a plurality of tenants in the multi-tenant environment; and

train, based on the training set of labels, the machine learning model to generate security labels.

15 . The computer readable storage device of claim 13 , wherein the executable instructions further cause the processor to:

identify, via the machine learning environment, a content of the electronic asset; and

determine the sensitivity level of the electronic asset based at least on the content of the electronic asset.

16 . The computer readable storage device of claim 15 , wherein the executable instructions further cause the processor to generate, via the machine learning model, the security label based on the sensitivity level of the electronic asset.

17 . The computer readable storage device of claim 13 , wherein the executable instructions further cause the processor to render a user interface comprising at least a description of the security label and a selectable element to apply the security label.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 17, 2021
From: KAPADIA, PARAS PANKAJ
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 058141/0350 →
Continuity (1)
Related Publication 20230153447A1 · May 18, 2023
References Cited (11)
US 8989386B2 · Falk · 2015 [cited by examiner]
US 11929155B1 · Schoenberg · 2024 [cited by examiner]
US 20180109574A1 · Vigoda et al. · 2018 [cited by applicant]
US 20180232528A1 · Williamson · 2018 [cited by examiner]
US 20200074091A1 · Jain · 2020 [cited by examiner]
US 20200241769A1 · Dain et al. · 2020 [cited by applicant]
US 20210344485A1 · Levin et al. · 2021 [cited by applicant]
US 20230098281A1 · Nainar · 2023 [cited by examiner]
“Executive Order on Improving the Nation's Cybersecurity”, In White House, May 12, 2021, 18 Pages. [cited by applicant]
Bailey, et al., “Create and configure sensitivity labels and their policies”, Retrieved from: https://docs.microsoft.com/en-us/microsoft-365/compliance/create-sensitivity-labels?view=o365-worldwide, Aug. 26, 2021, 12 Pa… [cited by applicant]
“International Search Report and Written Opinion Issued in PCT Application No. PCT/US22/041290”, Mailed Date: Dec. 2, 2022, 12 Pages. [cited by applicant]