AI Data Protection System for Cross-Environment Sensitive Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing complexity of managing sensitive data across various computing environments in enterprises, where data is spread vast and requires protection according to policies and regulations, poses challenges in ensuring compliance and security.

Innovation Solution

A data protection system that employs artificial intelligence to automatically identify sensitive data, determine data lineage, and apply appropriate protection measures such as anonymization, encryption, or tokenization, while also using personas for access control and exception management to ensure compliance with regulations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If data is stored across multiple computing environments and services, then business functionality and data sharing are improved, but data management complexity and security risk increase

Engineering Contradiction:
Improvedata sharing capabilityVSAvoiddata management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a data protection system as an intermediary layer between multiple computing environments. This system automatically discovers sensitive data, determines data lineage across systems, and applies protection measures without requiring manual configuration in each environment. The intermediary manages the complexity of cross-environment data sharing while maintaining security policies.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The data protection system performs automatic discovery and classification of sensitive data across computing environments without requiring manual intervention. The system self-configures protection policies based on discovered data types and lineage relationships, enabling autonomous management of data security across multiple environments.

Inventive Principle:
Principle #25Self-service

2Productivity

If manual data protection methods are used, then implementation simplicity is maintained, but productivity and coverage of data protection decrease

Engineering Contradiction:
Improvedata protection efficiencyVSAvoidautomated protection level
Core Design Contradiction:
ProductivityVSExtent of automation

Solution Approach 1:

The patent replaces manual mechanical processes of data identification and protection application with automated computational systems. Machine learning algorithms automatically discover sensitive data patterns, and the system programmatically applies protection measures across datasets, dramatically increasing productivity compared to manual methods.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The data protection system automatically performs data discovery, classification, and protection application without requiring manual configuration or intervention. The system self-manages the entire data protection workflow, from identifying sensitive data to applying appropriate protection measures, thereby maximizing both productivity and automation extent.

Inventive Principle:
Principle #25Self-service

3Reliability

If access control policies are strictly enforced, then data security is improved, but ease of operation for legitimate users decreases

Engineering Contradiction:
Improvedata securityVSAvoiduser access convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The data protection system performs preliminary classification and tagging of sensitive data before access requests occur. By pre-establishing protection policies and data categorization, the system can automatically evaluate access requests against predefined criteria, maintaining strict security enforcement while providing seamless access for legitimate users who meet the criteria.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11956245B1Intelligent data protection
Publication Date: 2024.04.09 WELLS FARGO BANK NA
  • US11956245B1 patent drawing
  • US11956245B1 patent drawing
  • US11956245B1 patent drawing

AI summary

A technological approach can be employed to protect data. Datasets from distinct computing environments of an organization can be scanned to identify data elements subject to protection, such as sensitive data. The identified elements can be automatically protected such as by masking, encryption, or tokenization. Data lineage including relationships amongst data and linkages between computing environments can be determined along with data access patterns to facilitate understanding of data. Further, personas and exceptions can be determined and employed as bases for access recommendations.