Automatic Encryption Rule Generation for Sensitive Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data protection methods are inefficient and resource-intensive, particularly when encrypting large numbers of files, as they often encrypt non-sensitive data and require significant time and processing power, and manual user intervention is needed to determine file sensitivity, which can lead to overhead and errors.

Innovation Solution

A system that uses machine learning techniques to automatically generate encryption rules by analyzing file content using natural language processing and heuristic algorithms, determining whether files contain sensitive information and applying encryption only when necessary, based on context conditions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual user intervention is used to determine file sensitivity, then encryption can be applied selectively, but the process requires significant time and processing power

Engineering Contradiction:
Improveselective encryption accuracyVSAvoidencryption processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables files to self-identify their sensitivity status through embedded sensitivity indicators or metadata, eliminating the need for manual user intervention or complex analysis. Files automatically carry information about their sensitivity level, allowing the encryption system to quickly determine whether encryption is needed without time-consuming processing

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Sensitivity information is determined and embedded in files before the encryption process begins. This preliminary classification allows the encryption system to immediately identify which files require encryption without performing time-intensive analysis during the encryption operation itself

Inventive Principle:
Principle #10Preliminary action

2Reliability

If all files are encrypted to ensure security, then data protection is maximized, but non-sensitive data is unnecessarily encrypted consuming resources

Engineering Contradiction:
Improvedata protection coverageVSAvoidencryption resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The encryption system applies different treatment to different files based on their local characteristics - specifically their sensitivity indicators. Sensitive files receive full encryption protection while non-sensitive files are excluded, creating a localized quality approach where encryption intensity matches the actual security needs of each file

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system changes the encryption parameter (whether to encrypt) based on the sensitivity parameter of each file. By monitoring and responding to sensitivity indicator values, the system dynamically adjusts encryption application, encrypting only when the sensitivity parameter indicates a need for protection

Inventive Principle:
Principle #35Parameter changes

3Reliability

If encryption is applied to protect sensitive data, then security is improved, but the overhead of processing and managing encryption increases

Engineering Contradiction:
Improvesensitive data securityVSAvoidencryption management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system introduces sensitivity indicators or metadata as an intermediary layer between files and the encryption process. This intermediary carries information about file sensitivity that guides the encryption system, simplifying the management complexity by providing clear, structured information about which files require encryption without requiring complex analysis or user intervention

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9984006B2Data storage systems and methods
Publication Date: 2018.05.29 COMMVAULT SYSTEMS INC
  • US9984006B2 patent drawing
  • US9984006B2 patent drawing
  • US9984006B2 patent drawing

AI summary

Data storage systems are disclosed for automatically generating encryption rules based on a set of training files that are known to include sensitive information. The system may use a number of heuristic algorithms to generate one or more encryption rules for determining whether a file includes sensitive information. Further, the system may apply the heuristic algorithms to the content of the files, as determined by using natural language processing algorithms, to generate the encryption rules. Moreover, systems are disclosed that are capable of automatically determining whether to encrypt a file based on the generated encryption rules. The content of the file may be determined using natural language processing algorithms and then the encryption rules may be applied to the content of the file to determine whether to encrypt the file.