Backup Data Remediation via Sensitive Object Extraction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current data leakage prevention (DLP) software inefficiently remediates backup data by transferring entire backup images instead of specific data objects, leading to unnecessary storage requirements and restricted access, which hampers backup operations like data restoration and access times.
Innovation Solution
A method that examines backup images to identify sensitive data and modifies remediation information to restrict access, allowing for efficient remediation without a separate data store by using access control engines to scan and encrypt sensitive data, and manage access credentials for corresponding access groups.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If DLP software transfers entire backup images to remediation store, then sensitive data is secured, but storage resources are consumed and access time is increased
Solution Approach 1:
The patent segments the backup image into individual data objects and identifies only the specific objects containing sensitive data. Instead of transferring the entire backup image, the system extracts and transfers only the identified sensitive data objects to the remediation store, thereby reducing storage resource consumption while maintaining security.
Solution Approach 2:
The patent extracts only the sensitive data objects from the backup image and separates them from the rest of the backup data. This extraction process allows the system to store and manage only the necessary sensitive portions in the remediation store, eliminating the need to store entire backup images.
2Reliability
If DLP software transfers entire backup images to remediation store, then sensitive data is secured, but access time is increased
Solution Approach 1:
By segmenting the backup image into individual data objects and identifying only those containing sensitive data, the system reduces the amount of data that needs to be transferred and accessed. This segmentation enables faster access times since only the relevant sensitive objects are retrieved rather than the entire backup image.
3Reliability
If DLP software provides access credentials to DLP administrators, then sensitive data is protected, but backup administrators cannot access remediated data
Solution Approach 1:
The patent implements a unified access control mechanism that allows both backup administrators and DLP administrators to access remediated data through a single interface. The system maintains data protection through access credentials while enabling multi-functional access for different administrator types, eliminating the need for separate access mechanisms.
4Reliability
If separate remediation store is used, then sensitive data is isolated, but device complexity increases
Solution Approach 1:
The patent merges the backup storage and remediation storage into a single unified storage system. The backup image is stored with embedded remediation information that identifies sensitive data objects, eliminating the need for a separate remediation store. This integration reduces system complexity while maintaining data isolation through metadata-based identification.
Data Source
AI summary
A method and apparatus for remediating backup data to control access to sensitive data is described. In one embodiment, the method for facilitating sensitive data remediation from backup images without a separate data store includes examining the backup images to identify sensitive data and modifying remediation information associated with the sensitive data, wherein the remediation information restricts access to the sensitive data to at least one corresponding access group.


