Backup Data Recovery Filtering for Privacy Compliance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The conflict between privacy regulations requiring data deletion and compliance requirements for data backups poses a challenge in data management, particularly in ensuring that specific data elements are not recoverable while maintaining backup integrity.

Innovation Solution

A data recovery system configured to receive a recovery prevention configuration from a user, which identifies specific backup data elements to exclude from recovery processes, allowing for privacy protection without deleting backup data by filtering out these elements during the recovery process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If backup data is retained to comply with data backup regulations, then data backup compliance is improved, but data privacy protection deteriorates

Engineering Contradiction:
Improvedata backup complianceVSAvoiddata privacy risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts specific data elements from backup data that are subject to privacy regulations (such as personally identifiable information) and isolates them in a separate secure storage location. This extraction allows the main backup data to remain intact for compliance purposes while the sensitive extracted elements are protected through secure deletion or isolation, thus resolving the contradiction between maintaining backup compliance and protecting data privacy.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent segments backup data into different categories based on sensitivity and regulatory requirements. By dividing the backup data storage into multiple segments or zones (e.g., sensitive data segment, non-sensitive data segment), the system can apply different protection mechanisms to each segment. This segmentation enables compliance with backup retention requirements for non-sensitive data while implementing enhanced privacy protections for sensitive data segments.

Inventive Principle:
Principle #1Segmentation

2Object-affected harmful factors

If all backup data is deleted to satisfy privacy regulations, then data privacy protection is improved, but data backup integrity deteriorates

Engineering Contradiction:
Improvedata privacy protectionVSAvoidbackup data integrity
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

Instead of deleting entire backup datasets, the patent extracts only the specific sensitive data elements that require deletion under privacy regulations. This selective extraction and deletion approach maintains the integrity and completeness of the overall backup data while removing only the necessary sensitive portions, thus protecting both privacy and backup integrity.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies different quality standards and protection levels to different parts of the backup data based on their sensitivity. Rather than uniformly deleting or protecting all backup data, the system implements local quality control where sensitive data elements receive enhanced protection measures (such as secure deletion or encryption) while non-sensitive data maintains standard backup integrity, resolving the contradiction between privacy protection and backup integrity.

Inventive Principle:
Principle #3Local quality

3Object-affected harmful factors

If sensitive data elements are identified and protected, then data privacy protection is improved, but system complexity deteriorates

Engineering Contradiction:
Improvedata privacy protectionVSAvoiddata management complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent implements automated mechanisms that enable the backup system to self-identify sensitive data elements using predefined classification rules and metadata. The system automatically tags, segments, and protects sensitive data without requiring manual intervention or complex external management processes. This self-service approach reduces operational complexity while maintaining robust privacy protection.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent creates a universal data classification and protection framework that can handle multiple types of sensitive data (personal information, financial data, health records, etc.) through a single integrated system. This multi-functional approach consolidates what would otherwise require multiple separate complex systems into one unified solution, reducing overall system complexity while providing comprehensive privacy protection across diverse data types.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12105981B2Preventing recovery of specific data elements
Publication Date: 2024.10.01 RUBRIK INC
  • US12105981B2 patent drawing
  • US12105981B2 patent drawing
  • US12105981B2 patent drawing

AI summary

Techniques for preventing recovery of specific data elements based on a recovery prevention configuration defined by a user are disclosed. In some embodiments, a computer system performs operations comprising: receiving a recovery prevention configuration from a first computing device of a first user, the recovery prevention configuration comprising at least one recovery prevention parameter specified by the first user via one or more user interface elements displayed on the first computing device, the at least one recovery prevention parameter being configured to identify one or more backup data elements stored in a secondary storage system; storing the recovery prevention configuration in a database in association with the secondary storage system; and filtering out the one or more backup data elements stored in the secondary storage system from a data recovery process based on the at least one recovery prevention parameter of the stored recovery prevention configuration.