Cognitive Encryption via Metadata Classification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data management systems face inefficiencies in organizing and securing sensitive information due to limitations in directory-based and keyword/search-based systems, particularly in handling large volumes of heterogeneous data and ensuring adequate protection and access control, which can lead to human error and missed security threats.

Innovation Solution

A cognitive encryption system that utilizes an external metadata management system to identify and perform security actions on data sets by extracting facets and custom tags, enabling real-time alerts and remedial actions, and executing encryption and access control measures based on metadata analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual processes are used to determine and enforce encryption levels and access control, then flexibility in decision-making is maintained, but human error increases and security reliability deteriorates

Engineering Contradiction:
Improvesecurity protection reliabilityVSAvoidautomation of security classification
Core Design Contradiction:
ReliabilityVSExtent of automation

Solution Approach 1:

The system enables self-service automation where the data storage system automatically classifies data sensitivity levels and enforces encryption/access control without human intervention. The metadata collection system autonomously identifies sensitive information, determines appropriate security levels, and applies protective measures, eliminating human error while maintaining adaptive security decision-making through intelligent algorithms.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements feedback mechanisms where metadata about data characteristics is continuously collected, analyzed, and used to adjust security classifications. The system monitors data access patterns, sensitivity indicators, and contextual information, then dynamically adjusts encryption levels and access controls based on this feedback, improving reliability through adaptive automated decision-making.

Inventive Principle:
Principle #23Feedback

2Adaptability or versatility

If directory-based file systems are used to organize data, then structured organization is achieved, but the system breaks down when documents need to be organized across multiple categories or with alternative schemas

Engineering Contradiction:
Improvedata organization flexibilityVSAvoidfile system structure complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system adds a metadata dimension to traditional directory structures. Instead of relying solely on hierarchical folder arrangements, the system attaches rich metadata descriptors to data items that enable multi-dimensional organization and search. This allows documents to be simultaneously categorized across multiple dimensions (e.g., department, project, sensitivity level, date) without requiring complex nested directory structures.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The metadata system serves multiple functions simultaneously: it organizes data by sensitivity level for security classification, enables keyword-based search, provides contextual information for access control decisions, and supports alternative organization schemas. This universal metadata layer replaces the need for multiple specialized organization systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If keyword or full-text search systems are used to locate data, then rigid directory structures are discarded, but users must remember specific terms or phrases and the lack of structure creates difficulties when similar keywords appear across different document classes

Engineering Contradiction:
Improvedata search easeVSAvoidcontextual information loss
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The system applies local quality by attaching specific metadata descriptors to different data items based on their unique characteristics. Instead of relying on generic keyword matching, the system uses context-specific metadata tags that capture the meaning and classification of each data item. This allows search to be both flexible (like full-text search) and contextually accurate (like structured organization).

Inventive Principle:
Principle #3Local quality

4Quantity of substance

If the amount of data stored increases, then storage capacity is improved, but the ability to adequately protect sensitive information becomes more challenging

Engineering Contradiction:
Improvedata storage volumeVSAvoidsensitive information protection
Core Design Contradiction:
Quantity of substanceVSReliability

Solution Approach 1:

The system segments the large volume of stored data into individually classified units with attached metadata. Each data item is independently evaluated for sensitivity, and appropriate security measures are applied at the item level rather than treating all data uniformly. This segmentation enables scalable security management where protection reliability is maintained regardless of total data volume.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11914869B2Methods and systems for encryption based on intelligent data classification
Publication Date: 2024.02.27 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11914869B2 patent drawing
  • US11914869B2 patent drawing
  • US11914869B2 patent drawing

AI summary

Systems and methods for cognitive encryption of data are disclosed. The methods may include maintaining a plurality of data storage systems in communication with an external metadata management system, operating the metadata management system to store metadata corresponding to data residing on the plurality of data storage systems, identifying a candidate data set residing on at least one of the plurality of data storage systems on which at least one security action should be performed using information included in the metadata management system, and in response to identifying the candidate data set, identifying the at least one security action.