Computing Instance Data Risk Analysis for Sensitive Data Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computing instance environments lack effective methods to evaluate and manage data risk associated with sensitive data categories, leading to potential security vulnerabilities and exposure risks.

Innovation Solution

A data risk analysis system that evaluates computing instances for sensitive data categories, determines access privileges, and triggers security notifications or workflows based on risk metrics, allowing for granular risk assessment and management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If data is stored in the data tier of computing instance environment, then information storage capability is improved, but data security risk increases

Engineering Contradiction:
Improveinformation storage capabilityVSAvoiddata security risk
Core Design Contradiction:
Quantity of substanceVSObject-affected harmful factors

Solution Approach 1:

The patent segments data into different sensitivity categories (public, internal, confidential, restricted) and applies different risk assessment rules and access controls to each category. This allows the system to store diverse data types while managing security risks through granular classification and differentiated protection strategies.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a data risk analysis service as an intermediary layer between the data storage tier and access requests. This service evaluates data sensitivity, determines risk levels, and mediates access decisions, thereby enabling comprehensive data storage while maintaining security through an intermediate risk assessment mechanism.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If access privileges are granted to users for data retrieval, then data accessibility is improved, but exposure risk increases

Engineering Contradiction:
Improvedata accessibilityVSAvoidexposure risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies different access control policies and risk assessment criteria to different data categories and user roles. Instead of uniform access control, the system tailors permissions and risk evaluations to specific data sensitivity levels and user contexts, enabling broad accessibility where appropriate while restricting access to sensitive data.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements a feedback mechanism where the data risk analysis service continuously evaluates access requests based on data sensitivity, user permissions, and contextual factors. The service provides risk assessments that feed back into access decision-making, allowing the system to maintain accessibility while dynamically adjusting security based on real-time risk evaluation.

Inventive Principle:
Principle #23Feedback

3Measurement precision

If comprehensive data monitoring is implemented, then security detection capability is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent creates a universal data risk analysis service that handles multiple security functions through a single system component. This service performs data classification, risk assessment, access evaluation, and monitoring across all data categories, reducing overall system complexity by consolidating security functions rather than implementing separate mechanisms for each.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12373596B2Data risk of an instance
Publication Date: 2025.07.29 SERVICENOW INC
  • US12373596B2 patent drawing
  • US12373596B2 patent drawing
  • US12373596B2 patent drawing

AI summary

Each instance environment of a plurality of computing instance environments is associated with its corresponding set of users belonging to one or more user groups, its corresponding processes, and its corresponding data access privileges. For at least one of the computing instance environments, database tables accessible by the corresponding computing instance environment are analyzed to determine whether each of the database tables includes data belonging to one or more sensitive data categories. Based at least in part on a result of the analysis determining whether each of the database tables includes data belonging to the one or more sensitive data categories, a data risk metric is determined for the corresponding computing instance environment.