Credential Management for Privacy Data Access Requests

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data management systems face challenges in efficiently processing data subject access requests while maintaining data security, as they often need to handle multiple data sources with different structures and formats, risking data breaches if security is compromised.

Innovation Solution

A method and system that receive data subject access requests, determine the relevant data source, retrieve credentials using metadata, acquire and process data, and manage credentials to ensure security by invalidating and updating access permissions, allowing for seamless transition to new credentials if necessary.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If computing tools search multiple data assets with different data structures and storage formats to process data subject access requests, then the ability to fulfill data access requests is improved, but the risk of data exposure to breach or loss increases

Engineering Contradiction:
Improveability to process data subject access requestsVSAvoidrisk of data exposure to breach or loss
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a credential management system that acts as an intermediary between the computing tools and the data assets. The system retrieves credentials from secure storage, validates them, and uses them to access external data sources. This mediator layer ensures that data access requests are processed through controlled authentication mechanisms, reducing the risk of direct exposure while maintaining the ability to search and access multiple data assets with different structures and formats.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If credentials are stored for accessing external data sources, then the efficiency of processing data subject access requests is improved, but the security risk of credential compromise increases

Engineering Contradiction:
Improveefficiency of processing data subject access requestsVSAvoidsecurity of credential storage
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements preliminary action by retrieving and validating credentials before they are used to access external data sources. The system checks credential validity, monitors usage, and automatically invalidates credentials after use or when expiration is detected. This preliminary validation and monitoring approach allows efficient processing of data subject access requests while maintaining security through proactive credential management rather than reactive response to breaches.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If the system monitors credential validity and automatically invalidates expired credentials, then data security is improved, but the complexity of credential management increases

Engineering Contradiction:
Improvedata securityVSAvoidcomplexity of credential management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service by creating a system that automatically monitors credential validity, detects expired or invalid credentials, and invalidates them without human intervention. The credential management system autonomously tracks usage patterns, checks expiration dates, and revokes access when necessary. This automation reduces the need for manual credential management while maintaining high security standards, as the system serves itself by managing its own security credentials through predefined rules and automatic validation processes.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11947708B2Data processing systems and methods for automatically protecting sensitive data within privacy management systems
Publication Date: 2024.04.02 ONETRUST LLC
  • US11947708B2 patent drawing
  • US11947708B2 patent drawing
  • US11947708B2 patent drawing

AI summary

In particular embodiments, a sensitive data management system is configured to remove sensitive data after a period of non-use. Credentials used to access remote systems and/or third-party systems are stored with metadata that is updated with each use of the credentials. After a period of non-use, determined based on credential metadata, the credentials are deleted. Personal data retrieved to process a consumer request is stored with metadata that is updated with each use of the personal data. After a period of non-use, determined based on personal data metadata, the personal data is deleted. The personal data is also deleted if the system determines that the process or system that caused the personal data to be retrieved is no longer in use. An encrypted version of personal data may be stored for later use in verifying proper consumer request fulfillment.