Automated Data Classification for DRM Policy Orchestration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for managing electronic data in computer systems are inefficient, as they require manual identification of data for digital rights management, leading to time-consuming processes and potential user errors, and often result in unnecessary service costs and liability due to unstructured data not receiving adequate services.

Innovation Solution

An information management system that automatically classifies data objects using granular policies and rules, enabling the orchestration of services like DRM, data placement, and compliance, eliminating the need for manual data identification and ensuring only necessary services are applied.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual identification of data for DRM services is used, then data protection can be applied, but the process is time-consuming and prone to user error

Engineering Contradiction:
Improveaccuracy of data identificationVSAvoidtime for manual data identification
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables self-service through automated classification engines that independently identify and categorize data objects requiring DRM protection without human intervention. The classification engine automatically scans data objects, applies classification rules, and determines which objects need protection, eliminating the manual identification process while maintaining high accuracy through systematic rule-based evaluation

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The manual mechanical process of administrators reviewing and identifying data objects is replaced by an automated information management system with classification engines that use rules-based logic and metadata analysis. This substitution transforms the time-consuming manual operation into an efficient automated process that can handle large volumes of data objects simultaneously

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If all data objects are protected with DRM services, then data security is improved, but unnecessary service costs increase

Engineering Contradiction:
Improvedata securityVSAvoidservice costs
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The system applies local quality by providing differentiated DRM protection levels based on the specific classification of each data object. Instead of uniform protection across all data, the classification engine identifies only those objects requiring protection and applies appropriate DRM services selectively. This ensures data security for sensitive objects while avoiding unnecessary costs for objects that don't require protection

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system avoids excessive action by implementing partial protection only where needed. The classification engine evaluates each data object against classification rules and applies DRM services only to objects that meet specific criteria, rather than applying protection universally. This partial action approach maintains security for critical data while minimizing unnecessary service costs

Inventive Principle:
Principle #16Partial or excessive action

3Ease of operation

If unstructured data is not classified, then storage simplicity is maintained, but compliance risks and service optimization are lost

Engineering Contradiction:
Improvedata management simplicityVSAvoidcompliance adherence
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary action by automatically classifying data objects before DRM services or other data management operations are applied. The classification engine proactively identifies and categorizes data objects, assigning classification metadata that enables subsequent compliance checks and service optimizations. This preliminary classification ensures compliance requirements are met before any operations occur

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The classification system acts as an intermediary layer between raw unstructured data and DRM/services operations. The classification engine introduces structured classification metadata that bridges the gap between simple storage and complex compliance requirements, enabling automated decision-making about which objects need protection without complicating the underlying storage structure

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9323901B1Data classification for digital rights management
Publication Date: 2016.04.26 EMC IP HLDG CO LLC
  • US9323901B1 patent drawing
  • US9323901B1 patent drawing
  • US9323901B1 patent drawing

AI summary

Information management is used to enforce and control rights associated with data through the use of policies implemented by a digital rights management (“DRM”) server. An information management system collects information about data objects in a computer system and classifies the data objects into one or more categories. The categories are mapped to service level objectives that include or request encryption and identify DRM policies to associate with data objects within each category. Each DRM policy identifies one or more users authorized to access data objects the DRM policy is associated with. Encryption is orchestrated, in one embodiment, by identifying a data object to the DRM server in an encryption request, and identifying a DRM policy to associate with the data object. The DRM server encrypts the data object and only allows it be decrypted by authorized users.