Data Fingerprinting for Post-Deletion Compliance Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The challenge lies in analyzing and determining the impact of unauthorized data access or compromise after personal information has been deleted, as existing technologies struggle to identify affected data, entities, and applicable regulations when the data is no longer available, hindering compliance with regulatory requirements.

Innovation Solution

A system generates a fingerprint for data attributes before deletion, which includes metadata and jurisdictional information, allowing for analysis of the impact of events on deleted data by retrieving and analyzing the fingerprint even after the data is no longer available, thereby identifying affected entities and applicable regulations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If personal information is deleted after a minimum time period to satisfy regulatory requirements, then data retention compliance is improved, but the ability to analyze data compromise events after deletion deteriorates

Engineering Contradiction:
Improveregulatory complianceVSAvoiddata availability for analysis
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system creates a fingerprint of the personal information before deletion occurs. This preliminary action preserves the essential data characteristics (such as data type, structure, and identifying attributes) in a compressed representation that can be used later for compromise analysis without requiring the original data to be retained.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Instead of retaining the actual personal information, the system creates a copy in the form of a fingerprint that captures the essential characteristics of the data. This fingerprint copy allows for later analysis and matching without exposing the original sensitive information, thus maintaining compliance while enabling post-deletion analysis.

Inventive Principle:
Principle #26Copying

2Difficulty of detecting and measuring

If personal information is retained for analysis of compromise events, then the ability to determine affected entities and regulations is improved, but regulatory compliance regarding data retention deteriorates

Engineering Contradiction:
Improvecompromise analysis capabilityVSAvoidregulatory compliance
Core Design Contradiction:
Difficulty of detecting and measuringVSReliability

Solution Approach 1:

The fingerprint is created in advance before the data is deleted, capturing all necessary identification and structural information. This preliminary creation of the fingerprint enables comprehensive compromise analysis capability while the actual data can still be deleted, thus maintaining regulatory compliance.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system extracts and isolates the essential characteristics of the personal information into a separate fingerprint structure. This extraction allows the critical analysis information to be separated from the sensitive data itself, enabling compromise detection while the original data can be compliantly deleted.

Inventive Principle:
Principle #2Taking out (Extraction)

3Object-affected harmful factors

If data is deleted to minimize storage and security risks, then data security and storage efficiency are improved, but the ability to perform post-event analysis deteriorates

Engineering Contradiction:
Improvesecurity risksVSAvoiddata for analysis
Core Design Contradiction:
Object-affected harmful factorsVSLoss of information

Solution Approach 1:

The system creates a fingerprint copy that preserves the essential structural and identifying characteristics of the data without retaining the actual sensitive information. This copy can be used for security analysis and event detection while the original data is deleted, thus minimizing security risks and storage requirements while maintaining analytical capability.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The critical analysis information is extracted from the full data set and isolated into a compact fingerprint representation. This extraction allows the system to retain only the necessary information for security analysis while deleting the rest of the data, thereby reducing storage footprint and minimizing exposure of sensitive information.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS8930326B2Generating and utilizing a data fingerprint to enable analysis of previously available data
Publication Date: 2015.01.06 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US8930326B2 patent drawing
  • US8930326B2 patent drawing
  • US8930326B2 patent drawing

AI summary

According to one embodiment of the present invention, a system analyzes data in response to detecting occurrence of an event, and includes a computer system including at least one processor. The system maps fields between the data and a fingerprint definition identifying relevant fields of the data to produce a fingerprint for the data. The data is deleted after occurrence of the event. The produced fingerprint is stored in a data repository, and retrieved in response to detection of the event occurrence after the data has been deleted. The system analyzes the retrieved fingerprint to evaluate an impact of the event on corresponding deleted data. Embodiments of the present invention further include a method and computer program product for analyzing data in response to detecting occurrence of an event in substantially the same manner described above.