Data Governance Minimization for Cloud Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In modern data warehouse architectures, especially those using Database as a Service (DBaaS), enterprises face challenges in provisioning the right roles and permissions, leading to data sharing security issues due to over-provisioning and susceptibility to data abuse, which existing firewalls and security measures fail to adequately address.

Innovation Solution

A computerized method for minimizing data governance by imposing access rules, measuring over-provisioning and data abuse susceptibility, implementing dark data governance, and identifying infrequently used roles to enhance data security, which includes principles of least privilege, tracking columnar usage, and masking data access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If data sharing is enabled across multiple teams in a consolidated data warehouse, then data accessibility and collaboration are improved, but security risks and susceptibility to data abuse increase

Engineering Contradiction:
Improvedata accessibilityVSAvoidsecurity risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments data access by implementing role-based access control (RBAC) where the data warehouse system divides permissions into distinct roles (e.g., data engineer, data scientist, business user) with specific access levels. Each role is granted only the minimum necessary permissions for its function, preventing excessive access while maintaining data accessibility for authorized users.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system applies different security policies and access rules to different data sets, columns, and users based on their specific sensitivity and usage requirements. Sensitive data columns receive enhanced protection (e.g., masking, encryption) while less sensitive data remains accessible, creating localized security measures tailored to each data element's risk profile.

Inventive Principle:
Principle #3Local quality

2Reliability

If comprehensive data governance is implemented to secure data, then data security is improved, but system complexity and operational overhead increase

Engineering Contradiction:
Improvedata securityVSAvoidgovernance complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements data classification and sensitivity labeling during data ingestion and storage, before access requests occur. Security policies are pre-configured based on data classification levels, so when access requests are made, the system automatically applies appropriate controls without requiring complex real-time analysis or manual approval processes.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system automatically monitors and detects suspicious access patterns, data exfiltration attempts, and policy violations using built-in analytics engines. When anomalies are detected, the system automatically responds by revoking access, alerting administrators, or applying additional controls without requiring constant human intervention, reducing operational overhead while maintaining security.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If access permissions are generously provisioned to enable data sharing, then ease of operation is improved, but the attack surface increases

Engineering Contradiction:
Improveease of data sharingVSAvoidattack surface
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements dynamic access control where permissions are not static but adjust based on context such as user behavior, time of access, data sensitivity, and risk assessments. The system continuously evaluates access requests against multiple factors and grants or denies permissions in real-time, allowing legitimate sharing while blocking potential attacks without requiring pre-configured extensive permissions.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS20230334162A1Minimizing data governance to improve data security
Publication Date: 2023.10.19 THEOM INC
  • US20230334162A1 patent drawing
  • US20230334162A1 patent drawing
  • US20230334162A1 patent drawing

AI summary

In one aspect, a computerized method for minimizing a data governance in order to improve data security, comprising: providing and imposing a set of access rules to a set of data, wherein the set of data is stored in a data warehouse; measuring a level of over provisioning of the set of data; measuring a level of data abuse susceptibility of the set of data; implementing a dark data governance operation on the set of data; and identifying a set of infrequently used roles in the set of data.