Data Governance System Using Targeted User Profiling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data access governance methods face challenges in efficiently identifying data owners, managing permissions, and detecting suspicious activities within large unstructured data stores, often requiring extensive manual effort and lacking precision.

Innovation Solution

A system utilizing targeted crowdsourcing methodologies to select a subset of employees or users based on usage statistics and attributes, who are then queried to provide information about resource ownership, permissions, and potential security breaches, with their input analyzed and updated in a governance database.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual methods are used to identify data owners and manage permissions in large unstructured data stores, then comprehensive coverage can be achieved, but the process requires extensive manual effort and time

Engineering Contradiction:
Improveaccuracy of identifying data ownersVSAvoidtime required for manual effort
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system enables data owners to self-identify and self-register their owned data resources through automated profiling and monitoring. The usage profiler automatically detects data access patterns and identifies potential data owners, who then confirm their ownership through the system interface, eliminating the need for extensive manual identification processes while maintaining high accuracy.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual mechanical processes with automated electronic systems. The usage profiler, compliance profiler, and database automatically monitor, analyze, and identify data owners through programmed algorithms that process usage statistics and access patterns, substituting human manual effort with automated computational processes that are both faster and equally accurate.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If comprehensive monitoring of all users is implemented, then complete data protection is achieved, but the system complexity and resource requirements increase significantly

Engineering Contradiction:
Improvedata protection effectivenessVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system extracts and focuses monitoring efforts only on critical data resources and high-risk users identified through usage profiling. Rather than monitoring all users equally, the compliance profiler identifies and prioritizes monitoring of specific users who access sensitive data or exhibit suspicious patterns, reducing system complexity while maintaining effective data protection for critical resources.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements differentiated monitoring strategies for different data resources and user groups. High-value sensitive data receives enhanced monitoring and compliance checking, while less critical data uses standard monitoring. This localized quality approach ensures strong protection where needed without the overhead of comprehensive high-intensity monitoring across the entire system.

Inventive Principle:
Principle #3Local quality

3Loss of information

If detailed usage profiling of all users is performed, then complete visibility into data access is achieved, but the processing load and time requirements increase

Engineering Contradiction:
Improvevisibility into data accessVSAvoidprocessing efficiency
Core Design Contradiction:
Loss of informationVSProductivity

Solution Approach 1:

The usage profiler implements partial profiling by focusing on the most relevant access patterns and data resources. Rather than analyzing every single access event in detail, the system identifies and profiles key usage patterns that indicate ownership, permission issues, or suspicious activity. This partial action approach maintains sufficient visibility into data access while significantly reducing processing load compared to exhaustive profiling of all user activities.

Inventive Principle:
Principle #16Partial or excessive action

4Reliability

If extensive permission management processes are implemented, then complete permission control is achieved, but the ease of operation decreases

Engineering Contradiction:
Improvepermission control accuracyVSAvoidease of permission management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The compliance profiler continuously monitors data access and provides feedback about permission violations and issues. When suspicious activity or permission problems are detected, the system automatically alerts relevant users and initiates correction processes. This feedback mechanism maintains accurate permission control while simplifying operation by automatically detecting and reporting issues rather than requiring manual verification of every permission decision.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10521601B2System and method for data governance
Publication Date: 2019.12.31 SAILPOINT TECH ISRAEL LTD
  • US10521601B2 patent drawing
  • US10521601B2 patent drawing
  • US10521601B2 patent drawing

AI summary

A system for determining information about a resource. The system includes a profiler to generate a targeted subset of users for at least one selected resource according to at least one of: a pre-defined goal and usage statistics of the resource with respect to the goal; an addresser to request from the subset of users information regarding the goal and a collector to collect and analyze the information and to update attributes of the resource according to the information.