Sensitive Data Leakage Path Identification System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizations face challenges in detecting and preventing accidental non-compliance with data privacy regulations like GDPR, particularly when sensitive data can inadvertently travel to prohibited geographic locations due to scattered content sources and inappropriate user permissions.

Innovation Solution

A system and method that identify potential leakage paths of sensitive information by discovering users with read permissions, determining additional information transfer paths, and flagging prohibited locations or users, with the capability to prevent data transfer or access through flagged paths and users.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If organizations scatter content sources across multiple geographic locations to improve service accessibility, then user access convenience is improved, but the risk of sensitive data inadvertently reaching prohibited locations increases

Engineering Contradiction:
Improveuser access convenienceVSAvoiddata leakage risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary analysis of information transfer paths before data actually flows through them. It proactively identifies potential leakage paths by analyzing user permissions, storage locations, and transfer routes in advance, allowing organizations to take preventive measures before compliance violations occur.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system continuously monitors and analyzes information transfer paths, providing feedback about potential compliance risks. When new leakage paths are detected or when user permissions change, the system updates its analysis and alerts relevant stakeholders, enabling continuous compliance management in dynamic distributed environments.

Inventive Principle:
Principle #23Feedback

2Measurement precision

If manual monitoring of data transfer paths is implemented to detect non-compliance, then detection capability is improved, but operational complexity and resource requirements increase significantly

Engineering Contradiction:
Improvenon-compliance detection capabilityVSAvoidmonitoring system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system automatically performs compliance analysis without requiring manual intervention. It self-configures by discovering users with read permissions, automatically analyzing information transfer paths, and generating compliance reports. The system manages its own operation by continuously monitoring permission changes and updating path analyses autonomously.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual mechanical monitoring processes with automated computational analysis. Instead of human operators manually tracking data flows and permissions, the system uses automated algorithms to analyze user permissions, map information transfer paths, and identify compliance risks, dramatically reducing operational complexity.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If comprehensive analysis of all information transfer paths is performed to ensure compliance, then compliance accuracy is improved, but processing time and computational resources increase

Engineering Contradiction:
Improvecompliance assurance accuracyVSAvoidanalysis processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system extracts and focuses analysis only on relevant information transfer paths involving sensitive data and users with appropriate permissions. Rather than analyzing all possible data flows in the organization, it selectively identifies and analyzes only those paths that pose compliance risks, significantly reducing processing requirements while maintaining accuracy.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The compliance analysis is segmented into discrete, manageable components: discovering users with read permissions, identifying information transfer paths for each user, analyzing each path for compliance issues, and generating targeted reports. This segmentation allows the system to process complex compliance requirements in smaller, more efficient steps.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11822684B1Systems and methods for identifying possible leakage paths of sensitive information
Publication Date: 2023.11.21 COHESITY INC
  • US11822684B1 patent drawing
  • US11822684B1 patent drawing
  • US11822684B1 patent drawing

AI summary

A computer-implemented method for identifying possible leakage paths of sensitive information may include (i) discovering an original set of users having permission to read the sensitive information at an originating storage device in an originating location via an original set of information transfer paths and (ii) performing a security action. The security action may include (A) determining an additional set of information transfer paths having information transfer paths other than the information transfer paths already discovered, via which the original set of users can write the sensitive information and (B) identifying an additional set of users having permission to read the sensitive information via the additional set of information transfer paths.