Data Segmentation via Content and Behavioral Classes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing volume of unstructured and scattered data poses challenges in managing and securing sensitive information, particularly in healthcare and other regulated sectors, where improper handling can lead to data breaches and non-compliance with regulations due to the lack of understanding of data storage and usage within networks.

Innovation Solution

A data-defined network (DDN) approach that classifies data based on observed attributes and behavior, using artificial intelligence and machine learning to identify normal and anomalous behavior, and enforces policies to ensure compliance and security by organizing data structures around content and behavioral classes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If data is stored in unstructured formats across multiple locations, then data storage capacity is increased, but data visibility and control are reduced

Engineering Contradiction:
Improvedata storage capacityVSAvoiddata visibility
Core Design Contradiction:
Quantity of substanceVSLoss of information

Solution Approach 1:

The patent segments data into structured categories (sensitive, non-sensitive, temporary, permanent) and organizes them in a hierarchical file system with defined directories. This segmentation allows the system to maintain comprehensive data storage while restoring visibility and control through structured organization, enabling the data management system to identify, classify, and manage data segments according to their sensitivity and retention requirements.

Inventive Principle:
Principle #1Segmentation

2Reliability

If perimeter defenses are used for data security, then network boundary protection is improved, but interior defense capability is reduced

Engineering Contradiction:
Improvenetwork boundary protectionVSAvoidinterior defense capability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements a layered security architecture that segments protection into multiple zones: perimeter defenses (firewalls, intrusion detection), internal data classification (sensitive vs. non-sensitive), and file-level encryption. This segmentation creates纵深 defense in depth, where each layer provides independent protection, allowing the system to maintain strong perimeter protection while adding robust interior defense capabilities through structured data organization and classification.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies prior cushioning by implementing data classification and encryption before data is stored or accessed. Sensitive data is identified, classified, and encrypted in advance, creating a buffer of protection that remains in place regardless of perimeter breach status. This pre-established security cushioning ensures that even if perimeter defenses are compromised, the interior data remains protected through pre-applied security measures.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

3Reliability

If local security processes are deployed on every device, then interior defense is improved, but system complexity and vulnerability points are increased

Engineering Contradiction:
Improveinterior defenseVSAvoidsecurity system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges security functions into a centralized data management system that operates at the file and data level rather than requiring separate security processes on each device. By combining classification, encryption, access control, and monitoring functions into a unified system that works with the underlying operating systems and file structures, the patent reduces overall system complexity while maintaining comprehensive interior defense capabilities.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates a universal data management framework that provides multiple security functions (classification, encryption, access control, retention management) through a single integrated system. This multi-functional approach eliminates the need for separate security processes on each device, as the centralized system can enforce security policies across all data regardless of location or format, reducing complexity while maintaining comprehensive protection.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Adaptability or versatility

If data classification is not implemented, then data handling flexibility is maintained, but compliance with regulations becomes difficult

Engineering Contradiction:
Improvedata handling flexibilityVSAvoidregulatory compliance
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments data into classified categories (sensitive, non-sensitive) with defined handling requirements for each segment. This segmentation enables automated application of appropriate security measures and retention policies based on data type, maintaining flexibility in how different data segments are handled while ensuring regulatory compliance through consistent, rule-based management of sensitive information.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic data classification that automatically adjusts security measures based on data characteristics and context. The system dynamically identifies, classifies, and applies appropriate security policies to data as it is created, modified, or accessed, providing flexible adaptability to different data types while maintaining consistent compliance with regulatory requirements through automated policy enforcement.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11381587B2Data segmentation
Publication Date: 2022.07.05 HELIOS DATA INC
  • US11381587B2 patent drawing
  • US11381587B2 patent drawing
  • US11381587B2 patent drawing

AI summary

Techniques are disclosed relating to data management. A computer system may evaluate network traffic to extract and group data objects based on their content satisfying similarity criteria, and to identify baseline behavior with respect to those data objects. The computer system may generate data-defined network (DDN) data structures that include a content class and one or more behavioral classes. The content class may be indicative of one or more of the data objects that have been grouped based on them satisfying the similarity criteria. The one or more behavioral classes may indicate baseline behavior of those data objects within the content class as determined from evaluation of the network traffic. The computer system may detect, using the DDN data structures, anomalous data behavior within network traffic. In response to detecting anomalous data behavior, the computer system may prevent network traffic corresponding to the anomalous data behavior from being communicated.