Data Sensitivity Classification for Secure Storage Distribution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data storage systems often fail to correctly implement data security measures during initial backups, as the backup administrators may not be familiar with the clients' specific security policies, leading to potential misclassification of data sensitivity.

Innovation Solution

A system that distributes data amongst storage components using data sensitivity classifications, which involves creating a data distribution policy, categorizing data files, assigning sensitivity ratings, and continuously reevaluating data files to ensure they are stored on appropriate storage components that meet their sensitivity requirements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If backup administrators configure backup profiles independently, then data distribution can be performed, but data security measures may not be implemented correctly according to client security policies

Engineering Contradiction:
Improvedata distribution capabilityVSAvoiddata security implementation
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a data sensitivity classification system as an intermediary layer between the backup administrator and the storage system. This intermediary automatically classifies data into sensitivity categories (e.g., public, internal, confidential) and maps them to appropriate storage locations, ensuring security policies are enforced without requiring administrators to manually configure each security parameter.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs self-service by automatically evaluating data sensitivity and making intelligent decisions about storage placement. The data sensitivity classification module autonomously analyzes data characteristics, compares them against security policies, and determines appropriate storage destinations without requiring continuous human intervention or expert knowledge from administrators.

Inventive Principle:
Principle #25Self-service

2Reliability

If different clients have different security profiles for the same data types, then security requirements can be met, but the complexity of configuring backup profiles increases

Engineering Contradiction:
Improvesecurity policy complianceVSAvoidbackup profile configuration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the complex security configuration task into separate, manageable components: data sensitivity classification, security policy definition, and storage location mapping. By segmenting the configuration process, administrators can define security policies at high levels (e.g., 'confidential data must be encrypted') without needing to configure every individual storage parameter for each client.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The data sensitivity classification system serves multiple functions simultaneously: it classifies data, determines sensitivity levels, maps to storage locations, and enforces security policies. This multi-functional approach eliminates the need for separate configuration mechanisms for each function, reducing overall system complexity while maintaining security compliance.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If initial backup configuration is performed manually, then data can be stored, but continuous security compliance cannot be ensured

Engineering Contradiction:
Improveinitial backup speedVSAvoidcontinuous security compliance
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements continuous security compliance through ongoing data sensitivity evaluation and storage location verification. The system continuously monitors data movements, re-evaluates sensitivity classifications, and ensures data remains in appropriate storage locations even after initial backup, maintaining security compliance throughout the data lifecycle.

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The system incorporates feedback mechanisms that continuously monitor storage compliance and provide real-time adjustments. When data is moved or reclassified, the system receives feedback about the new storage location and automatically verifies it meets security requirements, enabling continuous compliance assurance without manual intervention.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12216778B2Distributing data amongst storage components using data sensitivity classifications
Publication Date: 2025.02.04 EMC IP HLDG CO LLC
  • US12216778B2 patent drawing
  • US12216778B2 patent drawing
  • US12216778B2 patent drawing

AI summary

Described is a system for distributing data amongst storage components using data sensitivity (or security) classifications. The system may define categories for classifying data files and assign a sensitivity (or security) rating to each of the defined categories. The categories and/or associated sensitivity ratings may be determined using machine learning components that may leverage industry-specific information or data sensitivity information used by other clients. The system may then continuously reevaluate (or reclassify) data files to determine whether they are stored on a storage component that meets the necessary data sensitivity requirements. If the system determines particular data files are stored on a corresponding storage component that does not meet certain data sensitivity requirements, the system may perform an action to secure the particular data files.