Data Sensitivity Classification for Secure Storage Distribution
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data storage systems often fail to correctly implement data security measures during initial backups, as the backup administrators may not be familiar with the clients' specific security policies, leading to potential misclassification of data sensitivity.
Innovation Solution
A system that distributes data amongst storage components using data sensitivity classifications, which involves creating a data distribution policy, categorizing data files, assigning sensitivity ratings, and continuously reevaluating data files to ensure they are stored on appropriate storage components that meet their sensitivity requirements.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If backup administrators configure backup profiles independently, then data distribution can be performed, but data security measures may not be implemented correctly according to client security policies
Solution Approach 1:
The patent introduces a data sensitivity classification system as an intermediary layer between the backup administrator and the storage system. This intermediary automatically classifies data into sensitivity categories (e.g., public, internal, confidential) and maps them to appropriate storage locations, ensuring security policies are enforced without requiring administrators to manually configure each security parameter.
Solution Approach 2:
The system performs self-service by automatically evaluating data sensitivity and making intelligent decisions about storage placement. The data sensitivity classification module autonomously analyzes data characteristics, compares them against security policies, and determines appropriate storage destinations without requiring continuous human intervention or expert knowledge from administrators.
2Reliability
If different clients have different security profiles for the same data types, then security requirements can be met, but the complexity of configuring backup profiles increases
Solution Approach 1:
The patent segments the complex security configuration task into separate, manageable components: data sensitivity classification, security policy definition, and storage location mapping. By segmenting the configuration process, administrators can define security policies at high levels (e.g., 'confidential data must be encrypted') without needing to configure every individual storage parameter for each client.
Solution Approach 2:
The data sensitivity classification system serves multiple functions simultaneously: it classifies data, determines sensitivity levels, maps to storage locations, and enforces security policies. This multi-functional approach eliminates the need for separate configuration mechanisms for each function, reducing overall system complexity while maintaining security compliance.
3Productivity
If initial backup configuration is performed manually, then data can be stored, but continuous security compliance cannot be ensured
Solution Approach 1:
The patent implements continuous security compliance through ongoing data sensitivity evaluation and storage location verification. The system continuously monitors data movements, re-evaluates sensitivity classifications, and ensures data remains in appropriate storage locations even after initial backup, maintaining security compliance throughout the data lifecycle.
Solution Approach 2:
The system incorporates feedback mechanisms that continuously monitor storage compliance and provide real-time adjustments. When data is moved or reclassified, the system receives feedback about the new storage location and automatically verifies it meets security requirements, enabling continuous compliance assurance without manual intervention.
Data Source
AI summary
Described is a system for distributing data amongst storage components using data sensitivity (or security) classifications. The system may define categories for classifying data files and assign a sensitivity (or security) rating to each of the defined categories. The categories and/or associated sensitivity ratings may be determined using machine learning components that may leverage industry-specific information or data sensitivity information used by other clients. The system may then continuously reevaluate (or reclassify) data files to determine whether they are stored on a storage component that meets the necessary data sensitivity requirements. If the system determines particular data files are stored on a corresponding storage component that does not meet certain data sensitivity requirements, the system may perform an action to secure the particular data files.


