Data Protection Simulation for Distributed Database Risk Prioritization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Data security analysts lack tools to effectively identify and prioritize the protection of sensitive data across distributed network databases, determining the most vulnerable data and the most effective protection mechanisms, given limited computational and organizational resources.

Innovation Solution

A method and system that simulates the application of protection mechanisms on data stores in a distributed network database, analyzing the impact of these mechanisms through data grouping, risk metric simulation, and ranking based on simulated values to optimize security protections.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If protection mechanisms are applied to all data stores in distributed databases, then security coverage is improved, but resource consumption increases exponentially

Engineering Contradiction:
Improvesecurity coverageVSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent segments the distributed database into multiple data store groups and applies protection mechanisms selectively to specific groups rather than uniformly to all data stores. This segmentation allows organizations to prioritize protection for high-risk data stores while reducing resource consumption on lower-risk data stores, resolving the contradiction between comprehensive security coverage and exponential resource consumption.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If comprehensive data security analysis is performed across all data stores, then identification accuracy is improved, but computational complexity increases

Engineering Contradiction:
Improveidentification accuracyVSAvoidcomputational complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent performs preliminary actions by first analyzing data store metadata, access patterns, and risk indicators to identify high-priority data stores before applying comprehensive security analysis. This preliminary filtering reduces the scope of detailed analysis to only the most vulnerable data stores, maintaining identification accuracy while significantly reducing computational complexity across the entire distributed database.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If security protections are implemented across all data stores, then enterprise security is improved, but implementation cost increases

Engineering Contradiction:
Improveenterprise securityVSAvoidimplementation cost
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent applies local quality by implementing different levels and types of security protections tailored to specific data store groups based on their risk profiles, sensitivity, and compliance requirements. Rather than applying uniform enterprise-wide protections, the system customizes protection strategies for local data store contexts, achieving effective enterprise security while optimizing implementation costs by avoiding over-protection of low-risk data stores.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12388875B2Method, apparatus, and computer-readable medium for data protection simulation and optimization in a computer network
Publication Date: 2025.08.12 INFORMATICA CORP
  • US12388875B2 patent drawing
  • US12388875B2 patent drawing
  • US12388875B2 patent drawing

AI summary

A system, method and computer-readable medium for data protection simulation and optimization in a computer network, including grouping data stored in data stores in the computer network into groupings according to an architectural or a conceptual attributes, storing, current values of risk metrics for each grouping, each of the metrics corresponding to sensitive domains, receiving a risk reduction goal corresponding to at least one risk metric in the risk metrics, the at least one risk metric corresponding to at least one sensitive domain in the sensitive domains, determining a simulated value of the at least one risk metric for each grouping in the groupings by simulating application of a protection mechanism to sensitive data in each corresponding data store, the sensitive data corresponding to the at least one sensitive domain, and ranking the groupings based on the at least one simulated value of the at least one risk metric for each grouping.