Distributed Data Store Segmentation for Sensitive Content Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprises face challenges in managing and securing unstructured and semi-structured data due to risks of data breaches, misuse of confidential information, and the need for effective data classification and access control, particularly from both internal and external threats.

Innovation Solution

A system and method for organizing and processing data using dynamic, adaptive filters that categorize and classify select content, employing content-based, contextual, and taxonomic filters to securely store and manage sensitive data, ensuring controlled release and distribution based on security clearances.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data is stored in distributed data stores with multiple filters and classification systems, then data security and classification accuracy are improved, but system complexity and data access time increase

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments data into different classification levels (confidential, internal, public) and stores them in separate distributed data stores. Each data store is managed by specific filters tailored to its classification level, allowing security to be improved through segmentation while managing complexity by organizing systems into modular, classification-based units.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediary components including a classification engine that automatically categorizes data before storage, and a data release control system that acts as a mediator between data requests and distributed data stores. These intermediaries handle the complex security and classification logic, shielding users from system complexity while maintaining high security standards.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If dynamic adaptive filters are used to classify and secure data, then classification accuracy and security are improved, but processing time and computational resources increase

Engineering Contradiction:
Improveclassification accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements preliminary classification of data upon ingestion into the system. The classification engine automatically analyzes and categorizes data before it enters the distributed storage system, assigning appropriate security labels and routing to relevant data stores. This preliminary action ensures high classification accuracy while avoiding repeated processing delays during data access operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent employs dynamic adaptive filters that can adjust their classification criteria based on data patterns, user roles, and security contexts. These filters learn from classification outcomes and refine their accuracy over time, improving measurement precision while optimizing processing time through adaptive decision-making that avoids unnecessary computational overhead for routine classifications.

Inventive Principle:
Principle #15Dynamics

3Reliability

If controlled release mechanisms with security clearances are implemented, then data protection and compliance are improved, but data distribution efficiency and accessibility decrease

Engineering Contradiction:
Improvedata protectionVSAvoiddata distribution efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements a feedback mechanism in the data release control system that tracks data access patterns, user roles, and security clearance levels. The system automatically adjusts release permissions based on accumulated feedback, granting access to authorized users without requiring manual security reviews for each request. This maintains strong data protection while improving distribution efficiency through automated, policy-based access decisions.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent creates a universal data release control system that handles multiple security requirements (confidentiality, integrity, availability, compliance) through a single integrated mechanism. The system evaluates user clearances, data classifications, and policy rules simultaneously to make comprehensive access decisions, improving data protection across multiple dimensions while maintaining distribution efficiency by avoiding multiple separate control processes.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12200015B2Information infrastructure management tools with extractor, storage and data release control functions and segmental data stores
Publication Date: 2025.01.14 DIGITAL DOORS INC
  • US12200015B2 patent drawing
  • US12200015B2 patent drawing
  • US12200015B2 patent drawing

AI summary

Method and system of organizing and processing data in a distributed computing system having designated, distributed data stores for sensitive content (e.g., trade secrets) or select content (e.g., critical content). Sensitive/select data is extracted via configurable filters and stored in the designated data stores, sometimes subject to security controls, with limiting distribution functions and controlled release of the sensitive/select data. Distribution is limited due to designated, configurable filters.