Dynamic Data Placement for Privacy Compliance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems for managing access and data sensitivity in computing environments require manual and often cumbersome processes to comply with privacy laws, such as GDPR, HIPPA, and PIPEDA, placing a burden on security and privacy experts to handle data storage, access, and compliance independently.
Innovation Solution
A method and system that dynamically places and stores data based on sensitivity and access types, using a Built-in Legal Framework File System (LFFS) that enforces consent-based access, automates data encryption, and segregates data into 'hot' and 'cold' volumes for efficient protection and compliance, utilizing metadata to track access and consent information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If manual processes are used to manage data access and sensitivity compliance, then experts can control data management, but the burden on experts increases and efficiency decreases
Solution Approach 1:
The system enables self-service by automatically analyzing data access patterns, identifying sensitive data, and enforcing compliance rules without requiring manual intervention from experts. The automated access value calculation and data placement decisions eliminate the burden of manual compliance management while maintaining security and privacy standards.
Solution Approach 2:
The system changes the approach from manual parameter setting to automated parameter calculation. By dynamically calculating access values based on multiple parameters (data sensitivity, access frequency, access type) and automatically adjusting data placement accordingly, the system eliminates manual compliance management while maintaining security standards.
2Productivity
If data is stored on a single volume, then storage is simple, but access efficiency and security for different data types deteriorates
Solution Approach 1:
The system segments data storage into multiple volumes based on access patterns and sensitivity levels. High-access confidential data is separated from low-access data, and each volume can be optimized for its specific access characteristics. This segmentation enables differentiated security measures and access controls without requiring complete system redesign.
Solution Approach 2:
The system implements dynamic data placement where data is automatically moved between volumes based on changing access patterns and compliance requirements. The automated access value calculation continuously monitors data access and adjusts placement decisions, allowing the storage structure to adapt to varying productivity and security needs without manual reconfiguration.
3Reliability
If sensitive data is not separated from non-sensitive data, then storage is simpler, but security and compliance requirements deteriorate
Solution Approach 1:
The system applies local quality by differentiating security measures based on data sensitivity and access characteristics. Different volumes are created with appropriate security controls matched to their contents - high-security measures for high-access confidential data, standard measures for other data types. This localized approach ensures compliance without uniformly applying maximum security to all data.
Data Source
AI summary
An approach is disclosed for placing data on volumes. Accesses to data entries at a source location are analyzed to determine locations of the data entries in one or more files. Types of data are identified at the one or more data entries. Types of accesses are identified for the data entries. Durations of the types of accesses to the data entries are identified. An access value is calculated by mapping the one or more types of data combined with the one or more types of accesses combined with the one or more durations of the types of accesses. Confidential sensitive data is moved according to the calculated access value, where a highly accessed confidential data is separated from lighted accessed confidential data by moving a selected portion of data from the source location to the destination location.


