Dynamic Data Placement for Privacy Compliance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems for managing access and data sensitivity in computing environments require manual and often cumbersome processes to comply with privacy laws, such as GDPR, HIPPA, and PIPEDA, placing a burden on security and privacy experts to handle data storage, access, and compliance independently.

Innovation Solution

A method and system that dynamically places and stores data based on sensitivity and access types, using a Built-in Legal Framework File System (LFFS) that enforces consent-based access, automates data encryption, and segregates data into 'hot' and 'cold' volumes for efficient protection and compliance, utilizing metadata to track access and consent information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If manual processes are used to manage data access and sensitivity compliance, then experts can control data management, but the burden on experts increases and efficiency decreases

Engineering Contradiction:
ImproveData management easeVSAvoidCompliance automation
Core Design Contradiction:
Ease of operationVSExtent of automation

Solution Approach 1:

The system enables self-service by automatically analyzing data access patterns, identifying sensitive data, and enforcing compliance rules without requiring manual intervention from experts. The automated access value calculation and data placement decisions eliminate the burden of manual compliance management while maintaining security and privacy standards.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system changes the approach from manual parameter setting to automated parameter calculation. By dynamically calculating access values based on multiple parameters (data sensitivity, access frequency, access type) and automatically adjusting data placement accordingly, the system eliminates manual compliance management while maintaining security standards.

Inventive Principle:
Principle #35Parameter changes

2Productivity

If data is stored on a single volume, then storage is simple, but access efficiency and security for different data types deteriorates

Engineering Contradiction:
ImproveData access efficiencyVSAvoidStorage structure complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system segments data storage into multiple volumes based on access patterns and sensitivity levels. High-access confidential data is separated from low-access data, and each volume can be optimized for its specific access characteristics. This segmentation enables differentiated security measures and access controls without requiring complete system redesign.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements dynamic data placement where data is automatically moved between volumes based on changing access patterns and compliance requirements. The automated access value calculation continuously monitors data access and adjusts placement decisions, allowing the storage structure to adapt to varying productivity and security needs without manual reconfiguration.

Inventive Principle:
Principle #15Dynamics

3Reliability

If sensitive data is not separated from non-sensitive data, then storage is simpler, but security and compliance requirements deteriorate

Engineering Contradiction:
ImproveData securityVSAvoidData segregation structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system applies local quality by differentiating security measures based on data sensitivity and access characteristics. Different volumes are created with appropriate security controls matched to their contents - high-security measures for high-access confidential data, standard measures for other data types. This localized approach ensures compliance without uniformly applying maximum security to all data.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11327665B2Managing data on volumes
Publication Date: 2022.05.10 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11327665B2 patent drawing
  • US11327665B2 patent drawing
  • US11327665B2 patent drawing

AI summary

An approach is disclosed for placing data on volumes. Accesses to data entries at a source location are analyzed to determine locations of the data entries in one or more files. Types of data are identified at the one or more data entries. Types of accesses are identified for the data entries. Durations of the types of accesses to the data entries are identified. An access value is calculated by mapping the one or more types of data combined with the one or more types of accesses combined with the one or more durations of the types of accesses. Confidential sensitive data is moved according to the calculated access value, where a highly accessed confidential data is separated from lighted accessed confidential data by moving a selected portion of data from the source location to the destination location.