Dynamic Sensitivity Scoring for Enterprise Data Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional data security approaches struggle to identify and protect sensitive data across multiple locations and systems, especially in enterprise environments, as they rely on static methods that fail to accurately assess the sensitivity of personal data, leading to inadequate protection and compliance issues under new regulations like GDPR.
Innovation Solution
A data security and protection system using uniqueness factor classification and analysis, which monitors and analyzes data in real-time to determine a sensitivity score based on population attribute data, providing a dynamic and granular assessment of risk to identify and protect sensitive personal data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional data security techniques (encryption, masking, backups) are used, then data protection is provided, but these techniques fail to accurately identify sensitive data across multiple locations and systems
Solution Approach 1:
The patent applies dynamics by transitioning from static data classification policies to dynamic, real-time sensitivity scoring. The system continuously monitors data elements and recalculates sensitivity scores based on current aggregation states and access patterns, allowing the identification of sensitive data to adapt as data is moved, combined, or accessed across systems.
Solution Approach 2:
The patent changes the parameter of data sensitivity from a fixed categorical label to a continuous numerical score. This sensitivity score is dynamically adjusted based on multiple factors including data aggregation level, access frequency, and contextual risk factors, enabling more precise identification of sensitive data states.
2Adaptability or versatility
If general data protection policies are applied to all client or department data, then broad coverage is achieved, but insufficient protection is provided for specific sensitive data elements
Solution Approach 1:
The patent applies local quality by implementing granular, element-level sensitivity scoring rather than uniform department-level policies. Each data element receives an individual sensitivity score based on its specific characteristics, aggregation state, and access patterns, allowing differentiated protection measures tailored to the actual sensitivity of each data element.
Solution Approach 2:
The patent performs preliminary sensitivity assessment and scoring on data elements before they are accessed or combined. This advance identification of sensitive data elements allows proactive application of protection measures and enables the system to anticipate when data aggregation may create sensitive combinations before they occur.
3Ease of operation
If manual identification of sensitive data by administrators is used, then policy creation is simplified, but sensitive data stored outside known locations is not protected
Solution Approach 1:
The patent implements self-service by enabling the system to automatically identify and score sensitive data elements without requiring manual administrator intervention. The sensitivity scoring mechanism autonomously monitors data across all locations and systems, automatically detecting sensitive data elements and their aggregation states, thereby eliminating the limitations of manual identification while maintaining policy management simplicity.
4Reliability
If data sensitivity is assessed based on data location and department ownership, then initial protection coverage is achieved, but aggregated data sensitivity is not detected
Solution Approach 1:
The patent applies feedback by continuously monitoring data aggregation events and updating sensitivity scores in real-time. When data elements are combined or accessed together, the system detects these aggregation patterns and recalculates sensitivity scores accordingly, providing feedback loops that enable dynamic adjustment of protection measures based on actual data usage and combination patterns.
Data Source
AI summary
A data security and protection system that provides monitoring, diagnostics, and analytics within an enterprise network to identify potentially sensitive data is disclosed. The system may provide one or more data stores to store and manage personal data within a network. The system may also provide one or more servers to facilitate operations using information from the one or more data stores. The system may also provide an analytics system with processing components that determines uniqueness of personal data. The system may receive personal data and population attribute data via a data access interface. The analytics system may compare the data received to determine a fraction assignment, which when further processed using at least a combination or correlation technique, may yield a detailed uniqueness factor classification and analysis of the personal data to indicate its relative sensitivity. If there is risk associated with the sensitivity of the personal data, additional security actions may be taken by the data security and protection system.


