Event-Based SPI Security for Usage-Aware Data Retention
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current data storage systems lack mechanisms to determine when sensitive and personal information (SPI) is unlikely to be used, leading to inefficient purging, rigidity in data retention, and potential non-compliance with regulations, resulting in additional overhead and user unfriendliness.
Innovation Solution
An event-based framework that learns and detects events indicating actions on user data, predicting the need for actions such as moving, modifying, or removing sensitive information, and provides real-time customer service assistance to confirm these actions, using reinforcement learning to improve future recommendations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Extent of automation
If time window-based purging is used, then data retention is automated, but data may be purged unnecessarily resulting in overhead costs and loss of information
Solution Approach 1:
The system continuously monitors user interactions with SPI and uses this feedback to dynamically adjust retention decisions. When users interact with data beyond the time window, the system receives feedback that the data is still needed and reverses the purging action, preventing information loss while maintaining automation.
Solution Approach 2:
The purging policy transitions from static time-based rules to dynamic, usage-aware decisions. The system adapts retention behavior based on real-time user interaction patterns, allowing data to be retained longer when usage indicates continued need, thereby avoiding unnecessary information loss.
2Device complexity
If time window-based purging is used, then data management is simplified, but system rigidity increases and adaptability to user needs decreases
Solution Approach 1:
The system incorporates feedback loops that monitor user interactions with SPI and automatically adjust retention decisions. This feedback mechanism enables the system to adapt to changing user needs while maintaining relatively simple data management architecture, resolving the contradiction between simplicity and adaptability.
Solution Approach 2:
The system dynamically changes the retention parameter based on usage patterns rather than relying on fixed time windows. By adjusting retention duration as a variable parameter responsive to user behavior, the system achieves adaptability without significantly increasing management complexity.
3Ease of operation
If SPI data is retained longer, then user friendliness improves, but overhead costs to system providers increase
Solution Approach 1:
The system applies partial retention rather than complete retention. It retains SPI only for the duration necessary based on actual usage patterns, avoiding both premature deletion and excessive retention. This partial action approach balances user friendliness with cost efficiency by retaining data just long enough to serve user needs.
Solution Approach 2:
The retention parameter is dynamically adjusted based on usage intensity and patterns. The system changes retention duration from a fixed long period to a variable duration that responds to user behavior, thereby reducing overhead costs while maintaining user friendliness during active usage periods.
4Device complexity
If time window-based purging is used, then compliance is easier to implement, but compliance with international SPI laws may be violated
Solution Approach 1:
The system uses feedback from user location and interaction data to determine appropriate retention periods. When users relocate to different countries, the system receives feedback about changed circumstances and adjusts retention accordingly, ensuring compliance with international laws while maintaining simple implementation through automated decision-making.
Solution Approach 2:
The compliance approach transitions from static time-based rules to dynamic, context-aware retention. The system adapts retention behavior based on real-time user location and usage data, ensuring reliability of compliance with varying international regulations without significantly increasing implementation complexity.
Data Source
AI summary
A system and method are disclosed for event-based data security. The method includes learning customer events which require an action on sensitive and personal information (SPI), learning a mapping between the customer events and a first subset of the SPI, detecting for a particular customer an event having an impact on the SPI of the particular customer, determining a second subset of the SPI that may be impacted by the event, determining an action to perform for the second subset of the SPI, and performing the action on the second subset of SPI. The method further includes learning the mapping using data streams, where the data streams comprise security policies, customer interactions, publicly available information and a product catalog. The method further includes where the action comprises moving the SPI, modifying the SPI, masking the SPI or removing the SPI.


