Local Data Classification Service for On-Premises Compliance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Organizations face challenges in efficiently classifying and managing large amounts of data stored across various database systems within their local networks, particularly when sensitive data must remain on-premises due to regulatory requirements, leading to time-consuming manual processes and potential errors.
Innovation Solution
Implementing a local data classification service that runs on a client network, utilizing a data classification engine and management interface similar to those provided by remote provider networks, allowing for seamless transition and accurate classification without exposing sensitive data outside the client network's boundaries.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If manual data classification processes are used to locate and identify data for remote storage, then data can be classified and transmitted to remote provider networks, but the process becomes time-consuming and labor-intensive
Solution Approach 1:
The system enables self-service through automated data classification services that autonomously scan, identify, and classify data across distributed database systems without requiring manual human intervention. The service automatically determines which data should be transmitted to remote provider networks based on pre-defined classification rules and sensitivity criteria.
Solution Approach 2:
Manual mechanical processes of data location and classification are replaced with automated computational systems. The patent implements software-based data classification services that use algorithms and automated scanning mechanisms to identify and categorize data, substituting human manual work with automated information processing systems.
2Reliability
If sensitive data is stored on premises to comply with regulatory requirements, then data security and compliance are improved, but the ability to utilize remote storage services for that data is restricted
Solution Approach 1:
The system applies local quality by implementing location-specific data classification and retention policies. Different data classification rules and security requirements are applied based on the local regulatory environment and organizational policies. The automated service identifies which data must remain on-premises versus which data can be transmitted to remote provider networks, allowing each data element to be handled according to its specific compliance requirements.
3Ease of operation
If data is stored across various database systems throughout the local network, then data organization and accessibility are improved, but the complexity of locating and classifying data increases
Solution Approach 1:
The automated data classification service implements universality by providing a single unified service that can operate across multiple different database systems and data formats. The service is designed to work with various data sources throughout the local network, applying consistent classification rules universally across diverse data environments without requiring separate manual processes for each database system.
Data Source
AI summary
A connected device at a client network implements a local data classification service for classifying data based on a data classification service of a remote provider network. The local data classification service receives a request to classify data at one or more data sources of the client network. The request is initiated from a client device of the client network according to a management interface for a data classification service of a remote provider network (e.g., using the same API request used by the remote classification service). The local data classification service obtains at least some of the data from the one or more data sources of the client network. The local data classification service classifies the obtained data according to different types of sensitivity using the data classification engine in the execution environment without the data being exposed outside of a data isolation boundary of the client network.


