Metadata Tagging for PII Security Compliance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems face challenges in ensuring compliance with security rules for Personally Identifiable Information (PII) across different geographical locations and applications, leading to potential penalties for non-compliance.

Innovation Solution

The implementation of metadata tags, specifically a first metadata tag indicating security rules for the application and a second metadata tag indicating rules for the user, which are added to the PII and encrypted to ensure compliance, allowing the data processing center to handle and store the PII according to specified security settings.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If PII is transferred and stored across multiple geographical locations for processing and backup, then data availability and processing capability are improved, but compliance with security rules becomes more difficult to ensure

Engineering Contradiction:
Improvedata processing capabilityVSAvoidsecurity rules compliance
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments security rule compliance into application-level metadata tags that are attached to each PII data element. This segmentation allows different PII elements to have different security requirements enforced independently, enabling multi-location storage while maintaining compliance through granular control tags that travel with the data.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies preliminary action by encoding security rules into metadata tags before PII is transferred or stored. The compliance requirements are predetermined and attached to data elements prior to movement, ensuring that security constraints are established in advance rather than enforced reactively at each location.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If multiple security rules are enforced for different applications and users, then security compliance is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity complianceVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal metadata tag structure that can accommodate multiple security rules for different applications and users through a standardized format. The tag system is multi-functional, handling encryption requirements, retention policies, and access controls through a single unified mechanism rather than separate systems for each rule type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system enables self-service by embedding all necessary security rule information directly in the metadata tags attached to PII. Data processing systems can automatically enforce compliance by reading and acting on the tag information without requiring complex centralized coordination or manual intervention for each security rule.

Inventive Principle:
Principle #25Self-service

3Reliability

If PII is protected with encryption and metadata tags, then security compliance is improved, but data processing overhead increases

Engineering Contradiction:
Improvesecurity complianceVSAvoiddata processing overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts security rule enforcement from the main data processing workflow by using separate metadata tags that reference encryption keys and policies. The actual PII data can be processed efficiently while security compliance is handled through lightweight tag validation and key management operations rather than encrypting/decrypting data with every processing step.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11397830B2Security rules compliance for personally identifiable information
Publication Date: 2022.07.26 HEWLETT PACKARD ENTERPRISE DEV LP
  • US11397830B2 patent drawing
  • US11397830B2 patent drawing
  • US11397830B2 patent drawing

AI summary

In an example, a first metadata tag and a second metadata tag are added to first Personally Identifiable Information (PII) of a first user handled by a first application. The first PII is to be part of call home data captured from a hosting system. The first metadata tag may be indicative of security rules to be complied with for the first application and the second metadata tag may be indicative of security rules to be complied with for the first user. The first PII, the first metadata tag, and the second metadata tag may be protected and transmitted to a data processing center. The transmission may be in response to a determination to transmit the call home data.