Sensitive Data Leak-Detection Engine for Pre-Deployment Code Scanning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional security management systems lack comprehensive computing logic and infrastructure for efficient sensitive data leak-detection, particularly in large-scale software development environments, leading to inefficiencies and increased computational costs.

Innovation Solution

A sensitive data leak-detection engine integrated into the software development environment, utilizing a logging framework, onboarding engine, and code scanning package to automate sensitive data scanning during the development stage, identifying potential leaks through a mock library and generating notifications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional security management systems are used for sensitive data leak-detection, then basic security checking can be performed, but computational overhead and resource consumption increase significantly

Engineering Contradiction:
Improvesensitive data leak-detection capabilityVSAvoidcomputational overhead
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system performs sensitive data scanning during the development stage before code is deployed to production environments. By detecting and addressing sensitive data leaks in advance, the system prevents the need for computationally intensive scanning of production systems, thereby reducing overall computational overhead while maintaining detection reliability

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The security management system is divided into distinct functional components including a sensitive data leak-detection engine, logging framework, onboarding engine, and code scanning package. This segmentation allows each component to operate independently with optimized resource allocation, reducing the computational burden on any single system element

Inventive Principle:
Principle #1Segmentation

2Reliability

If comprehensive sensitive data scanning is implemented in production systems, then all sensitive data leaks can be detected, but CPU usage and memory requirements increase significantly

Engineering Contradiction:
Improvesensitive data leak-detection coverageVSAvoidsystem performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system shifts security scanning operations to the development stage, performing sensitive data detection before code reaches production. This preliminary action ensures comprehensive detection coverage while preserving production system performance by eliminating the need for continuous scanning in live environments

Inventive Principle:
Principle #10Preliminary action

3Reliability

If integrated sensitive data leak-detection is implemented during development stage, then security management is improved, but integration complexity with existing development processes increases

Engineering Contradiction:
Improvesecurity management effectivenessVSAvoidsystem integration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The sensitive data leak-detection engine is designed as a universal system that can integrate with multiple different development workflows and logging frameworks through standardized interfaces. The mock library for common logger and configurable scanning parameters enable the system to work across diverse development environments without requiring custom integration for each case

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system introduces an intermediary logging framework that sits between the development code and the security detection engine. This intermediary layer standardizes data collection and filtering, simplifying integration with existing development processes while maintaining comprehensive detection capabilities

Inventive Principle:
Principle #24Intermediary (Mediator)

4Ease of operation

If automated onboarding process is implemented for sensitive data scanning, then ease of operation is improved, but initial setup time and configuration complexity increase

Engineering Contradiction:
Improvedeveloper usabilityVSAvoidonboarding time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The onboarding engine implements automated configuration that allows the system to self-configure by detecting existing development environments, logging frameworks, and code structures. This self-service capability reduces manual setup requirements and accelerates the onboarding process while maintaining ease of operation for developers

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12443747B2Sensitive data leak-detection engine in a security management system
Publication Date: 2025.10.14 MICROSOFT TECHNOLOGY LICENSING LLC
  • US12443747B2 patent drawing
  • US12443747B2 patent drawing
  • US12443747B2 patent drawing

AI summary

Methods, systems, and computer storage media for providing a sensitive data scanning in a sensitive data leak-detection engine of a security management system. Sensitive data scanning—for example confidential information scanning or credential scanning—provides sensitive data leak-detection via a software development environment during a software development process. In operation, a request—to execute a sensitive data scanning operation on an instance of in-development code—is accessed. The sensitive data scanning operation executable via a sensitive data leak-detection engine that provides code security management services in a software development environment. A code scanning package is accessed. The code scanning package comprises software development environment code scanning parameters. Based on the software development environment code scanning parameters, the in-development code is scanned for sensitive data. A notification comprising a sensitive data scan result associated with the in-development code is generated. The notification is communicated to cause the notification to be displayed.