Privacy Annotation Framework for Sensitive Data Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing user productivity applications face challenges in identifying and protecting sensitive data within structured or semi-structured documents, such as spreadsheets and presentations, where sensitive information can be split across multiple data entities, making it difficult to prevent data loss and ensure compliance with privacy policies.

Innovation Solution

A data loss protection framework that identifies sensitive data within user content by apportioning it into chunks, processing these chunks to determine sensitive content using classification rules and policies, and annotating the sensitive data within the user interface, providing users with options to obfuscate or mask the data, while also establishing thresholds for notification and annotation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If sensitive data is split across multiple data entities in structured documents, then data can be stored and processed efficiently, but identification and protection of sensitive data becomes difficult

Engineering Contradiction:
Improvedata processing efficiencyVSAvoidsensitive data identification difficulty
Core Design Contradiction:
ProductivityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent segments sensitive data identification into two levels: (1) chunk-level scanning that processes data in manageable segments to maintain efficiency, and (2) element-level annotation that identifies specific content elements containing sensitive data. This segmentation allows efficient processing while maintaining precise detection capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces annotation indicators as intermediary elements that bridge the gap between chunk-level processing and element-level identification. These indicators serve as mediators that flag content elements containing sensitive data without requiring complete manual inspection of each element.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If annotation indicators are presented for all content elements containing sensitive data, then complete protection coverage is achieved, but user interface complexity and information overload increase

Engineering Contradiction:
Improveprotection coverage completenessVSAvoiduser interface complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by presenting annotation indicators selectively rather than uniformly. The system evaluates the quantity of content elements containing sensitive data and adjusts the presentation strategy accordingly - using summary indicators when quantities are high and detailed indicators when quantities are low, optimizing the balance between coverage and interface complexity.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements dynamic adjustment of annotation indicator presentation based on the quantity of sensitive data detected. The system transitions between different presentation modes (summary vs. detailed) depending on the situation, making the interface adaptable to the data characteristics rather than static.

Inventive Principle:
Principle #15Dynamics

3Reliability

If real-time identification and annotation of sensitive data is implemented, then data loss prevention is improved, but processing time and computational resources increase

Engineering Contradiction:
Improvedata loss prevention effectivenessVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary scanning and identification of sensitive data during the content edit process rather than waiting for final processing. By identifying sensitive data early and annotating it in real-time, the system prevents data loss before it occurs while managing processing loads through incremental analysis.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent maintains continuous monitoring and annotation during the content editing process. Rather than performing batch processing, the system continuously identifies and annotates sensitive data as it appears or is modified, ensuring uninterrupted protection while distributing computational load over time.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS11544402B2Annotations for privacy-sensitive user content in user applications
Publication Date: 2023.01.03 MICROSOFT TECHNOLOGY LICENSING LLC
  • US11544402B2 patent drawing
  • US11544402B2 patent drawing
  • US11544402B2 patent drawing

AI summary

Systems, methods, and software for data privacy annotation frameworks for user applications are provided herein. An exemplary method includes identifying content elements among user content in a user data file that contain sensitive data corresponding to one or more predetermined data schemes. During a content edit process for the user content in a user application, the method includes controlling presentation of annotation indicators for one or more of the content elements based at least in part on a quantity of the content elements that contain the sensitive data.