Protected Data Type Library for Security Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizations face difficulties in identifying and managing security weaknesses within computing systems that handle protected data, making it challenging to respond efficiently to data breaches.

Innovation Solution

A protected data type library and usage graph system that provides automated tracking and analysis of protected data usage across computing systems, enabling secure deployment and real-time monitoring to limit unauthorized access and exposure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If organizations deploy numerous computing systems to handle diverse data types, then system functionality and data processing capability are improved, but the complexity of identifying and managing security weaknesses increases

Engineering Contradiction:
Improvesystem functionalityVSAvoidsecurity management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements automated feedback mechanisms where security analysis tools continuously scan computing systems, identify protected data usage, and provide real-time feedback to security management platforms. This enables dynamic tracking and monitoring of security weaknesses across diverse systems without manual intervention, resolving the contradiction between system versatility and security management complexity.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system enables computing systems to self-report and self-analyze their protected data usage through automated scanning and classification tools. Each system performs self-service security assessments, generating detailed reports on protected data handling practices, which eliminates the need for centralized manual security audits and reduces management complexity while maintaining comprehensive oversight.

Inventive Principle:
Principle #25Self-service

2Ease of manufacture

If manual methods are used to identify protected data usage, then implementation simplicity is maintained, but the time and resources required to respond to data breaches increase

Engineering Contradiction:
Improveimplementation simplicityVSAvoidbreach response time
Core Design Contradiction:
Ease of manufactureVSLoss of time

Solution Approach 1:

The patent implements preliminary automated scanning and classification actions that continuously identify and catalog protected data usage before breaches occur. Security weaknesses are detected and documented in advance through automated tools, creating a ready database of security information that enables immediate response to breaches without time-consuming manual investigations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system replaces manual mechanical security assessment methods with automated electronic scanning and analysis tools. These tools automatically traverse computing systems, identify protected data, and analyze security configurations, substituting human manual efforts with automated mechanical processes that operate faster and more consistently, thereby reducing breach response time while maintaining ease of implementation.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If comprehensive security monitoring is implemented across all computing systems, then security awareness and breach detection capability are improved, but the computational resources and system complexity increase

Engineering Contradiction:
Improvesecurity awarenessVSAvoidcomputational resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent implements local quality monitoring where security scanning and analysis are tailored to each computing system's specific characteristics, data types, and risk profiles. Rather than uniform comprehensive monitoring, the system adjusts the depth and scope of security analysis locally based on individual system needs, reducing unnecessary computational overhead while maintaining high security awareness where most critical.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system applies partial monitoring actions focused on critical areas rather than exhaustive monitoring of all systems at maximum intensity. Automated tools prioritize scanning of systems handling sensitive protected data and perform deeper analysis only where security risks are highest, using partial action to achieve sufficient security awareness while conserving computational resources that would be consumed by uniform excessive monitoring across all systems.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS9866574B1Protected data type handling awareness
Publication Date: 2018.01.09 AMAZON TECH INC
  • US9866574B1 patent drawing
  • US9866574B1 patent drawing
  • US9866574B1 patent drawing

AI summary

Protected data type classes are provided for performing operations on protected data types. A fact manifest is generated for a software package that utilizes the classes at build time. The fact manifest describes the protected data types used by the software package. The fact manifest can be used to deploy the software package only to hosts that are authorized to handle the specified protected data types. The fact manifest can also be utilized to create a protected data type usage graph that identifies the hosts that handle protected data, the type of protected data handled, and the network connections between the hosts. The protected data type classes can also generate data at runtime identifying the runtime usage of protected data. The protected data type usage graph can also specify the runtime usage of protected data by the hosts.