Request Classification System for Personal Data Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems fail to consistently classify and route personal data requests at the point of entry within an enterprise's trusted internal computing network, leading to potential data breaches and non-compliance with regulations due to inconsistent processing across various request channels.

Innovation Solution

A system that classifies requests for personal data at or before the point of entry using machine-learning processing to determine the appropriate classification based on entities, origins, actions, and data elements, routing them accordingly through a predetermined queue to ensure compliance with regulations, regardless of the request channel.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If data requests are processed immediately upon receipt without classification, then processing speed is improved, but data security and regulatory compliance deteriorate

Engineering Contradiction:
Improverequest processing speedVSAvoiddata security compliance
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The system performs classification of data requests at the point of entry into the trusted internal computing network, before the requests are routed to downstream processing systems. This preliminary classification ensures that security measures and regulatory compliance checks are established in advance, allowing fast processing while maintaining security standards.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If different request channels process data requests independently, then channel autonomy and flexibility are improved, but consistency in processing regulated data deteriorates

Engineering Contradiction:
Improverequest channel autonomyVSAvoidprocessing consistency
Core Design Contradiction:
Adaptability or versatilityVSManufacturing precision

Solution Approach 1:

The classification system is designed to handle multiple types of data requests from various channels (email, online entry, mobile application, voice call, in-person requests) through a unified classification framework. The system universally applies classification rules across all channels, ensuring consistent processing of regulated data while preserving channel-specific interfaces and user experiences.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If classification occurs after data access actions are initiated, then processing efficiency is improved, but the ability to prevent unauthorized access deteriorates

Engineering Contradiction:
Improvedata access efficiencyVSAvoidunauthorized data access risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system classifies data requests at the point of entry, before any data access actions are initiated. This preliminary classification determines the appropriate handling and routing of requests, ensuring that security measures are in place before data access occurs, thereby preventing unauthorized access while maintaining efficient processing.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If a centralized classification system is implemented at the point of entry, then data security and consistency are improved, but system complexity increases

Engineering Contradiction:
Improveclassification consistencyVSAvoidclassification system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The classification system acts as an intermediary component positioned at the entry point between external request channels and the trusted internal computing network. This centralized intermediary handles all classification logic in one location, ensuring consistent classification across all channels while simplifying the overall system architecture by consolidating classification functions rather than distributing them across multiple systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11165883B2Entry point classification of requests requiring access to data
Publication Date: 2021.11.02 BANK OF AMERICA CORP
  • US11165883B2 patent drawing
  • US11165883B2 patent drawing
  • US11165883B2 patent drawing

AI summary

Embodiments of the invention are directed to classifying requests associated with personal data at or before a point of entry to a trusted computing network. The invention provides for determining whether a request associated with personal data requires classification (for example, whether the request is impacted by regulations or other requirements necessitating classification/categorization). The determination may be based on what entity is requesting the data, the origin of the request, whose data is being requested, the type of action associated with the request and/or the data elements associated with the request. In addition, once the request has been determined to require classification the specific classification is determined and assigned to the request. The classification may be determined based on the rules associated with the regulation or other requirement(s) necessitating the classification/categorization. The classification may identify rules for processing the request along with routing for the request.