Scan Manager Segmentation for Sensitive Data Identification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing concern for protecting sensitive data on computer systems, both in business and personal contexts, due to risks of exposure or misuse, is not adequately addressed by existing technologies, which often fail to efficiently identify and manage sensitive information.

Innovation Solution

A computer-implemented method and system for scanning computer systems, utilizing a scan manager and scan agent to identify and report sensitive data, with user authentication, profile creation, and secure reporting to designated recipients, allowing for categorization and deployment of scanning criteria.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If existing scanning technologies are used to identify sensitive data, then scanning capability is provided, but the efficiency and effectiveness in identifying and managing sensitive information is insufficient

Engineering Contradiction:
Improveefficiency in identifying sensitive dataVSAvoideffectiveness in managing sensitive information
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system segments the sensitive data management process into distinct functional modules: scan manager for orchestration, scan agents for execution, category server for classification, and report manager for delivery. This segmentation enables each component to specialize in specific tasks, improving both efficiency and reliability of sensitive data identification and management.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediary components including the category server that mediates between scan agents and the central system, and the report manager that intermediates between scan results and recipients. These intermediaries enhance reliability by adding layers of verification and proper routing while maintaining high productivity through automated workflows.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If comprehensive scanning of all files is performed, then complete identification of sensitive data is achieved, but scanning time and system resources are excessively consumed

Engineering Contradiction:
Improvecompleteness of sensitive data identificationVSAvoidscanning time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system implements partial scanning by allowing users to select specific folders, drives, or file types for scanning rather than requiring complete system-wide scans. The scan manager enables targeted scanning of only those areas where sensitive data is likely to exist, achieving sufficient identification completeness while dramatically reducing scanning time and resource consumption.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system performs preliminary actions by allowing users to pre-configure scan profiles, select categories of sensitive data to look for, and designate target locations before initiating scans. This preliminary setup enables the system to focus scanning efforts only on relevant areas, maintaining high detection precision while minimizing time loss.

Inventive Principle:
Principle #10Preliminary action

3Loss of information

If detailed scan reports are generated and distributed to multiple recipients, then complete information delivery is achieved, but system complexity and reporting overhead increase

Engineering Contradiction:
Improvecompleteness of scan report informationVSAvoidreporting system complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The report manager is designed as a universal component that handles multiple functions: generating comprehensive scan reports, formatting them in standardized templates, routing to multiple recipients simultaneously, and managing delivery schedules. This multi-functionality achieves complete information delivery while minimizing system complexity by consolidating all reporting operations into a single versatile module.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system allows parameter changes in report generation by enabling users to select different levels of detail, choose specific categories to include or exclude, and adjust formatting options. The report manager can transform the same scan data into different report variants based on recipient needs, maintaining information completeness while managing complexity through configurable parameters.

Inventive Principle:
Principle #35Parameter changes

4Reliability

If user authentication and profile creation are implemented, then security and personalized scanning are improved, but system setup time and operational complexity increase

Engineering Contradiction:
Improvesecurity of scan managementVSAvoidsimplicity of system setup
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system implements self-service authentication where users create their own profiles and credentials through automated registration processes. The scan manager automatically verifies credentials and configures user-specific settings without requiring manual administrator intervention. This self-service approach enhances security through authenticated access while maintaining ease of operation by eliminating complex manual setup procedures.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9721106B2Method and system for scanning a computer system for sensitive content
Publication Date: 2017.08.01 ACCENTURE GLOBAL SERVICES LTD
  • US9721106B2 patent drawing
  • US9721106B2 patent drawing
  • US9721106B2 patent drawing

AI summary

A computer-implemented method for scanning a computer system for sensitive data. A scan manager manages a scan of files of a second computer. The scan manager receives a request to scan and identify files stored on the second computer based on at least one category of sensitive data. The scan manager receives scan report recipient information and generates a user profile based on the at least one category and the recipient information. The scan manager makes the user profile available to a category server for use in creating a scan profile defining the scan criteria and deploys a scan agent to a computer to conduct the scan based on the scan profile. When the scan is complete and upon creation of the scan report, the scan manager makes the scan report available to the intended recipients.