Self-removal Data Policy for Sensitive Field Deletion
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users are hesitant to upload sensitive data due to concerns about its storage and security, as existing systems lack mechanisms for guaranteed and controlled deletion of sensitive data items.
Innovation Solution
A system that links sensitive data fields to self-removal data policies with condition sets, allowing automatic deletion of sensitive data items based on time periods, events, or data access, without deleting the entire record or other data fields.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If sensitive data items are stored in online systems, then data processing and service functionality are improved, but security risks and user trust issues worsen due to lack of guaranteed deletion
Solution Approach 1:
The system establishes self-removal data policies with condition sets before sensitive data is uploaded. These pre-configured policies automatically trigger deletion when conditions are met, ensuring data is removed at predetermined times without requiring manual intervention or trusting the system administrator's discretion.
Solution Approach 2:
Sensitive data items are equipped with automatic self-deletion capabilities through associated self-removal policies. The data essentially removes itself when predefined conditions are satisfied, eliminating the need for external control or manual deletion processes and giving users autonomous control over their data lifecycle.
2Reliability
If sensitive data is deleted from the system, then security risks are reduced, but loss of information occurs when entire records are removed
Solution Approach 1:
The system separates sensitive data fields from the rest of the record structure. Self-removal policies are applied specifically to sensitive fields rather than entire records, allowing selective deletion of only the sensitive portions while preserving non-sensitive record data. This segmentation enables precise control over what information is retained and what is removed.
Solution Approach 2:
Different deletion policies are applied to different fields within a record based on their sensitivity characteristics. Sensitive fields have self-removal capabilities while non-sensitive fields maintain standard retention. This local differentiation allows the system to protect sensitive information while preserving valuable non-sensitive record data.
3Ease of operation
If manual deletion processes are used, then control over data retention is achieved, but operational complexity and time consumption increase
Solution Approach 1:
The system implements automatic self-removal mechanisms where sensitive data items autonomously delete themselves when predefined conditions are satisfied. This eliminates the need for manual deletion operations, reducing operational complexity while maintaining user control through the initial policy configuration.
Solution Approach 2:
Deletion conditions and policies are configured in advance before data upload or processing begins. The system automatically monitors and executes deletion when conditions are met, eliminating the need for ongoing manual management and reducing operational burden while maintaining precise control over data retention periods.
4Productivity
If sensitive data is retained for extended periods, then data utility and service capability are improved, but security breach risks and user hesitation worsen
Solution Approach 1:
The system implements dynamic data retention where the lifespan of sensitive data is not fixed but automatically adjusts based on predefined conditions such as time periods, event occurrences, or access patterns. This allows data to be retained as long as needed for service utility while automatically removing it when conditions indicate continued retention is unnecessary or risky.
Solution Approach 2:
The system continuously monitors conditions associated with self-removal policies and automatically triggers deletion when conditions are satisfied. This feedback mechanism ensures data is retained only as long as necessary for service purposes while providing automatic security measures that remove data when predefined safety conditions are met, reducing overall security risks.
Data Source
AI summary
System, method, and/or computer program product embodiments for automatic removal of sensitive data items from records are disclosed. In one or more embodiments, a record with a sensitive field (for storing a sensitive data item) is linked to a self-removal data policy that includes a condition set. When the condition set is true, the sensitive data item is automatically removed from the record without deleting the record and without removing other data items stored in other fields of the record. Conditions may be associated with a time period following the upload or storage of the sensitive date item, the occurrence of an event that requires the sensitive date item, a read or approval of the sensitive data item, etc. A user may modify a condition in the condition set to make the condition more stringent or less stringent.


