Sensitive Data Access Tracking with Graph-Based Audit Histories

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The rapid generation and storage of sensitive data, such as PII, PHI, and financial information, make it difficult to track data locations, access, and unauthorized access, complicating data protection and response to customer requests.

Innovation Solution

A data access tracking system using a graph database to store and track sensitive data identifiers, linking them to user operations, enabling efficient generation of access tracking reports through a classification engine and query engine.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If data volume increases to meet growing storage needs, then storage capacity is improved, but data tracking difficulty increases

Engineering Contradiction:
Improvedata storage capacityVSAvoiddata tracking difficulty
Core Design Contradiction:
Quantity of substanceVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces an intermediary tracking system that sits between the data storage infrastructure and users. This tracking system captures data access events, stores metadata about data locations and access patterns, and provides query capabilities without requiring direct modification of the underlying storage system. The intermediary layer enables tracking of sensitive data across large volumes by mediating between storage operations and monitoring requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If comprehensive data tracking is implemented to improve security monitoring, then data protection capability is improved, but system complexity increases

Engineering Contradiction:
Improvedata protection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the data tracking system into distinct functional modules: a tracking service that captures access events, a metadata storage component that organizes tracking information, and a query interface that retrieves tracking data. Each module performs a specific function, reducing overall system complexity by breaking down the monolithic tracking concept into manageable, independent components that can be developed and maintained separately.

Inventive Principle:
Principle #1Segmentation

3Loss of information

If detailed access history is recorded for all data operations, then audit capability is improved, but storage overhead increases

Engineering Contradiction:
Improveaudit capabilityVSAvoidstorage overhead
Core Design Contradiction:
Loss of informationVSQuantity of substance

Solution Approach 1:

The patent applies local quality by selectively tracking only sensitive data rather than all data uniformly. The system identifies sensitive data through classification and applies tracking metadata only to those specific data elements. This selective approach provides comprehensive audit capability for sensitive information while avoiding the storage overhead of tracking every data operation across the entire system.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12361006B1Data access tracking service
Publication Date: 2025.07.15 AMAZON TECH INC
  • US12361006B1 patent drawing
  • US12361006B1 patent drawing
  • US12361006B1 patent drawing

AI summary

Systems and techniques are described for tracking and providing access reports for individual pieces of data managed by a data storage service. A service may generate and store a record of operations performed on a piece of data, such that may be classified as containing sensitive or important data, in a data store. The record may link representations of users and the operations performed by those users to instances of the piece of data, as it is found in one or more data objects within the data store. The data store may link other instances of the piece of data and other operations performed on the piece of data to the first instance of the piece of data. The service may access the data store to produce a history record of the various instances of the piece of data and operations performed on those instances of the piece of data.