Automated Sensitive Data Discovery and Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Corporate computer networks face challenges in managing and protecting sensitive data due to inconsistencies in database implementations and lack of adherence to privacy protocols, leading to fragmentation and unauthorized access across large networks.

Innovation Solution

A computer-implemented method and system that scans networks to discover and identify databases and files containing sensitive data, applies protection policies using machine learning to determine data criteria, and implements cybersecurity measures to protect sensitive information according to industry standards.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If databases are created by different departments with little adherence to privacy protocols, then database creation flexibility is improved, but data security and compliance deteriorate

Engineering Contradiction:
Improvedatabase creation flexibilityVSAvoiddata security and compliance
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system performs preliminary scanning and classification of databases to identify sensitive data before protection policies are applied. This advance detection allows automatic policy provisioning without disrupting departmental database creation flexibility, resolving the contradiction between flexibility and security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system automatically scans, classifies, and applies protection policies to databases without requiring manual intervention from database administrators or department users. This self-service approach maintains operational flexibility while ensuring consistent security compliance across all departmental databases.

Inventive Principle:
Principle #25Self-service

2Reliability

If automatic scanning and policy application is implemented across the network, then data protection is improved, but system complexity and processing time worsen

Engineering Contradiction:
Improvedata protectionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system changes the parameters of database files by adding metadata tags and attributes that classify sensitivity levels. This parameter modification approach enables automatic policy application based on detected data characteristics, improving protection while keeping the scanning mechanism relatively simple and efficient.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent replaces manual database auditing and policy application mechanisms with an automated computer-implemented system. This substitution reduces the need for complex human-driven processes and simplifies the overall system architecture while enhancing data protection capabilities.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Measurement precision

If comprehensive database scanning is performed to identify sensitive data, then detection accuracy is improved, but processing time and computational resources worsen

Engineering Contradiction:
Improvesensitive data detection accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system applies different scanning depths and classification criteria to different database regions based on their sensitivity characteristics. By focusing detailed analysis only on potentially sensitive data portions rather than uniformly scanning entire databases, the system achieves high detection accuracy while reducing overall processing time and resource consumption.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11593514B2System and method for the discovery and protection of sensitive data
Publication Date: 2023.02.28 DATASPARC INC
  • US11593514B2 patent drawing
  • US11593514B2 patent drawing
  • US11593514B2 patent drawing

AI summary

A computer-implemented method, implemented by one or more computers including hardware and software. The method includes determining whether a computer system contains data subject to a protection policy; in response to a determination that the computer system contains data or information subject to said protection policy, determining whether the data is already subject to protection according to said protection policy; and in response to said determining, that the computer system contains data or information that is not already subject to protection according to said protection policy, applying or implementing the protection policy on the data or information.