Sensitive Data Retirement via Integrated Discovery and Anonymization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional data security systems are inadequate for comprehensive discovery, anonymization, monitoring, and retirement of sensitive data across various data sources and applications, leading to inefficiencies and incomplete security due to lack of integration and ineffective metadata sharing.

Innovation Solution

An integrated system and method that integrates sensitive data discovery with data retirement, using a platform with a sensitive data discovery engine, data anonymization engine, and data retirement engine to identify, anonymize, and retire sensitive data across multiple data sources, while sharing metadata for downstream security operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional data security systems are used for sensitive data discovery and retirement, then basic data protection can be achieved, but comprehensive security coverage and integration across multiple data sources are insufficient

Engineering Contradiction:
Improvedata security coverageVSAvoidsystem integration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple previously separate data security functions (discovery, anonymization, monitoring, and retirement engines) into a single integrated platform. This merging enables comprehensive security coverage across relational and non-relational data sources while managing complexity through unified architecture and shared metadata repositories.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The integrated data security platform is designed to perform multiple functions across diverse data sources including relational databases, NoSQL databases, data lakes, and cloud storage. The system provides universal security operations (discovery, anonymization, monitoring, retirement) that can be applied consistently across different data types and storage technologies.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Measurement precision

If manual methods are used to identify and manage sensitive data locations, then detailed control can be achieved, but enormous human effort and time are required

Engineering Contradiction:
Improvesensitive data location accuracyVSAvoiddata discovery time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system enables automated self-service data discovery where the discovery engine automatically scans, identifies, and catalogs sensitive data across multiple data sources without requiring manual intervention. The system autonomously performs pattern matching, dictionary-based identification, and data classification, significantly reducing both time and human effort while maintaining high precision through multiple detection methods.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The discovery engine performs preliminary identification and cataloging of sensitive data locations before security operations are applied. By pre-mapping sensitive data across the enterprise infrastructure and storing this information in metadata repositories, the system prepares the groundwork for subsequent anonymization, monitoring, and retirement operations, eliminating the need for repeated manual searches.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If sensitive data is retired without comprehensive discovery and anonymization, then retirement speed can be increased, but security risks and compliance violations increase

Engineering Contradiction:
Improvedata retirement speedVSAvoidsecurity compliance
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system performs preliminary discovery, classification, and anonymization of sensitive data before retirement operations are executed. The discovery engine identifies all sensitive data locations in advance, the anonymization engine applies appropriate masking or tokenization, and only then is the data retired. This preliminary processing ensures security compliance is maintained throughout the retirement process while enabling efficient bulk operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The monitoring component continuously tracks sensitive data throughout its lifecycle and provides feedback to the retirement engine about data locations, access patterns, and compliance status. This feedback mechanism ensures that retirement operations are performed on the correct data with appropriate security measures applied, maintaining reliability and compliance while enabling automated high-speed retirement processes.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11227068B2System and method for sensitive data retirement
Publication Date: 2022.01.18 MENTIS INC
  • US11227068B2 patent drawing
  • US11227068B2 patent drawing
  • US11227068B2 patent drawing

AI summary

A system including a data retirement engine (DRE) and a method are provided for retiring sensitive data. The DRE receives a sensitive data map generated by a sensitive data discovery engine (SDDE) integrated to the DRE. The sensitive data map includes locations of sensitive data of different data types in multiple data stores. The DRE generates tokens for operational data from the sensitive data map based on selectable data classifications using one or more tokenizers that desensitize the sensitive data, while retaining transactional data. The DRE determines candidates from the operational data in an entirety of a target data store for the tokenization based on rules adjustably configured based on predetermined criteria. The DRE tokenizes the candidates using the tokens on the target data store and facilitates detokenization using a soft delete mode and deletion of the tokens using a hard delete mode.