Sensitive Data Retirement via Integrated Discovery and Anonymization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional data security systems are inadequate for comprehensive discovery, anonymization, monitoring, and retirement of sensitive data across various data sources and applications, leading to inefficiencies and incomplete security due to lack of integration and ineffective metadata sharing.
Innovation Solution
An integrated system and method that integrates sensitive data discovery with data retirement, using a platform with a sensitive data discovery engine, data anonymization engine, and data retirement engine to identify, anonymize, and retire sensitive data across multiple data sources, while sharing metadata for downstream security operations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional data security systems are used for sensitive data discovery and retirement, then basic data protection can be achieved, but comprehensive security coverage and integration across multiple data sources are insufficient
Solution Approach 1:
The patent combines multiple previously separate data security functions (discovery, anonymization, monitoring, and retirement engines) into a single integrated platform. This merging enables comprehensive security coverage across relational and non-relational data sources while managing complexity through unified architecture and shared metadata repositories.
Solution Approach 2:
The integrated data security platform is designed to perform multiple functions across diverse data sources including relational databases, NoSQL databases, data lakes, and cloud storage. The system provides universal security operations (discovery, anonymization, monitoring, retirement) that can be applied consistently across different data types and storage technologies.
2Measurement precision
If manual methods are used to identify and manage sensitive data locations, then detailed control can be achieved, but enormous human effort and time are required
Solution Approach 1:
The system enables automated self-service data discovery where the discovery engine automatically scans, identifies, and catalogs sensitive data across multiple data sources without requiring manual intervention. The system autonomously performs pattern matching, dictionary-based identification, and data classification, significantly reducing both time and human effort while maintaining high precision through multiple detection methods.
Solution Approach 2:
The discovery engine performs preliminary identification and cataloging of sensitive data locations before security operations are applied. By pre-mapping sensitive data across the enterprise infrastructure and storing this information in metadata repositories, the system prepares the groundwork for subsequent anonymization, monitoring, and retirement operations, eliminating the need for repeated manual searches.
3Productivity
If sensitive data is retired without comprehensive discovery and anonymization, then retirement speed can be increased, but security risks and compliance violations increase
Solution Approach 1:
The system performs preliminary discovery, classification, and anonymization of sensitive data before retirement operations are executed. The discovery engine identifies all sensitive data locations in advance, the anonymization engine applies appropriate masking or tokenization, and only then is the data retired. This preliminary processing ensures security compliance is maintained throughout the retirement process while enabling efficient bulk operations.
Solution Approach 2:
The monitoring component continuously tracks sensitive data throughout its lifecycle and provides feedback to the retirement engine about data locations, access patterns, and compliance status. This feedback mechanism ensures that retirement operations are performed on the correct data with appropriate security measures applied, maintaining reliability and compliance while enabling automated high-speed retirement processes.
Data Source
AI summary
A system including a data retirement engine (DRE) and a method are provided for retiring sensitive data. The DRE receives a sensitive data map generated by a sensitive data discovery engine (SDDE) integrated to the DRE. The sensitive data map includes locations of sensitive data of different data types in multiple data stores. The DRE generates tokens for operational data from the sensitive data map based on selectable data classifications using one or more tokenizers that desensitize the sensitive data, while retaining transactional data. The DRE determines candidates from the operational data in an entirety of a target data store for the tokenization based on rules adjustably configured based on predetermined criteria. The DRE tokenizes the candidates using the tokens on the target data store and facilitates detokenization using a soft delete mode and deletion of the tokens using a hard delete mode.


