Sensitive Data Signatures for Fast, Accurate Secret Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security mechanisms struggle to efficiently and effectively identify, locate, and manage sensitive data within large data streams, determine authorized deployment scope, and facilitate testing without exposing actual sensitive data.

Innovation Solution

Implementing a contiguous sensitive data identification data structure (SDIDS) with predefined primary and secondary adherence signatures, embedded metadata, and correlation identifiers to enhance security functioning by reducing false positives and enabling efficient scanning and governance of sensitive data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If traditional security mechanisms are used to scan large data streams for sensitive data, then the scanning process becomes slow and inefficient, but using more comprehensive detection methods increases false positive rates

Engineering Contradiction:
Improvescanning speedVSAvoiddetection accuracy
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The patent divides the detection task into multiple stages by segmenting the data stream into records and analyzing them in batches. The sensitive data identification data structure (SDIDS) is processed in discrete units, allowing efficient scanning while maintaining accuracy through structured analysis of each segment.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary data structure (the SDIDS with adherence signatures) that mediates between the raw data stream and the detection process. This intermediary structure enables efficient pattern matching while filtering out false positives through the hierarchy of adherence signatures.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If comprehensive security checks are implemented to detect all vulnerabilities, then detection coverage improves, but system complexity and cost increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments security checks into distinct layers: primary adherence signature detection, secondary adherence signature verification, and contextual analysis. This segmentation allows comprehensive security coverage while managing complexity through structured, modular checks that can be implemented progressively.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs preliminary actions by pre-defining adherence signatures and creating the SDIDS structure before actual data processing. This preliminary setup enables comprehensive security coverage through pre-established detection criteria while reducing runtime complexity through optimized search patterns.

Inventive Principle:
Principle #10Preliminary action

3Speed

If sensitive data is scanned in real-time to prevent exposure, then security responsiveness improves, but computational resources are consumed

Engineering Contradiction:
Improveresponse timeVSAvoidcomputational resources
Core Design Contradiction:
SpeedVSUse of energy by moving object

Solution Approach 1:

The patent performs preliminary actions by pre-compiling adherence signatures and pre-structuring the SDIDS format before data processing. This allows real-time scanning with minimal computational overhead during actual data flow, as the detection logic is optimized and pre-prepared.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses adherence signatures as copies or representations of sensitive data patterns that can be efficiently matched without processing the actual sensitive data. This copying approach enables real-time detection while reducing computational resource consumption by working with simplified signature patterns rather than full data records.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS20260080081A1Sensitive data detection
Publication Date: 2026.03.19 MICROSOFT TECHNOLOGY LICENSING LLC
  • US20260080081A1 patent drawing
  • US20260080081A1 patent drawing
  • US20260080081A1 patent drawing

AI summary

Some embodiments form a sensitive data identification data structure (SDIDS) which includes an identifiable sensitive data (ISD) portion. Some embodiments scan for an SDIDS, and some do both. The SDIDS is distinguished by at least one of: specified rarity of an adherence signature, absence of a checksum, primary and secondary adherence signatures, non-prefix adherence signature position, non-suffix checksum position, or particular kinds of metadata. Some examples of suitable metadata include timestamp metadata, deployment metadata, origination metadata, ownership metadata, metadata for testing, correlation metadata, and combinations thereof. Some ISD examples include security keys, tokens, passwords, pass phrases, cryptologic artifacts, confidential data, private data, critical data, and data that is tagged or labeled as sensitive.