Data Management Service for Sensitive Data Source Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Identifying and protecting sensitive data within large computer networks is challenging due to the computational intensity of frequent scans and the complexity of managing multiple databases, especially when not all sensitive data records are of equal importance and when external databases are involved, leading to potential oversight of high-risk databases.

Innovation Solution

A data management service that classifies sensitive data using record classification rules, determines assessment scores for enterprise databases, and applies protection policies to sensitive data records, allowing administrators to target protection efforts effectively by grouping databases with common attributes and applying policies to source databases to secure dependent databases as well.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If frequent scans are used to identify sensitive data locations, then the accuracy of sensitive data knowledge is improved, but the computational intensity increases excessively

Engineering Contradiction:
Improveaccuracy of sensitive data knowledgeVSAvoidcomputational intensity
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent segments the database scanning process by classifying databases into groups based on sensitivity levels and protection policies. Instead of scanning all databases uniformly, the system divides them into segments (e.g., high-risk, medium-risk, low-risk groups) and applies different scanning frequencies and depths to each segment, reducing overall computational intensity while maintaining accuracy for critical databases.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system applies local quality by tailoring the scanning intensity and frequency to specific databases based on their sensitivity classification. High-risk databases receive more frequent and thorough scans, while low-risk databases receive less intensive monitoring. This ensures measurement precision is optimized locally for each database type rather than applying a uniform high-intensity scan across all databases.

Inventive Principle:
Principle #3Local quality

2Quantity of substance

If every database is examined without prioritization, then comprehensive coverage is achieved, but critical high-risk databases may be missed due to time constraints

Engineering Contradiction:
Improvecomprehensive coverageVSAvoidtime for examination
Core Design Contradiction:
Quantity of substanceVSLoss of time

Solution Approach 1:

The system performs preliminary classification of databases into risk groups and sensitivity levels before conducting detailed examinations. By预先 (in advance) categorizing databases based on their protection policies and sensitivity attributes, the system prepares a prioritized examination schedule that ensures critical databases are examined first, maintaining comprehensive coverage while optimizing time utilization.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms where examination results and risk assessments are continuously updated. Databases that show signs of increased risk or newly identified sensitive data automatically receive higher priority in subsequent examination cycles. This feedback loop ensures that time is dynamically allocated to databases that most need attention, maintaining comprehensive coverage adaptively.

Inventive Principle:
Principle #23Feedback

3Reliability

If protection policies are applied to all copies of sensitive data records, then complete protection is achieved, but it becomes impractical when external databases are involved and administrators cannot directly apply policies

Engineering Contradiction:
Improvecomplete protectionVSAvoidpracticality of policy application
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces an intermediary mechanism where the data classification and protection system acts as a mediator between internal databases and external databases. The system identifies sensitive data in internal databases and automatically generates and transmits protection policies to external databases through automated interfaces or APIs. This intermediary approach enables complete protection without requiring direct manual intervention for each external database connection.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements self-service by automatically detecting sensitive data, classifying it according to protection policies, and applying appropriate protection measures without requiring manual administrator intervention for each database. The automated classification and policy application mechanisms enable the system to serve itself in managing protection across multiple databases, including external ones, maintaining complete protection while improving ease of operation.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP2942731B1Identifying and securing sensitive data at its source
Publication Date: 2019.09.25 INFORMATICA CORP
  • EP2942731B1 patent drawingFigure 1A
  • EP2942731B1 patent drawingFigure 1B
  • EP2942731B1 patent drawingFigure 2A~2C

AI summary

A data management service identifies sensitive data stored on enterprise databases according to record classification rules that classify a data record as having a sensitive data type if the data record includes fields matching at least one of the record classification rules. The data management service determines assessment scores for enterprise databases according to sensitive data records and protection policies on the enterprise databases. The data management service provides an interface that groups enterprise databases having common attributes or common sensitive data types and indicates aggregated assessment scores for the groups of enterprise databases. Through the interface with the grouped enterprise databases, an administrator apply protection policies to enterprise databases. To apply the protection policy, the data management service applies the protection policy to a source database from which dependent enterprise databases access the sensitive database.