Sensitivity Scanning Agent for Distributed Data Stores

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Distributed computer networks face challenges in protecting sensitive information due to the risk of misclassification and exposure when using a single scanning tool across disparate data stores connected through non-private networks.

Innovation Solution

A method is provided to monitor file systems within distributed networks by detecting new data stores and determining their location. If a data store is in a foreign hosting environment, an agent of the native scanning tool is created within that environment to obtain sensitivity information without exposing the data to non-private networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a single scanning tool is used to evaluate data sensitivity across disparate data stores, then comprehensive coverage of all data stores is improved, but the risk of data exposure to third parties increases

Engineering Contradiction:
Improvecomprehensive coverageVSAvoiddata exposure risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The scanning system is segmented into multiple distributed scanning tools, each deployed within specific hosting environments (cloud or on-premise). Each scanning tool independently scans data stores within its own environment, eliminating the need to send data through non-private networks while maintaining comprehensive coverage across all environments.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A central coordination system acts as an intermediary that manages the distributed scanning tools. This coordinator receives scan results from multiple scanning tools and aggregates the sensitivity information, enabling comprehensive data coverage without requiring data to traverse non-private networks.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If data is sent through wide area networks to a single scanning tool, then centralized processing is simplified, but the risk of pilfering by third parties increases

Engineering Contradiction:
Improveprocessing simplicityVSAvoidpilfering risk
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The centralized scanning process is segmented into distributed scanning operations. Each scanning tool operates independently within its hosting environment, processing data locally without transmitting it through non-private networks. This maintains processing functionality while eliminating the exposure risk associated with network transmission.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Instead of sending actual data through networks for processing, the system creates copies of scanning tools in each hosting environment. These local copies perform the scanning function directly on the data, eliminating the need to transmit sensitive information across non-private networks while maintaining processing capability.

Inventive Principle:
Principle #26Copying

3Reliability

If access control measures are deployed to protect sensitive information, then authorized access is limited, but misclassification and location errors in data stores remain

Engineering Contradiction:
Improveaccess protectionVSAvoidsensitivity detection accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The distributed scanning tools autonomously scan data stores within their respective hosting environments and automatically classify sensitivity levels. This self-service approach complements access control measures by providing independent verification of data sensitivity, helping to identify misclassified or improperly located sensitive information without requiring manual intervention.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The scanning system provides feedback about actual data sensitivity locations and classifications back to the organization. This feedback mechanism enables continuous improvement of access control policies by identifying gaps between intended and actual data protection, allowing for more precise sensitivity detection and classification over time.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20250138863A1Sensitivity scanning in distinct hosting environments
Publication Date: 2025.05.01 ROYAL BANK OF CANADA
  • US20250138863A1 patent drawing
  • US20250138863A1 patent drawing
  • US20250138863A1 patent drawing

AI summary

A method for monitoring a file system within a distributed network is provided. From a local hosting environment having a native scanning tool, creation of a new data store within the network is detected. Responsive to detecting creation of the new data store, it is determined whether the new data store is physically located within a foreign hosting environment that is communicatively coupled to the local hosting environment through a non-private network. If the new data store is physically located within the foreign hosting environment, an agent of the native scanning tool is created within the foreign hosting environment and the agent is applied to the new data store within the foreign hosting environment to obtain sensitivity information for the new data store. The sensitivity information for the new data store is received and recorded in the local hosting environment.