Storage Management System for Sensitive Data Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In unsecured or partially secured primary storage environments, especially in educational institutions like universities, there is a lack of control over sensitive data stored by unsophisticated users, leading to potential data breaches and leaks due to the storage of sensitive information without encryption.
Innovation Solution
A backup or storage management system that automatically analyzes data for sensitive information and secures it by modifying its storage within the primary storage environment, reducing the risk of data breaches and leaks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If users are granted unrestricted access to the primary storage environment to maintain ease of operation, then ease of operation is improved, but data security deteriorates due to unsophisticated users storing sensitive information without encryption
Solution Approach 1:
The patent introduces an intermediary component (storage management system or agent) that sits between users and the primary storage environment. This intermediary automatically analyzes stored data, identifies sensitive information using patterns or machine learning, and applies encryption without requiring user action. This resolves the contradiction by maintaining user freedom of access while introducing a protective layer that ensures data security.
Solution Approach 2:
The system implements self-service by automatically detecting sensitive data and applying encryption measures without requiring user intervention. The storage management system autonomously monitors the storage environment, identifies sensitive information based on predefined criteria or machine learning models, and applies appropriate encryption. This allows unsophisticated users to maintain easy access while the system independently ensures data security.
2Reliability
If automatic analysis and encryption of sensitive data is implemented to improve data security, then data security is improved, but device complexity increases due to the need for automated analysis systems
Solution Approach 1:
The patent extracts the complex functionality of sensitive data detection and encryption from the core storage system and implements it as a separate, modular storage management system or agent. This extracted component can be independently developed, maintained, and updated without affecting the primary storage environment. By separating these functions, the system achieves enhanced security while managing complexity through modular design.
Solution Approach 2:
The system manages complexity by changing parameters such as using predefined sensitivity patterns for initial detection, implementing configurable encryption levels based on data type, and adjusting analysis thresholds. These parameter changes allow the system to adapt to different security requirements without fundamentally redesigning the architecture, thereby controlling complexity while maintaining security effectiveness.
3Reliability
If encryption is applied to sensitive data to reduce data breaches, then data security is improved, but productivity decreases due to additional processing overhead
Solution Approach 1:
The patent applies preliminary action by encrypting sensitive data at the time of storage rather than when it is accessed. The storage management system identifies and encrypts sensitive information as it is written to the primary storage environment, so that the encrypted form is already in place when retrieval occurs. This preliminary encryption minimizes the performance impact during data retrieval operations while still providing security.
Solution Approach 2:
The system applies local quality by selectively encrypting only the portions of data that are identified as sensitive, rather than encrypting entire storage volumes or all data uniformly. This selective approach encrypts only the necessary data elements (specific files, data blocks, or records containing sensitive information) while leaving other data in plaintext form, thereby maintaining storage and retrieval efficiency for non-sensitive data while providing security for sensitive portions.
Data Source
AI summary
A backup or storage management system is provided that can secure data within a primary storage environment that stores data in an unsecured format. The storage management system can automatically analyze data received for backup from the primary storage environment and determine whether the data includes information that has been identified as sensitive and/or information that is determined within a threshold degree of probability to be sensitive. The storage management system can then modify the storage of the data that includes sensitive information at the primary storage environment, thereby enabling the data to be secured within the unsecured, or partially secured, primary storage environment. Advantageously, in certain embodiments, by securing data with sensitive information within an unsecured storage environment, embodiments disclosed herein can reduce the occurrences of a data breach or data leak.


