Time-Limited Key Encryption for Data Retention Compliance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Online service providers face challenges in protecting sensitive user data from unauthorized disclosure and ensuring compliance with diverse regulatory requirements across jurisdictions, as well as managing data retention policies when multiple business units collaborate in data collection and sharing.

Innovation Solution

A data protector system that uses a key manager to generate time-limited encryption keys, allowing data consumers to access and decrypt sensitive data within a defined retention period, after which the keys are erased, ensuring data protection and compliance with retention policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If sensitive data is transferred to multiple databases for collaboration between business units, then data sharing and collaboration efficiency are improved, but data security and compliance control deteriorate

Engineering Contradiction:
Improvecollaboration efficiencyVSAvoiddata security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments sensitive data into multiple distributed databases across different business units and jurisdictions. Each database contains portions of the data, and no single database holds the complete sensitive information, thereby reducing security risks while enabling collaboration.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a data loss prevention (DLP) system as an intermediary layer between distributed databases. This mediator monitors, controls, and enforces data access policies across all databases, ensuring compliance with retention policies and security requirements while allowing legitimate collaboration.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Duration of action of moving object

If data retention periods are extended to meet business objectives, then business utility of data is improved, but regulatory compliance risk increases

Engineering Contradiction:
Improvedata retention periodVSAvoidregulatory compliance risk
Core Design Contradiction:
Duration of action of moving objectVSObject-affected harmful factors

Solution Approach 1:

The patent implements dynamic retention periods for distributed data, where the retention duration can vary by jurisdiction, data type, and regulatory requirements. The system automatically adjusts retention policies to balance business needs with compliance obligations in different regions.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The DLP system continuously monitors data retention status across distributed databases and provides feedback to enforce compliance. When retention periods expire or compliance requirements change, the system automatically triggers data deletion or anonymization processes to maintain regulatory adherence.

Inventive Principle:
Principle #23Feedback

3Reliability

If encryption keys are stored permanently to ensure data accessibility, then data access reliability is improved, but data protection against unauthorized access deteriorates

Engineering Contradiction:
Improvedata access reliabilityVSAvoidunauthorized access risk
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent implements time-limited encryption keys that automatically expire after a defined retention period. The key management system rotates and invalidates encryption keys according to retention policies, ensuring that even if keys are compromised, the window for unauthorized access is limited. This parameter change from permanent to temporary key validity resolves the contradiction between accessibility and security.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10237060B2Media agnostic, distributed, and defendable data retention
Publication Date: 2019.03.19 MICROSOFT TECHNOLOGY LICENSING LLC
  • US10237060B2 patent drawing
  • US10237060B2 patent drawing
  • US10237060B2 patent drawing

AI summary

A data protector is described. In an implementation, the data protector promotes and enforces a data retention policy of a data consumer. In an implementation, the data protector limits access to sensitive data to the data consumers. A key manager provides a time-limited encryption key to the data protector. Responsive to collection of the time-limited encryption key from the key manager and sensitive data from a data provider, the data protector encrypts the sensitive data with the time-limited encryption key effective to produce encrypted sensitive data. In some embodiments, the data protector provides a data consumer with access to the encrypted sensitive data and the key manager provides the data consumer with access to the time-limited encryption key to decrypt the encrypted sensitive data. The key manager deletes the time-limited encryption key in compliance with the data retention policy of the data consumer.