Anonymization Engine for Sensitive Data Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data security methods, such as wholesale encryption, are costly, inefficient, and impact system performance, making it difficult to protect sensitive information while allowing for searching, analysis, and efficient use of data, and there is a need for a system that can anonymize sensitive information to prevent unauthorized access and data breaches.

Innovation Solution

Implementing an anonymization engine that identifies and anonymizes sensitive information using privacy rules, transforming it into an identity-free state, allowing for secure data protection and access control, while maintaining data usability and efficiency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If wholesale encryption is applied to protect sensitive information, then data security is improved, but system performance and efficiency deteriorate

Engineering Contradiction:
Improvedata securityVSAvoidsystem performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies selective anonymization rather than wholesale encryption by identifying and anonymizing only specific sensitive fields (e.g., PII, PAI) within data records. This localized approach protects critical information while leaving other data intact, thereby maintaining system performance and efficiency without sacrificing essential security protections.

Inventive Principle:
Principle #3Local quality

2Reliability

If wholesale encryption is applied to protect sensitive information, then data security is improved, but data usability for searching and analysis deteriorates

Engineering Contradiction:
Improvedata securityVSAvoiddata usability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system selectively anonymizes only sensitive portions of data records while preserving the structure and content of non-sensitive fields. This enables data to remain usable for searching, analysis, and aggregation purposes without requiring full decryption, thus maintaining both security and data versatility.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent extracts and anonymizes only the sensitive elements (PII, PAI) from data records, separating them from the rest of the data. This extracted anonymized information prevents unauthorized identification while the remaining data structure stays intact for analytical purposes.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If wholesale encryption is applied to protect sensitive information, then data security is improved, but cost and complexity of key management increase

Engineering Contradiction:
Improvedata securityVSAvoidencryption key management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system extracts and anonymizes only the sensitive fields (PII, PAI) from data records, rather than encrypting entire data sets. This selective approach reduces the volume of data requiring encryption and key management, thereby lowering costs and complexity while maintaining protection for critical information.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10586054B2Privacy firewall
Publication Date: 2020.03.10 VISA INTERNATIONAL SERVICE ASSOCIATION
  • US10586054B2 patent drawing
  • US10586054B2 patent drawing
  • US10586054B2 patent drawing

AI summary

Embodiments of the invention relate to systems and methods for providing an anonymization engine. One embodiment of the present invention relates to a method comprising receiving a message directed at a recipient computer located outside a secure area by a privacy computer located within a secure area. The privacy computer may identify private information using a plurality of privacy rules and anonymize the message according to the plurality of privacy rules. Another embodiment may be directed to a method comprising receiving a request for sensitive data from a requesting computer. An anonymization computer may determine a sensitive data record associated with the request and may anonymize the sensitive data record by performing at least two of: removing unnecessary sensitive data entries from the sensitive data record, masking the sensitive data entries to maintain format, separating the sensitive data entries into associated data groupings, and de-contexting the data.