Anonymization Module for Secure Data Transmission
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
As more enterprises use third-party hosted applications, there is a need for efficient data security measures to protect data from unauthorized access, especially considering regulatory requirements and the need to anonymize data transmitted and de-anonymize data retrieved from destination computing devices.
Innovation Solution
A method and system for anonymizing data using an anonymization module with a data encryption key, where the data is encrypted and decrypted as needed, allowing for secure transmission and retrieval, involving tokenization and symmetric key encryption techniques to maintain data security and integrity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If data is transmitted in plain text to third-party hosted applications, then data transmission is simple and fast, but data security and protection from unauthorized access deteriorates
Solution Approach 1:
The patent introduces an anonymization module as an intermediary component between the client and third-party hosted application. This module encrypts data before transmission and decrypts it upon retrieval, acting as a security mediator that allows data to travel through networks while maintaining protection. The anonymization module handles the encryption/decryption operations transparently, enabling secure transmission without requiring changes to the underlying application architecture.
Solution Approach 2:
The patent changes the parameter of data representation from plain text to encrypted/anonymized form. By transforming the data format through encryption algorithms, the system maintains transmission efficiency while fundamentally altering the security characteristics. The anonymization process modifies data parameters (encoding, encryption keys, data structure) to ensure that data appears scrambled and unreadable to unauthorized parties during transmission and storage.
2Reliability
If data is anonymized using encryption, then data security and protection from unauthorized access is improved, but data processing complexity and system complexity increases
Solution Approach 1:
The anonymization module implements self-service functionality by automatically handling encryption and decryption operations without requiring manual intervention. The system manages its own security operations through integrated encryption/decryption mechanisms that operate transparently in the background. The module self-manages key operations and data transformation, reducing the need for complex external security infrastructure.
Solution Approach 2:
The anonymization module is designed as a universal component that can be integrated into various client applications and communicates with different third-party hosted applications. It provides multi-functional capabilities including encryption, decryption, anonymization, and de-anonymization within a single integrated module. This universal design reduces overall system complexity by consolidating security functions rather than requiring separate security components for each operation.
3Reliability
If data is encrypted and anonymized, then data protection during transmission is improved, but data retrieval and processing efficiency deteriorates
Solution Approach 1:
The system performs preliminary encryption actions when data is first transmitted to the third-party application, and maintains the encrypted state in the database. When retrieval is needed, the decryption process is prepared and executed efficiently. By pre-establishing encryption mechanisms and maintaining consistent encryption states, the system avoids repeated encryption/decryption operations during normal read access, thereby maintaining retrieval efficiency while preserving protection.
Solution Approach 2:
The anonymization module handles decryption operations automatically and transparently during data retrieval, eliminating the need for manual decryption processes. The system self-manages the decryption workflow, managing keys and authentication automatically. This self-service approach ensures that decryption occurs efficiently in the background without adding noticeable overhead to the data retrieval process, maintaining productivity while ensuring data protection.
Data Source
AI summary
A method and system for anonymizing data to be transmitted to a destination computing device is disclosed. Anonymization strategy for data anonymization is provided. Data to be transmitted is received from a user computer. Selective anonymization of the data is performed, based on the anonymization strategy, using an anonymization module. The data is anonymized using the anonymization module, to derive an anonymized data, using a data encryption key. The anonymized data is transmitted to the destination computer over a network. In some embodiments, the data encryption key is encrypted and decrypted prior to anonymization.


