Anonymization Module Selective Data Masking Cloud Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
As more enterprises use third-party hosted applications, there is a need for efficient data security measures to protect data from unauthorized access, particularly in cloud computing environments where data is transmitted and stored across networks.
Innovation Solution
A method and system for anonymizing data transmitted to a destination computing device using an anonymization strategy, which includes an anonymization module that selectively anonymizes data based on predefined strategies, ensuring secure transmission and storage while allowing for searchable and sortable anonymized data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If data is transmitted to third-party hosted applications, then accessibility and functionality are improved, but data security and privacy are worsened
Solution Approach 1:
The patent introduces an intermediary anonymization layer between the client and the third-party hosted application. This intermediary component selectively anonymizes data fields before transmission to the destination computing device, while maintaining the ability to retrieve and de-anonymize data locally. The intermediary thus mediates the data flow, enabling accessibility to third-party services while protecting sensitive information from unauthorized access.
Solution Approach 2:
The patent segments data into different categories based on sensitivity and regulatory requirements. Different anonymization strategies are applied to different data fields (e.g., full anonymization for PII, partial anonymization for semi-sensitive data, no anonymization for non-sensitive data). This segmentation allows selective protection while maintaining functionality for non-sensitive data.
2Object-affected harmful factors
If selective anonymization is applied to data, then data security is improved, but data processing complexity is worsened
Solution Approach 1:
The patent defines and stores anonymization strategies in advance before data transmission occurs. These pre-configured strategies specify which data fields require anonymization and what anonymization method to apply. By preparing the anonymization rules beforehand, the actual data processing during transmission becomes simpler and more automated, reducing the complexity burden during execution.
Solution Approach 2:
The patent changes the parameters of data fields (such as masking, tokenization, or encryption) based on predefined anonymization strategies. By transforming data parameters according to stored strategy rules, the system achieves security without requiring complex real-time decision-making during data transmission.
3Object-affected harmful factors
If data is anonymized before transmission, then data privacy is improved, but data usability for analysis is worsened
Solution Approach 1:
The patent applies different levels of anonymization to different data fields based on their sensitivity and usability requirements. Sensitive fields like Social Security Numbers receive full anonymization, while less sensitive fields maintain higher usability. This local quality approach preserves data usability for analysis in fields where it is needed while protecting privacy where critical.
Solution Approach 2:
The patent creates anonymized copies of data for transmission to third-party services, while maintaining the ability to retrieve and de-anonymize the data locally for analysis purposes. The anonymized data serves as a copy that protects privacy during transmission but can be transformed back to its original form for legitimate analysis needs.
Data Source
AI summary
A method and system for anonymizing data to be transmitted to a destination computing device is disclosed. An anonymization strategy module is executed on a computing device to store anonymization strategy for data anonymization in a data store. A logic configured to receive data from a user computer, to be stored in the destination computing device. An anonymization module is executed on the computing device to selectively anonymize data to be stored in the destination computing device, based on the anonymization strategy for the data to be stored. Anonymized data is transmitted to the destination computing device for storage, over a network.


