Centralized API for Sensitive Data Conversion
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The lack of synchronization in data conversion across different APIs for sensitive data from various repositories leads to errors in testing and analysis environments, and existing methods fail to maintain meaningful intelligence in fictional data, compromising security and usability.
Innovation Solution
A centralized API is introduced to retrieve data from multiple repositories, determine file types, and execute appropriate conversion algorithms to convert sensitive data into secure, fictional data strings while maintaining indicative characters, ensuring uniformity and accuracy across all data sets.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If each database uses a different API to mask sensitive data, then data security is maintained through individual conversion, but data synchronization is lost and numerous errors occur in testing environments
Solution Approach 1:
The patent merges multiple individual API conversion processes into a single centralized conversion service. This service receives data from multiple databases and applies unified masking rules, ensuring that sensitive data is converted consistently across all data repositories while maintaining security. The centralized approach eliminates the synchronization errors that occurred when each database used different conversion APIs.
Solution Approach 2:
The centralized conversion service performs multiple functions: it handles data masking for different file types (CSV, JSON, XML), manages multiple data repositories, and provides a universal conversion interface. This multi-functional service replaces the need for separate conversion APIs for each database, ensuring consistent data transformation across the entire system.
2Reliability
If all sensitive data is replaced with fictional data to secure the internal network, then security is improved, but the data loses meaning and testing/analysis services are disabled
Solution Approach 1:
The patent applies different masking strategies to different portions of data based on their sensitivity and importance. Critical sensitive data is fully masked or replaced with fictional values, while less sensitive data or data requiring analytical value retains some of its original characteristics. This local differentiation allows the system to maintain security for the most sensitive information while preserving data meaning and usefulness for testing and analysis purposes.
3Manufacturing precision
If a centralized API is implemented to synchronize data conversion, then data synchronization and accuracy are improved, but system complexity increases
Solution Approach 1:
The centralized conversion service acts as an intermediary between multiple data repositories and the external systems that need the data. Instead of each database having its own conversion logic, all data flows through this single intermediary service that applies unified masking rules. This mediator approach simplifies the overall system architecture by consolidating conversion logic in one place while maintaining data synchronization across all repositories.
Data Source
AI summary
A method for converting data via a centralized application programming interface (“API”) is provided. The method may include retrieving data files from two or more data repositories and transmitting the data files to the centralized API. For each of the data files, the method may include selecting a conversion application and executing the conversion application to convert the data files into secure data files. The executing may include converting sensitive data strings into fictional data strings. Each of the sensitive data strings may include a first sub-set of characters and a second sub-set of characters. The converting may include, for each of the sensitive data strings, replacing the first sub-set of characters with a third sub-set of characters and maintaining the second sub-set of characters. Following the converting, the method may include transmitting the secure data files to an external network.


