Context-Aware Sensitive Data Obfuscation System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprises face challenges in protecting sensitive data while allowing authorized access, as individuals may accidentally share personal information, leading to non-compliance with regulations like GDPR, which can result in fines, and there is a need for a system that obfuscates personal data based on both regulatory and contextual requirements.

Innovation Solution

A method and system that uses computer processors to detect sensitive data, retrieve applicable regulations, determine obfuscation locations, and apply context rules to obfuscate data on computing devices, providing informed consent and secure processing of personal data through a distributed data processing environment with an obfuscation program, user context database, and regulations database.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If sensitive data is obfuscated based on regulations, then data protection and compliance are improved, but data accessibility and usability for authorized operations deteriorate

Engineering Contradiction:
Improvedata protection complianceVSAvoiddata accessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system dynamically adjusts obfuscation levels based on contextual factors including user identity, device type, location, and operation type. Authorized users can access unobfuscated data when context rules permit, while default obfuscation protects data from unauthorized access. This dynamic approach resolves the contradiction by making data accessibility conditional rather than static.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

Different obfuscation rules are applied to different portions of data based on local context. The system identifies specific sensitive data elements and applies selective obfuscation rather than uniform obfuscation across all data. This allows authorized operations to access necessary unobfuscated portions while protected portions remain obfuscated, resolving the contradiction between protection and accessibility.

Inventive Principle:
Principle #3Local quality

2Reliability

If comprehensive regulation-based obfuscation is applied, then data security is improved, but system complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary analysis of user context, device characteristics, and operation types before applying obfuscation rules. By pre-evaluating contextual factors and determining appropriate obfuscation levels in advance, the system avoids complex real-time decision-making during data access operations, thereby reducing overall system complexity while maintaining comprehensive security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system introduces context rules as an intermediary layer between regulations and actual obfuscation application. Context rules translate complex regulatory requirements into actionable decision criteria that consider user identity, device type, location, and operation type. This intermediary simplifies the implementation complexity by providing a structured framework for applying diverse regulations.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If data is displayed without obfuscation, then data usability for authorized operations is improved, but risk of accidental sharing and non-compliance increases

Engineering Contradiction:
Improveoperational efficiencyVSAvoidaccidental data sharing risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system continuously monitors operational context and user actions, providing feedback that dynamically adjusts obfuscation levels. When the system detects conditions that increase accidental sharing risk (such as unauthorized device usage or suspicious operational patterns), it automatically increases obfuscation. This feedback mechanism maintains high productivity for authorized operations while dynamically mitigating accidental sharing risks.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system applies preliminary obfuscation protection to data before it can be accidentally shared, while still allowing authorized operations to access unobfuscated data through contextual authorization. By establishing protective obfuscation in advance and only removing it when context rules confirm authorized usage, the system prevents accidental sharing while maintaining operational efficiency for legitimate purposes.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS11308236B2Managing obfuscation of regulated sensitive data
Publication Date: 2022.04.19 KYNDRYL INC
  • US11308236B2 patent drawing
  • US11308236B2 patent drawing
  • US11308236B2 patent drawing

AI summary

In an approach to managing obfuscation of regulated sensitive data, one or more computer processors detect content for display on a computing device. One or more computer processors analyze the content for sensitive data. One or more computer processors retrieve one or more applicable regulations, where the regulations are associated with displaying sensitive data. One or more computer processors determine a location on the display for obfuscating the sensitive data in the content, based on the retrieved one or more applicable regulations. One or more computer processors identify one or more context rules applicable to the sensitive data in the content. One or more computer processors determine the one or more context rules override the one or more applicable regulations. One or more computer processors display the sensitive data in the content.