Coordinated Data Obfuscation for PII Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional data sanitization techniques fail to maintain the logical relationships between Personally Identifiable Information (PII) across network devices, leading to inadequate security and ineffective network analytics when PII is exposed to bad actors.

Innovation Solution

Implementing coordinated data obfuscation through obfuscation logic on network devices and analysis logic on analysis servers, using obfuscation parameters like salt and network address transformation ranges to maintain logical relationships while securing PII, allowing for secure data analysis without direct access to raw PII.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Object-affected harmful factors

If conventional data sanitization techniques are used, then data security is improved, but the logical relationships between PII across network devices are lost

Engineering Contradiction:
Improvedata securityVSAvoidlogical relationships between PII
Core Design Contradiction:
Object-affected harmful factorsVSLoss of information

Solution Approach 1:

The patent introduces an intermediary obfuscation layer that transforms PII while preserving relationships. Each network device applies a locally stored obfuscation parameter (salt) to transform its PII, creating an intermediary representation that maintains logical relationships while obscuring actual values from unauthorized access.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the parameter representation by applying different obfuscation parameters (salts) to PII values. The same PII can be obfuscated differently at each device using device-specific salts, yet the transformed values maintain consistent logical relationships across the network, resolving the contradiction between security and relationship preservation.

Inventive Principle:
Principle #35Parameter changes

2Productivity

If PII is exposed for network analytics, then analytics capabilities are improved, but security against bad actors deteriorates

Engineering Contradiction:
Improvenetwork analytics capabilitiesVSAvoidexposure to bad actors
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary obfuscation action at the network devices before data is transmitted to analysis servers. The obfuscation parameters are applied in advance to transform PII into a secure format that can be analyzed without exposing raw values, enabling analytics while preventing bad actor access.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates a copy of the PII data in an obfuscated form for analysis purposes. The analysis server receives and processes copies of the obfuscated PII rather than the original raw data, enabling analytical capabilities while the original secure PII remains protected from bad actors.

Inventive Principle:
Principle #26Copying

3Object-affected harmful factors

If independent obfuscation is applied at each network device, then data security is improved, but coordination between devices deteriorates

Engineering Contradiction:
Improvedata securityVSAvoidcoordination between devices
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent applies local quality by giving each network device its own obfuscation parameter (salt) stored in local memory. Each device independently transforms its local PII using its own salt, simplifying the coordination mechanism while maintaining security. The consistency across devices is achieved through the shared obfuscation framework rather than complex coordination protocols.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11729149B2Coordinated data obfuscation
Publication Date: 2023.08.15 CISCO TECHNOLOGY INC
  • US11729149B2 patent drawing
  • US11729149B2 patent drawing
  • US11729149B2 patent drawing

AI summary

Techniques are provided herein for coordinated data obfuscation. In one example, a first network device in a network obtains, from a controller in or having communication to the network, an obfuscation parameter that is further obtained by one or more second network devices in the network. Personally Identifiable Information (PII) of the first network device has a given logical relationship to PII of the one or more second network devices. Based on the obfuscation parameter, the first network device obfuscates the PII of the first network device to generate obfuscated PII of the first network device. The obfuscated PII of the first network device has the given logical relationship to obfuscated PII of the one or more second network devices. The first network device provides the obfuscated PII of the first network device to a server configured to collect the obfuscated PII of the one or more second network devices.