Data Masking System with Granular Expression Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional methods for protecting sensitive data in secure storage environments are inadequate in minimizing modern data management risks and associated costs, as they fail to provide precise and controlled data flow and presentation, leading to increased organizational costs in data breach mitigation and notification efforts.
Innovation Solution
A system and method for controlling the expression of data from a sensitive data storage device by using a data mask indicator to apply a limited expression format, allowing authorized access while logging user activity and providing alerts for abnormal access patterns, thereby protecting sensitive information from unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional permission-based access protocols are used to protect secure data, then data access control is provided, but precise and controlled data flow and presentation cannot be achieved, leading to increased organizational costs in data breach mitigation and notification efforts
Solution Approach 1:
The patent segments data into different expression levels (full expression, partial expression, masked expression) based on sensitivity. Each data field can be independently controlled with specific expression formats, allowing precise control over what portions of data are visible to users versus what remains protected. This segmentation enables granular data flow control without requiring complete access restrictions.
Solution Approach 2:
The patent applies different expression formats to different data fields based on their specific sensitivity requirements. Each data field can have its own mask indicator and expression level, allowing localized control quality rather than uniform restriction across all data. This enables precise data flow control where only necessary portions are exposed while maintaining overall security.
2Productivity
If data is fully accessible to authorized users, then operational efficiency is improved, but the risk of unauthorized access and data breaches increases
Solution Approach 1:
The patent implements partial expression where users receive exactly the amount of data expression they need for their operational tasks, rather than providing full access. This partial action principle allows users to work efficiently with sufficient data while automatically limiting exposure to only what is necessary, thereby reducing breach risk without compromising productivity.
Solution Approach 2:
The patent introduces an intermediary expression control mechanism that sits between the data storage and user access points. This intermediary applies expression formats and mask indicators to transform raw data into controlled presentations, allowing users to access data efficiently while the intermediary filters and protects against excessive exposure that could lead to breaches.
3Measurement precision
If comprehensive logging and monitoring of user activity is implemented, then data breach detection capability is improved, but system complexity and processing overhead increase
Solution Approach 1:
The patent implements preliminary logging where mask indicators and expression levels are predetermined and associated with data fields before user access occurs. This preliminary action captures essential monitoring information in advance, allowing accurate tracking of what data was accessed and at what expression level without requiring complex real-time analysis during user interactions.
Solution Approach 2:
The patent incorporates feedback mechanisms where user interactions with expressed data are automatically logged and monitored. The system provides feedback by recording which users accessed which data fields at which expression levels, enabling precise breach detection while using straightforward logging processes that avoid excessive system complexity.
4Reliability
If data is masked and expression is limited, then data protection is improved, but data utility and accessibility for legitimate purposes may be reduced
Solution Approach 1:
The patent implements dynamic expression control where data accessibility adjusts based on user credentials, task requirements, and context. Users can access data at appropriate expression levels without manual unmasking, and the system dynamically determines what level of expression is suitable for each access scenario. This maintains protection while ensuring legitimate accessibility without excessive restriction.
Solution Approach 2:
The patent creates a universal expression control system that handles multiple data types and access scenarios through a single framework. The same expression formats and mask indicators work across different data fields and user types, providing consistent protection while maintaining accessibility through standardized controls rather than complex case-by-case management.
Data Source
AI summary
A computer-implemented method for controlling the expression of a block of data from a sensitive data storage device, the method including the steps of receiving from a software application a request to transfer the block of data from the source sensitive data storage device for expression at a destination device, determining a data mask indicator for the block of data, applying a limited expression format based upon the data mask indicator, and expressing the block of data at the destination device in the limited expression format, such as to facilitate protecting or masking sensitive data. The method may further include allowing a user to request revelation of a masked portion of the block of data, recording in a memory log user activity relating to such revelation request(s) of the user, and providing regular reports and/or administrative alerts relating to such logged user activity.


