Data Masking System with Granular Expression Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for protecting sensitive data in secure storage environments are inadequate in minimizing modern data management risks and associated costs, as they fail to provide precise and controlled data flow and presentation, leading to increased organizational costs in data breach mitigation and notification efforts.

Innovation Solution

A system and method for controlling the expression of data from a sensitive data storage device by using a data mask indicator to apply a limited expression format, allowing authorized access while logging user activity and providing alerts for abnormal access patterns, thereby protecting sensitive information from unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional permission-based access protocols are used to protect secure data, then data access control is provided, but precise and controlled data flow and presentation cannot be achieved, leading to increased organizational costs in data breach mitigation and notification efforts

Engineering Contradiction:
Improvedata securityVSAvoiddata flow control precision
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments data into different expression levels (full expression, partial expression, masked expression) based on sensitivity. Each data field can be independently controlled with specific expression formats, allowing precise control over what portions of data are visible to users versus what remains protected. This segmentation enables granular data flow control without requiring complete access restrictions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different expression formats to different data fields based on their specific sensitivity requirements. Each data field can have its own mask indicator and expression level, allowing localized control quality rather than uniform restriction across all data. This enables precise data flow control where only necessary portions are exposed while maintaining overall security.

Inventive Principle:
Principle #3Local quality

2Productivity

If data is fully accessible to authorized users, then operational efficiency is improved, but the risk of unauthorized access and data breaches increases

Engineering Contradiction:
Improvedata access efficiencyVSAvoiddata breach risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent implements partial expression where users receive exactly the amount of data expression they need for their operational tasks, rather than providing full access. This partial action principle allows users to work efficiently with sufficient data while automatically limiting exposure to only what is necessary, thereby reducing breach risk without compromising productivity.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent introduces an intermediary expression control mechanism that sits between the data storage and user access points. This intermediary applies expression formats and mask indicators to transform raw data into controlled presentations, allowing users to access data efficiently while the intermediary filters and protects against excessive exposure that could lead to breaches.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If comprehensive logging and monitoring of user activity is implemented, then data breach detection capability is improved, but system complexity and processing overhead increase

Engineering Contradiction:
Improveuser activity tracking accuracyVSAvoidlogging system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent implements preliminary logging where mask indicators and expression levels are predetermined and associated with data fields before user access occurs. This preliminary action captures essential monitoring information in advance, allowing accurate tracking of what data was accessed and at what expression level without requiring complex real-time analysis during user interactions.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent incorporates feedback mechanisms where user interactions with expressed data are automatically logged and monitored. The system provides feedback by recording which users accessed which data fields at which expression levels, enabling precise breach detection while using straightforward logging processes that avoid excessive system complexity.

Inventive Principle:
Principle #23Feedback

4Reliability

If data is masked and expression is limited, then data protection is improved, but data utility and accessibility for legitimate purposes may be reduced

Engineering Contradiction:
Improvedata protectionVSAvoiddata accessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements dynamic expression control where data accessibility adjusts based on user credentials, task requirements, and context. Users can access data at appropriate expression levels without manual unmasking, and the system dynamically determines what level of expression is suitable for each access scenario. This maintains protection while ensuring legitimate accessibility without excessive restriction.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent creates a universal expression control system that handles multiple data types and access scenarios through a single framework. The same expression formats and mask indicators work across different data fields and user types, providing consistent protection while maintaining accessibility through standardized controls rather than complex case-by-case management.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10380368B1Data field masking and logging system and method
Publication Date: 2019.08.13 STATE FARM MUTAL AUTOMOBILE INSURANCE COMPANY
  • US10380368B1 patent drawing
  • US10380368B1 patent drawing
  • US10380368B1 patent drawing

AI summary

A computer-implemented method for controlling the expression of a block of data from a sensitive data storage device, the method including the steps of receiving from a software application a request to transfer the block of data from the source sensitive data storage device for expression at a destination device, determining a data mask indicator for the block of data, applying a limited expression format based upon the data mask indicator, and expressing the block of data at the destination device in the limited expression format, such as to facilitate protecting or masking sensitive data. The method may further include allowing a user to request revelation of a masked portion of the block of data, recording in a memory log user activity relating to such revelation request(s) of the user, and providing regular reports and/or administrative alerts relating to such logged user activity.