Data Masking Proxy for Secure Database Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional cryptographic techniques fail to effectively protect data after decryption and are costly and cumbersome to implement, especially in ensuring total communication security and compliance with privacy laws across national borders, leading to potential unauthorized data disclosure.
Innovation Solution
A data masking system comprising a data masking proxy, configuration wizard, policy store, masking algorithm engine, and report server that de-personalizes data on-the-fly, using static or dynamic masking techniques to ensure secure data access and compliance with various privacy regulations, applicable to various clients and environments.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If cryptographic techniques are used to protect data in transit, then data privacy is improved, but data protection after decryption fails and key management becomes tedious
Solution Approach 1:
The patent segments data protection into multiple layers: cryptographic protection for data in transit and masking for data at rest. This segmentation allows each technique to address specific stages of data handling, avoiding the limitation of relying solely on cryptography for all protection needs.
Solution Approach 2:
The patent introduces masking as an intermediary layer between decrypted data and applications. This intermediary ensures that even when data is decrypted for processing, the actual sensitive values remain protected through masking, eliminating the need for complex key management while maintaining privacy.
2Reliability
If total communication security is implemented, then data protection is improved, but cost increases and implementation becomes cumbersome
Solution Approach 1:
The patent applies partial action by implementing masking only for specific sensitive columns and tables that require protection, rather than applying total communication security to all data. This selective approach reduces implementation complexity and cost while maintaining adequate protection for critical data.
Solution Approach 2:
The patent changes the protection parameter from binary (encrypted/not encrypted) to a spectrum of masking techniques including static masking, dynamic masking, and template masking. This allows organizations to adjust the level of protection based on specific needs, reducing overall implementation burden.
3Ease of operation
If data is decrypted for application access, then data usability is improved, but unauthorized disclosure risk increases
Solution Approach 1:
The patent introduces a masking intermediary that sits between the data decryption layer and application access layer. This intermediary maintains masked versions of sensitive data that applications can use for processing without exposing actual values, thus enabling data usability while preventing unauthorized disclosure.
Solution Approach 2:
The patent creates masked copies of sensitive data that can be used by applications instead of the actual decrypted data. These copies preserve the structure and format needed for processing while containing no real sensitive information, eliminating the risk of unauthorized disclosure.
Data Source
AI summary
An approach is provided for masking data. A determination is made whether an action initiated by an authenticated user corresponds to one of a plurality of policies stored in a policy store, wherein the policies relate to whether data to be retrieved from a data source is to be masked. A new policy is generated if no match is found in the policy store. Information associated with the new policy is received, wherein the information is input by the user. The new policy is stored in the policy store.


