Data Obfuscation Framework for Sensitive Content Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing user productivity applications face challenges in identifying and protecting sensitive data within structured user data files, such as spreadsheets and presentations, where sensitive information is often split across multiple data entities, making it difficult to prevent data loss and misappropriation.

Innovation Solution

A data loss protection framework that classifies sensitive content using a classification service, annotates it in the user interface, and provides obfuscation options to mask the sensitive data, maintaining the data scheme while rendering it unidentifiable, utilizing a shared service across multiple applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If sensitive data is identified and protected in structured user data files, then data loss prevention is improved, but detection difficulty increases due to sensitive data being split across multiple data entities

Engineering Contradiction:
Improvedata loss preventionVSAvoidsensitive data detection
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent divides the sensitive data detection and protection process into separate functional modules: a classification service that identifies sensitive content, an annotation component that marks detected sensitive data, and an obfuscation module that masks the sensitive information. This segmentation allows each component to specialize in one aspect of the problem, improving overall detection capability despite the distributed nature of sensitive data across multiple entities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a classification service as an intermediary between the user application and the data protection mechanisms. This service receives user content, classifies portions as sensitive or non-sensitive, and provides indications to the application. The intermediary handles the complexity of detecting split sensitive data, shielding the user application from this difficulty while maintaining reliable detection.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If user content is processed to classify sensitive portions, then sensitive data identification is improved, but processing time increases

Engineering Contradiction:
Improvesensitive content classificationVSAvoidcontent processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The classification service processes user content to identify sensitive portions, but the system allows for selective application of obfuscation based on user choices and sensitivity levels. Not all sensitive data requires the same level of processing or protection, allowing the system to balance classification precision with processing time by applying full classification only where necessary.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system performs classification of user content before final distribution or publishing. By identifying and marking sensitive portions in advance, the system prepares the data for selective obfuscation only when needed, rather than processing all content uniformly. This preliminary classification improves efficiency by pre-identifying what requires protection.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If obfuscation options are provided in the user interface, then user control over sensitive data is improved, but interface complexity increases

Engineering Contradiction:
Improveuser controlVSAvoiduser interface
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The user interface presents obfuscation options specifically at the locations where sensitive data is detected and annotated, rather than providing global controls for all data. Each sensitive portion can have its own obfuscation controls, allowing users to manage sensitivity locally where needed while keeping the rest of the interface simple and uncluttered.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system automatically classifies and annotates sensitive content, then presents targeted obfuscation options to the user only for the detected sensitive portions. The user application itself performs the classification and preparation work, serving the user by automatically identifying what needs protection and presenting relevant controls, rather than requiring the user to manually configure protection for all data.

Inventive Principle:
Principle #25Self-service

4Reliability

If sensitive data is replaced with obfuscated content, then data protection is improved, but data utility is reduced

Engineering Contradiction:
Improvedata protectionVSAvoiddata utility
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The obfuscation process changes the parameters of the sensitive data by replacing actual values with masked or pseudonymized versions that maintain the data scheme and format. This allows the obfuscated data to retain structural utility for analysis and processing while the sensitive information parameters are transformed to prevent identification and misappropriation.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

Instead of destroying or completely removing sensitive data, the system creates obfuscated copies that maintain the data scheme and structural properties. These copies preserve the utility needed for analysis, reporting, and processing while the sensitive information is replaced with placeholder values that cannot be used for identification or misappropriation.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11182490B2Obfuscation of user content in user data files
Publication Date: 2021.11.23 MICROSOFT TECHNOLOGY LICENSING LLC
  • US11182490B2 patent drawing
  • US11182490B2 patent drawing
  • US11182490B2 patent drawing

AI summary

Systems, methods, and software for data obfuscation frameworks for user applications are provided herein. An exemplary method includes providing user content to a classification service configured to process the user content to classify portions of the user content as comprising sensitive content, and receiving from the classification service indications of the user content that contains the sensitive content. The method includes presenting graphical indications in a user interface to the user application that annotate the user content as containing the sensitive content, and presenting obfuscation options in the user interface for masking the sensitive content within at least a selected portion among the user content. Responsive to a user selection of at least one of the obfuscation options, the method includes replacing associated user content with obfuscated content that maintains a data scheme of the associated user content.