Data Sanitization via Directory Table Mapping
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for allowing authorized parties to interact with electronic systems that store restricted data items, such as personal and financial information, often fail to accurately replicate the behavior of production systems, leading to potential data leaks due to unpredicted malfunctions in production environments.
Innovation Solution
A method that sanitizes restricted data items by transferring an original data set to a sanitizer, identifying and modifying the locations of these items using a data directory table, and applying sanitizing tools to preserve the state of the data set, allowing for secure interaction in testing or analysis environments without revealing sensitive information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a mock electronic system is synthesized to resemble the production system, then authorized parties can interact with the system for testing and analysis, but the mock system may not accurately replicate unexpected production system states, leading to potential data leaks
Solution Approach 1:
The patent extracts only the restricted data items from the production system data set and applies sanitization techniques to them, while preserving the rest of the data structure and relationships. This allows the mock system to accurately replicate production system behavior patterns without exposing sensitive information, resolving the contradiction between providing access for testing and ensuring data security through accurate behavioral replication.
Solution Approach 2:
The patent introduces a sanitization layer as an intermediary between the production system data and the mock system. This intermediary component transforms the data by applying sanitization rules to restricted data items while maintaining the overall data structure and statistical characteristics, enabling accurate replication of system behavior without direct exposure of sensitive production data.
2Object-affected harmful factors
If restricted data items are removed or replaced with fake data, then data security is improved, but the ability to perform accurate testing and analysis is reduced
Solution Approach 1:
The patent applies different quality levels to different parts of the data set. Restricted data items are sanitized with high protection (replaced with fake or obfuscated data), while non-restricted data items maintain their original quality and detail. This local differentiation allows accurate testing and analysis to proceed using real data patterns while sensitive information remains protected through selective sanitization.
Solution Approach 2:
The patent changes the quality parameter of restricted data items through sanitization transformations (e.g., masking, pseudonymization, or generation of fake data), while maintaining other parameters such as data structure, relationships, and statistical distributions. This selective parameter change enables both security improvement and preservation of testing accuracy.
3Productivity
If the production system is accessed directly for testing, then complete and accurate testing can be performed, but legal and contractual obligations to maintain secrecy of restricted data items are violated
Solution Approach 1:
The patent creates a copy of the production system data set and applies sanitization to restricted data items in the copy, while preserving the overall structure and data relationships. This copied and sanitized data set can be used for comprehensive testing without violating legal or contractual obligations to maintain secrecy, as the restricted data items have been transformed while retaining the data's functional characteristics for accurate testing.
Data Source
AI summary
Strategies are described for sanitizing a data set, having the effect of obscuring restricted data in the data set to maintain its secrecy. The strategies operate by providing a production data set to a sanitizer. The sanitizer applies a data directory table to identify the location of restricted data items in the data set and to identify the respective sanitization tools to be applied to the restricted data items. The sanitizer then applies the identified sanitization tools to the identified restricted data items to produce a sanitized data set. A test environment receives the sanitized data set and performs testing, data mining, or some other application on the basis of the sanitized data set. Performing sanitization on a sanitized version of the production data set is advantageous because it preserves the state of the production data set. The data directory table also provides a flexible mechanism for applying sanitization tools to the production data set.


