Database Marking With Artificial Records For Leak Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Companies face challenges in maintaining confidentiality of business-critical data when outsourcing processes to third-party service providers, as they may not be fully trusted or securely administered, and there's a risk of unauthorized data redistribution, especially with easily duplicable data like relational databases.
Innovation Solution
A system that marks databases with artificial records indistinguishable from regular records, allowing detection of unauthorized use by adding payment credentials or addresses traceable by third parties, enabling the database owner to track and respond to leaks, even if multiple copies are distributed.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If databases are distributed to third-party service providers for outsourcing, then business processes can be executed with external partners, but data confidentiality and security cannot be ensured
Solution Approach 1:
The patent applies preliminary action by embedding unique artificial records into database copies before distribution to third-party service providers. These artificial records serve as watermarks that enable later detection of unauthorized redistribution, allowing the data owner to take preventive measures before actual data leakage occurs.
Solution Approach 2:
The patent uses artificial records as an intermediary mechanism between the data owner and third-party service providers. These records act as traceable markers that facilitate monitoring and detection of data misuse without directly interfering with the legitimate outsourcing relationship.
2Measurement precision
If artificial records are added to database copies for leak detection, then unauthorized redistribution can be detected and traced, but the database structure and size increase
Solution Approach 1:
The patent applies local quality by inserting artificial records at specific locations within the database structure rather than uniformly throughout. Each database copy receives artificial records positioned according to its specific identifier, creating localized markers that enable precise tracking without requiring comprehensive modification of the entire database.
Solution Approach 2:
The patent uses copying by creating multiple database copies with identical data but differentiated by unique artificial records. This allows the original data to remain unchanged while the copies serve as traceable distributions, minimizing the impact on the core database structure.
3Adaptability or versatility
If multiple database copies are distributed to different service providers, then business flexibility and service scalability improve, but the ability to detect which specific copy was leaked becomes difficult
Solution Approach 1:
The patent applies segmentation by dividing the database distribution into distinct, traceable segments. Each service provider receives a database copy with unique artificial records that segment the overall distribution into individually identifiable portions, enabling precise identification of which segment (or provider) is responsible for any leakage.
Solution Approach 2:
The patent uses asymmetry by giving each database copy an asymmetric, unique identifier through artificial records. While all copies contain the same functional data, the asymmetric artificial records create distinguishable fingerprints that make it easy to identify the source of any leak among multiple symmetric-looking copies.
Data Source
AI summary
A method comprises receiving a database containing records. The method further comprises determining a number of artificial records to add to the database to achieve a false negative mark detection rate less than a specified threshold. The method also comprises marking the database by adding the determined number of artificial records to the database. Each artificial record contains at least one value that, when used, is detectable by a third party. The false negative rate comprises a probability of failing to detect the mark in a discovered subset of the database.


