Diagnostic Data Control via Dual Encryption and Selective Redaction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Diagnostic data dissemination in data processing systems poses a risk due to sensitive information that can be exploited by malicious parties, necessitating secure access controls to prevent data compromise.

Innovation Solution

Implementing dual encryption and selective redaction of diagnostic data packages, where sensitive information is encrypted with two sets of encryption data, one controlled by the operator and the other by the requestor, and selectively redacting data based on sensitivity levels to limit access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If diagnostic data is disseminated to vendors and third parties for system improvement, then system performance and reliability can be enhanced through feedback, but sensitive information may be exposed to malicious parties causing security risks

Engineering Contradiction:
Improvesystem reliabilityVSAvoiddata security risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments diagnostic data into multiple categories (encrypted data, redacted data, unencrypted data) based on sensitivity levels. Different portions of diagnostic data are treated differently - highly sensitive data is encrypted, moderately sensitive data is redacted, and non-sensitive data is provided in plain text. This segmentation allows the system to share necessary diagnostic information with vendors while protecting sensitive information from exposure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies encryption and redaction measures to diagnostic data before dissemination to vendors and third parties. By performing these protective actions in advance (prior to data sharing), the system ensures that sensitive information is already protected when the data is transmitted outside the organization, thereby preventing potential security risks while still enabling system improvement through feedback.

Inventive Principle:
Principle #10Preliminary action

2Object-affected harmful factors

If encryption is applied to protect sensitive diagnostic data, then data security is improved, but access control complexity and processing overhead increase

Engineering Contradiction:
Improvedata securityVSAvoidaccess control complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent applies different levels of protection (encryption, redaction, or no protection) to different portions of diagnostic data based on their sensitivity levels. Rather than uniformly encrypting all diagnostic data, the system selectively applies encryption only to highly sensitive portions, while using redaction for moderately sensitive data and providing unencrypted access to non-sensitive data. This local quality approach reduces overall complexity while maintaining necessary security.

Inventive Principle:
Principle #3Local quality

3Object-affected harmful factors

If sensitive information is redacted from diagnostic data packages, then data security risk is reduced, but diagnostic value and usefulness of the data may be diminished

Engineering Contradiction:
Improvedata security riskVSAvoiddiagnostic information loss
Core Design Contradiction:
Object-affected harmful factorsVSLoss of information

Solution Approach 1:

The patent applies redaction selectively to specific sensitive fields within diagnostic data packages while preserving non-sensitive diagnostic information. By identifying and redacting only the portions of data that pose security risks (such as personally identifiable information or proprietary algorithms) while leaving the rest of the diagnostic data intact, the system maintains both security and diagnostic value.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements partial redaction rather than complete redaction of sensitive fields. Instead of removing entire diagnostic records or fields, the system redacts only the specific sensitive portions within those fields, allowing vendors to still obtain sufficient diagnostic information to identify and resolve issues while minimizing information loss.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12197611B2System and method for securing diagnostic data collection using data control
Publication Date: 2025.01.14 DELL PROD LP
  • US12197611B2 patent drawing
  • US12197611B2 patent drawing
  • US12197611B2 patent drawing

AI summary

Methods and systems for managing the operation of data processing systems are disclosed. To manage the operation of data processing systems, diagnostic data may be collected. The diagnostic data may include information regarding the operation of the data processing systems usable to diagnose issues impacting the operation of the data processing systems. The diagnostic data may also include sensitive data that may be undesirable to disclose to third parties. To manage risk associated with distribution of the diagnostic data, the diagnostic data may be subjected to partial redaction and/or dual encryption to manage access to the sensitive data included therein. By redacting and/or dual encrypting portions of the sensitive data, access to the sensitive data after the diagnostic data is distributed may be prevented and/or limited to those parties to which an operator of a data processing system elects to provide decryption data.