Dialog System PII Protection via Audio Classification and Selective Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems face challenges in protecting personally identifying information (PII) during customer interactions in dialog systems, as they need to balance data security with the requirement to log interactions for quality improvement and dispute resolution without exposing sensitive data to third-party hosts.

Innovation Solution

A dialog system that classifies audio data turns and takes security actions such as suppression or encryption based on classification, using a classification module and security action module to protect PII by storing only non-identifying information or encrypting sensitive data, ensuring that PII is not logged or is logged in a protected format.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If audio data is logged for quality improvement and dispute resolution, then data security is compromised, but if audio data is not logged, then quality improvement and dispute resolution capabilities are lost

Engineering Contradiction:
Improvedata securityVSAvoidlogging capability
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system extracts and removes personally identifying information from audio data before logging, keeping only non-identifying portions. This allows the system to maintain logging capabilities for quality improvement and dispute resolution while protecting customer privacy and security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system applies different processing treatments to different portions of the audio data based on its sensitivity. Personally identifying information is suppressed or encrypted, while non-identifying information is logged in plain text, creating local variations in data protection quality throughout the log.

Inventive Principle:
Principle #3Local quality

2Adaptability or versatility

If third-party hosts are used for dialog system services, then system functionality is improved, but customer trust is reduced due to PII exposure risks

Engineering Contradiction:
Improvesystem functionalityVSAvoidcustomer trust risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system introduces an intermediary processing layer that anonymizes audio data before it is stored or accessed by third-party hosts. This intermediary step removes personally identifying information while preserving the functional utility of the dialog data, allowing third-party hosting without compromising customer trust.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary suppression of personally identifying information before the data reaches third-party hosts. By removing PII in advance, the system prevents potential security risks and maintains customer trust while still enabling third-party hosting for system functionality.

Inventive Principle:
Principle #9Preliminary anti-action

3Reliability

If all audio data is encrypted for security, then data security is improved, but processing efficiency and accessibility are reduced

Engineering Contradiction:
Improvedata securityVSAvoidprocessing efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system applies encryption or suppression only to the portion of audio data that contains personally identifying information, rather than encrypting all audio data. This partial action maintains security for sensitive portions while preserving processing efficiency and accessibility for non-sensitive portions.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system applies different security treatments to different portions of the audio data based on sensitivity. Personally identifying information receives encryption or suppression treatment, while non-identifying information remains in plain text for efficient processing and accessibility.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS8990091B2Parsimonious protection of sensitive data in enterprise dialog systems
Publication Date: 2015.03.24 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8990091B2 patent drawing
  • US8990091B2 patent drawing
  • US8990091B2 patent drawing

AI summary

In one embodiment, a method comprises classifying a representation of audio data of a dialog turn in a dialog system to a classification. The method may further comprise taking a security action on the classified representation of the audio data of the dialog turn as a function of the classification. The security action can be suppressing the representation of the audio data, encrypting the representation of the audio data, releasing the representation of the audio data, partially suppressing the representation of the audio data, partially encrypting the representation of the audio data, partially releasing the representation of the audio data, or a command.