Dynamic Application Encryption via Data Classification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems fail to effectively protect sensitive data across various states (at rest, in transit, and in memory) due to centralized data processing and storage, which increases the risk of data compromise and unauthorized access.
Innovation Solution
A dynamic application-level encryption system that receives data classification rules, identifies appropriate protection options, and applies encryption using store-specific or session keys, ensuring secure data access and management through a taxonomy-based classification and policy engine.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If centralized data processing and storage is implemented, then data accessibility and processing efficiency are improved, but data security and risk of unauthorized access deteriorate
Solution Approach 1:
The patent segments data into different classification categories (e.g., public, internal, confidential, restricted) and applies different encryption keys and access controls to each segment. This allows centralized storage while maintaining security through granular control, resolving the contradiction between data accessibility and security.
Solution Approach 2:
The patent implements local quality by applying different protection levels and encryption methods to different data segments based on their classification. Sensitive data receives stronger protection while less sensitive data has easier access, allowing efficient processing of overall data while securing critical information.
2Reliability
If data is encrypted with multiple keys and classification rules applied, then data security is improved, but system complexity and processing overhead increase
Solution Approach 1:
The patent performs preliminary data classification and key assignment during data ingestion or initial processing. Classification rules are pre-configured and encryption keys are pre-assigned to data categories, so that subsequent access operations only require simple key retrieval rather than complex real-time decision-making, reducing operational complexity.
Solution Approach 2:
The patent introduces a data classification service as an intermediary layer between the application and the encrypted data store. This service handles classification rules, key management, and access decisions centrally, simplifying the interface for applications while providing robust multi-key encryption and classification enforcement.
3Reliability
If granular data encryption is applied to protect sensitive information, then unauthorized access is prevented, but data retrieval and processing speed decrease
Solution Approach 1:
The patent performs preliminary classification and key assignment during data ingestion or initial processing. Classification rules are pre-configured and encryption keys are pre-assigned to data categories, so that subsequent access operations only require simple key retrieval rather than complex real-time decision-making, reducing operational complexity.
Solution Approach 2:
The patent introduces a data classification service as an intermediary layer between the application and the encrypted data store. This service handles classification rules, key management, and access decisions centrally, simplifying the interface for applications while providing robust multi-key encryption and classification enforcement.
Data Source
AI summary
Systems and methods for dynamic application level encryption are disclosed. In one embodiment, in an information processing apparatus comprising at least one computer processor, a method for dynamic application level encryption include: (1) receiving a plurality of data classification rules; (2) classifying data using the data classification rules; (3) identifying at least one protection option of a plurality of protection options for protecting the data in at least a rest state, an in-transit state, and an in-memory state; and (4) applying the at least one protection option to the data at rest.


