Dynamic Application Encryption via Data Classification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems fail to effectively protect sensitive data across various states (at rest, in transit, and in memory) due to centralized data processing and storage, which increases the risk of data compromise and unauthorized access.

Innovation Solution

A dynamic application-level encryption system that receives data classification rules, identifies appropriate protection options, and applies encryption using store-specific or session keys, ensuring secure data access and management through a taxonomy-based classification and policy engine.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If centralized data processing and storage is implemented, then data accessibility and processing efficiency are improved, but data security and risk of unauthorized access deteriorate

Engineering Contradiction:
Improvedata processing efficiencyVSAvoiddata security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments data into different classification categories (e.g., public, internal, confidential, restricted) and applies different encryption keys and access controls to each segment. This allows centralized storage while maintaining security through granular control, resolving the contradiction between data accessibility and security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by applying different protection levels and encryption methods to different data segments based on their classification. Sensitive data receives stronger protection while less sensitive data has easier access, allowing efficient processing of overall data while securing critical information.

Inventive Principle:
Principle #3Local quality

2Reliability

If data is encrypted with multiple keys and classification rules applied, then data security is improved, but system complexity and processing overhead increase

Engineering Contradiction:
Improvedata protection levelVSAvoidencryption system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent performs preliminary data classification and key assignment during data ingestion or initial processing. Classification rules are pre-configured and encryption keys are pre-assigned to data categories, so that subsequent access operations only require simple key retrieval rather than complex real-time decision-making, reducing operational complexity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a data classification service as an intermediary layer between the application and the encrypted data store. This service handles classification rules, key management, and access decisions centrally, simplifying the interface for applications while providing robust multi-key encryption and classification enforcement.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If granular data encryption is applied to protect sensitive information, then unauthorized access is prevented, but data retrieval and processing speed decrease

Engineering Contradiction:
Improveunauthorized access preventionVSAvoiddata retrieval speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent performs preliminary classification and key assignment during data ingestion or initial processing. Classification rules are pre-configured and encryption keys are pre-assigned to data categories, so that subsequent access operations only require simple key retrieval rather than complex real-time decision-making, reducing operational complexity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a data classification service as an intermediary layer between the application and the encrypted data store. This service handles classification rules, key management, and access decisions centrally, simplifying the interface for applications while providing robust multi-key encryption and classification enforcement.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11032320B1Systems and methods for dynamic application level encryption
Publication Date: 2021.06.08 JPMORGAN CHASE BANK NA
  • US11032320B1 patent drawing
  • US11032320B1 patent drawing
  • US11032320B1 patent drawing

AI summary

Systems and methods for dynamic application level encryption are disclosed. In one embodiment, in an information processing apparatus comprising at least one computer processor, a method for dynamic application level encryption include: (1) receiving a plurality of data classification rules; (2) classifying data using the data classification rules; (3) identifying at least one protection option of a plurality of protection options for protecting the data in at least a rest state, an in-transit state, and an in-memory state; and (4) applying the at least one protection option to the data at rest.