Federated Search with Encrypted PII Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Organizations face challenges in using public cloud-based solutions due to complex data privacy and security regulations, such as HIPAA and European data protection laws, which restrict the movement of personally identifiable information across borders, and concerns about law enforcement access to cloud data.
Innovation Solution
Implementing data obfuscation methods like encryption and tokenization to protect sensitive data, allowing it to be stored and used in the cloud while maintaining security and privacy, using a PRS server to intercept and encrypt or tokenize data before it leaves the enterprise infrastructure, and using a PRS server to manage access and authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If data is stored in public cloud infrastructure, then cost-effective cloud-based solutions and accessibility are improved, but data security, privacy compliance, and control over personally identifiable information deteriorate due to regulations like HIPAA and European data protection laws
Solution Approach 1:
The patent segments data into personally identifiable information (PII) and non-PII components. PII is extracted and stored separately in encrypted form in the cloud, while non-PII data can be freely accessed. This segmentation allows organizations to leverage cloud benefits while maintaining compliance with data protection regulations.
Solution Approach 2:
The patent extracts PII from datasets and stores it separately in an encrypted manner in the cloud, removing it from the main data processing environment. This extraction enables cloud-based processing of non-sensitive data while keeping sensitive information secure and compliant.
2Reliability
If data is obfuscated using encryption or tokenization, then data security and privacy are improved, but the ability to perform searches and analytics on the data deteriorates
Solution Approach 1:
The patent applies different quality treatments to different portions of data. PII fields are encrypted while non-PII fields remain in plaintext or less restricted formats. This local quality approach allows search and analytics on non-sensitive data while maintaining security on sensitive information.
Solution Approach 2:
The patent applies partial encryption only to PII portions of data rather than encrypting entire datasets. This partial action maintains security where needed while preserving full searchability and analytics capability on non-sensitive data portions.
3Reliability
If tokenization is used to replace sensitive data with tokens, then data security is improved, but the complexity of managing token references and vault systems increases
Solution Approach 1:
The patent extracts and encrypts only the PII portions of data, eliminating the need for complex tokenization vaults and reference databases. By directly encrypting sensitive fields rather than replacing them with tokens, the system reduces infrastructure complexity while maintaining security.
Data Source
AI summary
Systems and methods are provided for federated search. Search results can be federated across cloud-based data stores having data accessible to applications hosted in the cloud and private data stores protected by a data security provider that manages communications between a private network and the cloud. A search query invoked by a client of a cloud-based application can be partitioned into search criteria applicable to the cloud-based data stores and search criteria applicable to the private data store. The cloud-based application can perform a search using the search criteria applicable to the cloud-based data stores and use results of a search against the private data store to federate the results.


