Field-Level Data Encryption for Secure External Analytics
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data loss prevention solutions rely on observing data movement and detecting sensitive data after it has been transferred, failing to prevent data compromise and often inadvertently blocking legitimate data exports for analytics.
Innovation Solution
A system and method that encrypts sensitive data using the Advanced Encryption Standard (AES) before export, ensuring secure transmission over insecure channels, while allowing analysis through secure multi-party computation protocols, ensuring privacy and usability of the encrypted data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If data is exported to external entities for analysis, then data utility and analytics capability are improved, but data security and control are worsened
Solution Approach 1:
The system performs preliminary encryption of sensitive data fields before the data leaves the enterprise environment. This advance protection ensures that even if data is intercepted during export or analysis, the sensitive information remains protected. The encryption is applied selectively to specific sensitive fields while allowing non-sensitive data to remain accessible for analytics.
Solution Approach 2:
The patent introduces an intermediary data protection system that sits between the enterprise data source and external analytics entities. This intermediary layer encrypts sensitive data fields using field-level encryption, allowing external systems to receive and analyze data without having direct access to the original sensitive information. The intermediary maintains data utility for analytics while protecting security.
2Measurement precision
If conventional data loss prevention products observe and detect sensitive data export, then data exfiltration detection is improved, but data transmission time and analytics capability are worsened
Solution Approach 1:
Instead of detecting data exfiltration after it occurs, the system performs preliminary encryption of sensitive fields before data export. This eliminates the need for post-transfer detection and blocking, as the data is already protected during transmission. Analytics can proceed immediately on the encrypted or masked data without waiting for detection cycles.
Solution Approach 2:
The system extracts only the necessary non-sensitive portions of data for external analytics while keeping sensitive fields encrypted or masked. This selective data extraction allows external systems to perform analytics on relevant data without requiring access to the complete sensitive dataset, reducing transmission time and enabling faster analytics while maintaining security.
3Reliability
If sensitive data is blocked from being transferred, then data security is improved, but legitimate data export for analytics is worsened
Solution Approach 1:
The system applies different quality treatments to different fields within the same dataset. Sensitive fields are encrypted or masked with high security protection, while non-sensitive fields remain in plain text or less protected states. This field-level differentiation allows analytics to proceed on non-sensitive data without blocking, while sensitive data receives appropriate security protection.
Solution Approach 2:
An intermediary system processes data before export, applying selective encryption only to sensitive fields while leaving non-sensitive fields accessible. This intermediary layer enables legitimate data export for analytics by allowing external systems to receive and process non-sensitive data, while sensitive data is automatically protected through the intermediary's field-level encryption mechanism.
Data Source
AI summary
A system and method secures data including sensitive data parts for exporting and securely analyzes the secure exported data. In one embodiment, the secure data may be analyzed using at least two compute elements. In one embodiment, the system may use the AES process to secure the sensitive parts of the data.

