Field-Level Data Encryption for Secure External Analytics

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data loss prevention solutions rely on observing data movement and detecting sensitive data after it has been transferred, failing to prevent data compromise and often inadvertently blocking legitimate data exports for analytics.

Innovation Solution

A system and method that encrypts sensitive data using the Advanced Encryption Standard (AES) before export, ensuring secure transmission over insecure channels, while allowing analysis through secure multi-party computation protocols, ensuring privacy and usability of the encrypted data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If data is exported to external entities for analysis, then data utility and analytics capability are improved, but data security and control are worsened

Engineering Contradiction:
Improvedata analytics capabilityVSAvoiddata security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system performs preliminary encryption of sensitive data fields before the data leaves the enterprise environment. This advance protection ensures that even if data is intercepted during export or analysis, the sensitive information remains protected. The encryption is applied selectively to specific sensitive fields while allowing non-sensitive data to remain accessible for analytics.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary data protection system that sits between the enterprise data source and external analytics entities. This intermediary layer encrypts sensitive data fields using field-level encryption, allowing external systems to receive and analyze data without having direct access to the original sensitive information. The intermediary maintains data utility for analytics while protecting security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If conventional data loss prevention products observe and detect sensitive data export, then data exfiltration detection is improved, but data transmission time and analytics capability are worsened

Engineering Contradiction:
Improvedata exfiltration detection accuracyVSAvoiddata transmission time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

Instead of detecting data exfiltration after it occurs, the system performs preliminary encryption of sensitive fields before data export. This eliminates the need for post-transfer detection and blocking, as the data is already protected during transmission. Analytics can proceed immediately on the encrypted or masked data without waiting for detection cycles.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system extracts only the necessary non-sensitive portions of data for external analytics while keeping sensitive fields encrypted or masked. This selective data extraction allows external systems to perform analytics on relevant data without requiring access to the complete sensitive dataset, reducing transmission time and enabling faster analytics while maintaining security.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If sensitive data is blocked from being transferred, then data security is improved, but legitimate data export for analytics is worsened

Engineering Contradiction:
Improvedata securityVSAvoiddata export capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system applies different quality treatments to different fields within the same dataset. Sensitive fields are encrypted or masked with high security protection, while non-sensitive fields remain in plain text or less protected states. This field-level differentiation allows analytics to proceed on non-sensitive data without blocking, while sensitive data receives appropriate security protection.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

An intermediary system processes data before export, applying selective encryption only to sensitive fields while leaving non-sensitive fields accessible. This intermediary layer enables legitimate data export for analytics by allowing external systems to receive and process non-sensitive data, while sensitive data is automatically protected through the intermediary's field-level encryption mechanism.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11424909B1System and method for protecting data that is exported to an external entity
Publication Date: 2022.08.23 BAFFLE INC
  • US11424909B1 patent drawing
  • US11424909B1 patent drawing

AI summary

A system and method secures data including sensitive data parts for exporting and securely analyzes the secure exported data. In one embodiment, the secure data may be analyzed using at least two compute elements. In one embodiment, the system may use the AES process to secure the sensitive parts of the data.