Homomorphic Encryption for Secure Data Masking in Testing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional systems face risks of data exposure and compromisation when transferring unencrypted production data from a production environment to lower environments for testing, due to weak security and privacy controls, which can also compromise production keys.
Innovation Solution
Implementing a homomorphic encryption model that maintains, decrypts, encrypts, and masks data using cryptographic and homomorphic encryption functions to generate alternate ciphertext data, which is then decrypted and stored in a lower environment, ensuring that only masked cleartext data is exposed, thus protecting production data and keys.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If unencrypted production data is transferred to lower environments for testing, then testing and development can be performed, but data exposure and security compromise occur
Solution Approach 1:
The patent introduces homomorphic encryption as an intermediary mechanism that allows the lower environment to process encrypted production data without exposing cleartext. The encrypted data acts as a mediator between the production environment (which needs security) and the lower environment (which needs data for testing), enabling testing while maintaining security boundaries.
Solution Approach 2:
The patent changes the encryption parameter from standard encryption (which requires decryption to process) to homomorphic encryption (which allows processing in encrypted form). This parameter change in the encryption approach enables the lower environment to work with production data without compromising security.
2Loss of information
If production data is accessed in lower environments, then data utility for testing is improved, but security controls are compromised
Solution Approach 1:
Homomorphic encryption serves as an intermediary that preserves data utility for testing while maintaining security controls. The encrypted data structure allows meaningful processing and analysis in the lower environment without exposing sensitive information, thus maintaining reliability of security controls.
Solution Approach 2:
The patent creates a cryptographic copy of the production data that maintains the necessary structure and relationships for testing purposes while being mathematically transformed to prevent exposure of original sensitive information. This copying approach preserves data utility without compromising security.
3Ease of manufacture
If conventional encryption is used, then data is protected at rest, but data must be decrypted for processing which creates exposure risk
Solution Approach 1:
The patent fundamentally changes the encryption parameter from conventional encryption (which requires decryption for processing) to homomorphic encryption (which enables processing in encrypted form). This parameter change eliminates the need to decrypt data for processing, thus removing the exposure risk while maintaining ease of protection.
Solution Approach 2:
The patent substitutes the mechanical decryption-processing- reencryption workflow with a mathematical homomorphic encryption system that allows direct processing of encrypted data. This substitution eliminates the vulnerable decryption step while maintaining data protection throughout the processing lifecycle.
Data Source
AI summary
Systems and methods utilized to protect data. One method includes maintaining, by a first processing circuit in a production database of a production environment system, ciphertext data associated with a cryptographic function, wherein the production environment system corresponds to a first access level. The method further includes masking, by a second processing circuit in a middle environment system, the ciphertext data using a masking function to generate alternate ciphertext data, wherein the middle environment system is a proxy and communicably coupled with the production environment system over a secure network. The method further includes decrypting, by the second processing circuit in the middle environment system, the alternate ciphertext data utilizing a symmetric key to generate masked cleartext data, and storing, by the second processing circuit in a lower environment system, the masked cleartext data in a lower database, wherein the lower environment system correspond to a second access level.


