Integrated Logging Library for Sensitive-Data Obfuscation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data masking technologies face challenges in efficiently and securely handling large volumes of sensitive information, including vulnerabilities in centralized architectures and resource-intensive local scanning, leading to unauthorized disclosures and security risks.

Innovation Solution

An integrated logging library is incorporated within a logging framework to obfuscate sensitive information, reducing the need for separate scanning and masking functions, thereby enhancing security and resource efficiency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Extent of automation

If centralized architecture is used for data masking, then coordination of masking operations is improved, but security vulnerabilities increase due to centralized attack targets

Engineering Contradiction:
Improvecoordination of masking operationsVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Extent of automationVSReliability

Solution Approach 1:

The system segments the centralized data masking architecture into distributed masking functions across multiple logging libraries and components. Each logging library independently performs masking operations locally, eliminating the single point of failure and reducing security vulnerabilities associated with centralized architectures while maintaining coordinated masking through standardized patterns and guidelines.

Inventive Principle:
Principle #1Segmentation

2Reliability

If local scanning and masking is performed, then security control is improved, but resource consumption increases

Engineering Contradiction:
Improvesecurity controlVSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system applies partial action by implementing masking only for identified sensitive data patterns rather than scanning and masking all data. Logging libraries use predefined sensitive data patterns to selectively mask only relevant information, reducing unnecessary resource consumption while maintaining security control over sensitive information.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

Logging libraries perform self-service masking operations independently without requiring external scanning services. Each logging library contains built-in masking capabilities that automatically detect and mask sensitive data patterns in log messages, eliminating the need for resource-intensive external scanning infrastructure.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If separate scanning and masking functions are used, then flexibility is improved, but system complexity increases

Engineering Contradiction:
ImproveflexibilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system merges scanning and masking functions into unified logging libraries. Each logging library integrates both sensitive data detection and masking capabilities within a single component, reducing system complexity while maintaining flexibility through configurable masking patterns and multiple logging library options for different platforms.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

Logging libraries are designed with multi-functionality, serving as universal components that handle both logging and data masking operations. The same logging library infrastructure supports multiple platforms and applications while providing integrated masking capabilities, reducing the need for separate specialized components.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20250307463A1Integrated logging library for obfuscating sensitive information
Publication Date: 2025.10.02 CAPITAL ONE SERVICES LLC
  • US20250307463A1 patent drawing
  • US20250307463A1 patent drawing
  • US20250307463A1 patent drawing

AI summary

In some implementations, a device may configure, for a component that uses a platform, a logging library that is associated with a logging framework configured for the platform, wherein the logging library is configured to obfuscate the sensitive data. The device may obtain, for the component, component data via the platform, wherein the component data is associated with one or more operations of the component. The device may generate, via the logging framework, log data that includes obfuscated data generated via the logging library based on obtaining the component data, wherein the obfuscated data obfuscates any sensitive information in the log data. The device may perform, via the component, one or more actions using the log data.