Secure Data Redaction via Intercept Agent Policy Encoding

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems for secure data redaction and masking in intercepted data interactions cause significant delays and increase network traffic due to the need for separate execution of security applications and intercept agents, leading to degraded performance and increased workload on data processing systems.

Innovation Solution

A system and computer program product that dynamically adjust quality of service by encoding instructions for data modification using a coding grammar, allowing the modification to be performed either at the security system or the intercept system based on network and system conditions, thereby reducing the need to transmit large modified protocol packets and optimizing network traffic and system workload.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the security application executes separately from the intercept agent to perform data redaction and masking, then security compliance is ensured, but significant delays occur and network traffic increases

Engineering Contradiction:
Improvesecurity complianceVSAvoidprocessing delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent combines the security application and intercept agent into a unified system where the intercept agent can directly apply security policies and perform data redaction/masking operations. This integration eliminates the need for separate execution and communication between distinct components, thereby reducing processing delays while maintaining security compliance through the embedded security policy engine.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system performs security policy application and data redaction operations at the point of interception, before data is fully processed or transmitted. By executing security functions preliminarily at the intercept agent, the system avoids subsequent processing delays that would occur if security checks were performed later in separate security applications.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If the security application executes separately from the intercept agent to perform data redaction and masking, then security compliance is ensured, but network traffic increases

Engineering Contradiction:
Improvesecurity complianceVSAvoidnetwork traffic
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

By merging the security application functionality into the intercept agent, the system eliminates the need for separate communication channels and data transmissions between independent security applications and intercept agents. The intercept agent directly applies security policies and returns modified data, reducing network traffic while ensuring security compliance through integrated policy enforcement.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If separate security applications and intercept agents are used for data modification, then security policies can be applied, but workload on data processing systems increases

Engineering Contradiction:
Improvesecurity policy applicationVSAvoidsystem workload
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent merges security policy application capabilities directly into the intercept agent, consolidating what were previously separate workloads into a single integrated component. This reduces the overall system workload by eliminating redundant processing and communication overhead between separate security applications and intercept agents, while maintaining comprehensive security policy enforcement.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS10097582B2Secure data redaction and masking in intercepted data interactions
Publication Date: 2018.10.09 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10097582B2 patent drawing
  • US10097582B2 patent drawing
  • US10097582B2 patent drawing

AI summary

A system, and computer program product for modifying intercepted data interactions are provided in the illustrative embodiments. At a security application executing in a security data processing system, an intercepted packet of data arranged according to a protocol is received from an intercepting agent executing in an intercepting data processing system. A security policy is applied to the intercepted packet. In an instruction according to a coding grammar, a modification of the intercepted packet is encoded. The instruction is suited for the encoding under a circumstance of the modifying. The instruction is sent to the intercepting agent. The intercepting agent at the intercepting data processing system performs the modification according to the security policy and independently of the protocol.