Linked Encryption Tokenization for User Traceable Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems fail to effectively protect sensitive user data in log records, particularly in multi-tenant computing environments, as they lack robust mechanisms for anonymization and compliance with privacy regulations, leading to potential data breaches and non-compliance with data handling requirements.

Innovation Solution

A system that employs linked encryption tokenization, where raw log records are processed to generate tokenized logs using various tokenization mechanisms, such as one-to-one mapping, cryptographic, and time window encryption, ensuring data anonymization and compliance with privacy regulations by allowing controlled access and support for the 'right to be forgotten' feature.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If sensitive user data is stored in log records for auditing and debugging purposes, then the system can perform security compliance and event tracking, but user privacy is compromised and data protection requirements are violated

Engineering Contradiction:
Improvesecurity complianceVSAvoiduser privacy exposure
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces tokenization as an intermediary mechanism that replaces sensitive user data with non-sensitive tokens in log records. The tokenization service acts as a mediator between the logging system and privacy protection requirements, allowing the system to retain audit capabilities while eliminating direct exposure of personal information. Tokens serve as placeholders that preserve structural integrity of logs without containing actual sensitive data.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts sensitive data from log records through the tokenization process. When log records are generated, personally identifiable information (PII) such as names, email addresses, and social security numbers are identified and extracted, replaced with tokens. This extraction separates the sensitive information from the operational logs, enabling auditing functions to continue while protecting user privacy.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If multiple tokenization mechanisms are implemented to handle different data types and compliance requirements, then data protection compliance is improved, but system complexity increases

Engineering Contradiction:
Improvedata protection complianceVSAvoidtokenization system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal tokenization service that handles multiple tokenization mechanisms (one-to-one mapping, cryptographic, time window encryption) through a single integrated platform. This multi-functional service can adapt to different data types, retention requirements, and compliance standards without requiring separate systems. The service automatically selects appropriate tokenization strategies based on the specific data and organizational policies.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent employs different tokenization parameters and mechanisms based on specific requirements: one-to-one mapping for permanent auditability, cryptographic tokenization for enhanced security, and time window encryption for compliance with right-to-be-forgotten regulations. By changing tokenization parameters rather than implementing separate systems, the patent manages complexity while maintaining compliance flexibility.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If tokens are retained indefinitely to support audit trails, then security compliance is maintained, but the right to be forgotten cannot be implemented

Engineering Contradiction:
Improveaudit trail integrityVSAvoidright to be forgotten compliance
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic token retention policies where tokens can be retained, anonymized, or deleted based on time windows and compliance requirements. Rather than static permanent retention, the system dynamically adjusts token lifecycle management - maintaining tokens for active audit periods, anonymizing them after certain periods, and deleting them when no longer needed. This dynamic approach satisfies both audit trail requirements and right-to-be-forgotten obligations.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent employs periodic review and management of tokens based on time windows. Tokens are created with expiration periods, and the system periodically reviews and manages token retention. This periodic action allows the system to maintain audit trails for required periods while automatically removing or anonymizing tokens beyond those periods, thus supporting both continuous auditing and the right to be forgotten.

Inventive Principle:
Principle #19Periodic action

4Reliability

If tokenization is applied to all fields in log records, then comprehensive data protection is achieved, but processing time and computational resources increase

Engineering Contradiction:
Improvedata protection coverageVSAvoidlog processing speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies tokenization selectively to specific fields containing personally identifiable information rather than uniformly to all log record fields. The system identifies which fields require protection (such as user names, email addresses, social security numbers) and applies appropriate tokenization mechanisms only to those fields. This local quality approach maintains comprehensive protection for sensitive data while minimizing processing overhead on non-sensitive fields.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10783259B2Method and apparatus for linked encryption tokenization of user traceable data
Publication Date: 2020.09.22 SALESFORCE INC
  • US10783259B2 patent drawing
  • US10783259B2 patent drawing
  • US10783259B2 patent drawing

AI summary

A method and apparatus for tokenization of user-traceable data are described. User traceable data is data that is not directly personal data but can be traced back to the identity or an activity of the user. A first raw value is encrypted into a first token using a symmetric key encryption mechanism based on a combination of a second raw value including personal data of a user and a second token resulting from the tokenization of the second raw value where the first token is an anonymized representation of the first raw value.