Linked Encryption Tokenization for User Traceable Data
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems fail to effectively protect sensitive user data in log records, particularly in multi-tenant computing environments, as they lack robust mechanisms for anonymization and compliance with privacy regulations, leading to potential data breaches and non-compliance with data handling requirements.
Innovation Solution
A system that employs linked encryption tokenization, where raw log records are processed to generate tokenized logs using various tokenization mechanisms, such as one-to-one mapping, cryptographic, and time window encryption, ensuring data anonymization and compliance with privacy regulations by allowing controlled access and support for the 'right to be forgotten' feature.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If sensitive user data is stored in log records for auditing and debugging purposes, then the system can perform security compliance and event tracking, but user privacy is compromised and data protection requirements are violated
Solution Approach 1:
The patent introduces tokenization as an intermediary mechanism that replaces sensitive user data with non-sensitive tokens in log records. The tokenization service acts as a mediator between the logging system and privacy protection requirements, allowing the system to retain audit capabilities while eliminating direct exposure of personal information. Tokens serve as placeholders that preserve structural integrity of logs without containing actual sensitive data.
Solution Approach 2:
The patent extracts sensitive data from log records through the tokenization process. When log records are generated, personally identifiable information (PII) such as names, email addresses, and social security numbers are identified and extracted, replaced with tokens. This extraction separates the sensitive information from the operational logs, enabling auditing functions to continue while protecting user privacy.
2Reliability
If multiple tokenization mechanisms are implemented to handle different data types and compliance requirements, then data protection compliance is improved, but system complexity increases
Solution Approach 1:
The patent implements a universal tokenization service that handles multiple tokenization mechanisms (one-to-one mapping, cryptographic, time window encryption) through a single integrated platform. This multi-functional service can adapt to different data types, retention requirements, and compliance standards without requiring separate systems. The service automatically selects appropriate tokenization strategies based on the specific data and organizational policies.
Solution Approach 2:
The patent employs different tokenization parameters and mechanisms based on specific requirements: one-to-one mapping for permanent auditability, cryptographic tokenization for enhanced security, and time window encryption for compliance with right-to-be-forgotten regulations. By changing tokenization parameters rather than implementing separate systems, the patent manages complexity while maintaining compliance flexibility.
3Reliability
If tokens are retained indefinitely to support audit trails, then security compliance is maintained, but the right to be forgotten cannot be implemented
Solution Approach 1:
The patent implements dynamic token retention policies where tokens can be retained, anonymized, or deleted based on time windows and compliance requirements. Rather than static permanent retention, the system dynamically adjusts token lifecycle management - maintaining tokens for active audit periods, anonymizing them after certain periods, and deleting them when no longer needed. This dynamic approach satisfies both audit trail requirements and right-to-be-forgotten obligations.
Solution Approach 2:
The patent employs periodic review and management of tokens based on time windows. Tokens are created with expiration periods, and the system periodically reviews and manages token retention. This periodic action allows the system to maintain audit trails for required periods while automatically removing or anonymizing tokens beyond those periods, thus supporting both continuous auditing and the right to be forgotten.
4Reliability
If tokenization is applied to all fields in log records, then comprehensive data protection is achieved, but processing time and computational resources increase
Solution Approach 1:
The patent applies tokenization selectively to specific fields containing personally identifiable information rather than uniformly to all log record fields. The system identifies which fields require protection (such as user names, email addresses, social security numbers) and applies appropriate tokenization mechanisms only to those fields. This local quality approach maintains comprehensive protection for sensitive data while minimizing processing overhead on non-sensitive fields.
Data Source
AI summary
A method and apparatus for tokenization of user-traceable data are described. User traceable data is data that is not directly personal data but can be traced back to the identity or an activity of the user. A first raw value is encrypted into a first token using a symmetric key encryption mechanism based on a combination of a second raw value including personal data of a user and a second token resulting from the tokenization of the second raw value where the first token is an anonymized representation of the first raw value.


