Localized Data Export With Masking and Encryption for Secure Search
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data management systems face challenges in protecting sensitive information during data export, as they often send personally identifiable information in the clear, which can lead to security breaches and hinder full data comparisons.
Innovation Solution
A method and system for controlled release of information that exports data in a format with unmasked, masked, and encrypted portions, allowing access outside the security protocol through localized volumes, using custom applications for secure access and decryption on demand.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If data is exported in the clear for access outside security protocol, then ease of operation is improved, but security is worsened due to exposure of sensitive information
Solution Approach 1:
The data is segmented into different portions: unmasked portions for basic access, masked portions for sensitive information, and encrypted portions for highly sensitive data. This segmentation allows the system to provide different levels of access control, enabling operations outside the security protocol while protecting sensitive information through selective masking and encryption.
Solution Approach 2:
Different portions of the data have different security qualities. The unmasked portions are accessible outside the security protocol, while masked and encrypted portions maintain security protections. This local differentiation of security qualities allows the system to balance ease of operation with security by applying appropriate protection levels to specific data elements.
2Object-affected harmful factors
If data is masked and encrypted to protect sensitive information, then security is improved, but data comparison capability is worsened
Solution Approach 1:
The data is divided into masked portions and encrypted portions, allowing the system to mask sensitive information while preserving comparison capabilities for unmasked portions. This segmentation enables selective protection where data comparison remains possible for non-sensitive fields while sensitive fields are protected through masking and encryption.
Solution Approach 2:
The system applies masking and encryption only to the extent necessary for protection, leaving unmasked portions accessible for comparison. This partial action approach allows the system to protect sensitive information without过度 protecting data that does not require security, thereby maintaining data comparison capability where appropriate.
3Productivity
If full data is exported for analysis, then productivity is improved, but security is worsened due to transmission of sensitive information outside security protocol
Solution Approach 1:
The exported data is segmented into unmasked, masked, and encrypted portions, allowing the system to transmit data outside the security protocol while maintaining security through selective encryption. This enables productivity by providing data for analysis while security is preserved through the encrypted portions that remain protected during transmission.
Solution Approach 2:
The system changes the security parameters of the data by applying different levels of protection (unmasked, masked, encrypted) to different portions. This parameter transformation allows the data to be transmitted outside the security protocol in a secured manner, balancing productivity needs with security requirements.
Data Source
AI summary
Apparatuses and methods relate generally to controlled release of information. In a method, data of a data store in a network is exported in a format having unmasked, masked and encrypted portions and outside of a security protocol of the network. The data is provided as a localized volume for access via an application executing on a device for reading outside of the security protocol. The data has the masked and encrypted portions for a protected state. The data is searched with a search vector via the application. The application is configured for localized access of the data in the localized volume. Multiple records are found in the data responsive to the search vector. A target record of the multiple records is selected responsive to one or more of the unmasked portions of the data mixed in with the masked portions and the encrypted portions of the multiple records.


