Localized Data Export With Masking and Encryption for Secure Search

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data management systems face challenges in protecting sensitive information during data export, as they often send personally identifiable information in the clear, which can lead to security breaches and hinder full data comparisons.

Innovation Solution

A method and system for controlled release of information that exports data in a format with unmasked, masked, and encrypted portions, allowing access outside the security protocol through localized volumes, using custom applications for secure access and decryption on demand.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If data is exported in the clear for access outside security protocol, then ease of operation is improved, but security is worsened due to exposure of sensitive information

Engineering Contradiction:
Improveaccess outside security protocolVSAvoidexposure of sensitive information
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The data is segmented into different portions: unmasked portions for basic access, masked portions for sensitive information, and encrypted portions for highly sensitive data. This segmentation allows the system to provide different levels of access control, enabling operations outside the security protocol while protecting sensitive information through selective masking and encryption.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different portions of the data have different security qualities. The unmasked portions are accessible outside the security protocol, while masked and encrypted portions maintain security protections. This local differentiation of security qualities allows the system to balance ease of operation with security by applying appropriate protection levels to specific data elements.

Inventive Principle:
Principle #3Local quality

2Object-affected harmful factors

If data is masked and encrypted to protect sensitive information, then security is improved, but data comparison capability is worsened

Engineering Contradiction:
Improveprotection of sensitive informationVSAvoiddata comparison capability
Core Design Contradiction:
Object-affected harmful factorsVSLoss of information

Solution Approach 1:

The data is divided into masked portions and encrypted portions, allowing the system to mask sensitive information while preserving comparison capabilities for unmasked portions. This segmentation enables selective protection where data comparison remains possible for non-sensitive fields while sensitive fields are protected through masking and encryption.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system applies masking and encryption only to the extent necessary for protection, leaving unmasked portions accessible for comparison. This partial action approach allows the system to protect sensitive information without过度 protecting data that does not require security, thereby maintaining data comparison capability where appropriate.

Inventive Principle:
Principle #16Partial or excessive action

3Productivity

If full data is exported for analysis, then productivity is improved, but security is worsened due to transmission of sensitive information outside security protocol

Engineering Contradiction:
Improvedata analysis capabilityVSAvoidtransmission of sensitive information
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The exported data is segmented into unmasked, masked, and encrypted portions, allowing the system to transmit data outside the security protocol while maintaining security through selective encryption. This enables productivity by providing data for analysis while security is preserved through the encrypted portions that remain protected during transmission.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system changes the security parameters of the data by applying different levels of protection (unmasked, masked, encrypted) to different portions. This parameter transformation allows the data to be transmitted outside the security protocol in a secured manner, balancing productivity needs with security requirements.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12481776B2Controlled release of information in data export
Publication Date: 2025.11.25 KYOCERA DOCUMENT SOLUTIONS INC
  • US12481776B2 patent drawing
  • US12481776B2 patent drawing
  • US12481776B2 patent drawing

AI summary

Apparatuses and methods relate generally to controlled release of information. In a method, data of a data store in a network is exported in a format having unmasked, masked and encrypted portions and outside of a security protocol of the network. The data is provided as a localized volume for access via an application executing on a device for reading outside of the security protocol. The data has the masked and encrypted portions for a protected state. The data is searched with a search vector via the application. The application is configured for localized access of the data in the localized volume. Multiple records are found in the data responsive to the search vector. A target record of the multiple records is selected responsive to one or more of the unmasked portions of the data mixed in with the masked portions and the encrypted portions of the multiple records.