Masking Service Tokenizes Customer Data in Cloud Pipelines
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Organizations face challenges in protecting customer personal information when integrating with cloud-hosted applications, as existing solutions fail to effectively detect and tokenize sensitive data across various communication sources, risking privacy and security breaches.
Innovation Solution
A masking service is integrated into the on-premises pipeline of customer-facing services, utilizing a layered detection approach combining rule-based and machine learning-based methods to identify and tokenize customer personal information, ensuring it is not exposed when transmitted to cloud-hosted applications or external systems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If customer personal information is transmitted to cloud-hosted applications for service delivery, then service functionality and scalability are improved, but data security and privacy protection deteriorate due to exposure risks in external systems
Solution Approach 1:
The patent introduces a masking service as an intermediary component in the data transmission pipeline. This service sits between the customer-facing service and the cloud-hosted application, intercepting data flows and applying tokenization transformations. The masking service enables secure data transmission by replacing sensitive information with tokens before external transmission, thus mediating between the need for cloud-based scalability and the requirement for data security.
2Object-affected harmful factors
If sensitive data is tokenized before transmission to external systems, then data security is improved, but data utility and accessibility deteriorate due to loss of original information
Solution Approach 1:
The patent segments the data handling process into distinct stages: identification of sensitive data, tokenization transformation, transmission with tokens, and selective recovery. The segmentation allows different portions of the system to handle data differently - the masking service tokenizes data for secure transmission, while authorized systems can recover original data when needed, thus maintaining both security and utility through process segmentation.
Solution Approach 2:
The patent changes the parameter state of sensitive data through tokenization - transforming readable sensitive information into non-readable token representations. This parameter change (from plaintext to token format) secures data during transmission. The ability to reversibly change parameters back to the original state when authorized ensures data utility is preserved despite the initial transformation.
3Measurement precision
If multiple detection layers are implemented to identify different types of sensitive data, then detection accuracy is improved, but system complexity increases due to multiple processing stages
Solution Approach 1:
The patent divides the detection process into multiple specialized detection layers, each targeting specific types of sensitive data (e.g., personally identifiable information, financial data, health information). This segmentation of the detection function into specialized sub-layers improves overall detection accuracy by assigning specific expertise to each layer, while the modular structure manages complexity through clear separation of concerns.
Solution Approach 2:
The masking service implements a universal detection framework that handles multiple types of sensitive data through a common architecture. The detection layers work together within a single service component, providing multi-functional capability to identify various data types (PII, financial, health) using unified tokenization processes, thus achieving comprehensive detection without proportionally increasing system complexity.
Data Source
AI summary
Techniques are described that include detecting customer personal information within any appropriate set of data, such as customer communications produced by customer-facing services offered by an organization. Once detected, the customer personal information may be tokenized within the customer communications, making the data appropriate for external systems, such as cloud-hosted applications. The disclosed techniques include a masking service that may be plugged into an on-premises pipeline of any customer-facing service that makes requests to an off-premises, cloud-hosted application. The masking service may apply rule-based detection and/or machine learning-based detection to detect both structured and unstructured customer personal information included in customer communications. The masking service may further tokenize or otherwise obfuscate or replace the detected customer personal information. The tokenized customer communications may then be included in the requests to the cloud-hosted application or otherwise transmitted to external systems without exposing the customer personal information.


