Network Security Appliance Tokenizing Sensitive Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Off-the-shelf encryption and tokenization solutions are often insufficient for organizations, requiring significant changes to computer systems and software, which can be costly and introduce software bugs, leading many to forego implementation.

Innovation Solution

A network security device that analyzes data units, identifies application layer protocols, extracts sensitive data, and replaces it with tokens, using a token encoder to secure messages by interposing between end-user devices and servers, allowing for transparent data protection without altering existing systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If custom encryption or tokenization is implemented, then data security is improved, but system complexity and implementation cost increase significantly

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a security appliance as an intermediary device positioned between the network and existing computer systems. This appliance performs protocol analysis, data extraction, and tokenization operations on data traffic without requiring modifications to the existing systems. The intermediary handles all complexity of custom tokenization internally while presenting a transparent interface to both clients and servers, thus improving data security without increasing system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If custom encryption or tokenization is implemented, then data security is improved, but implementation cost and risk of software bugs increase

Engineering Contradiction:
Improvedata securityVSAvoidimplementation ease
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The security appliance serves as a standalone intermediary that encapsulates all tokenization functionality, eliminating the need for organizations to implement custom tokenization within their existing systems. This approach transfers implementation complexity and bug risk from the organization to the appliance vendor, while maintaining data security through professional-grade tokenization capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security appliance performs self-service by automatically analyzing incoming data traffic, identifying sensitive information based on protocol knowledge, extracting the data, and replacing it with tokens. The appliance manages its own operation, configuration, and token mapping without requiring deep integration into or modification of existing organizational systems, thereby simplifying implementation while maintaining security.

Inventive Principle:
Principle #25Self-service

3Reliability

If data is removed and replaced with tokens, then data security is improved, but system transparency and ease of operation may worsen

Engineering Contradiction:
Improvedata securityVSAvoidsystem transparency
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The security appliance acts as an invisible intermediary that performs tokenization transparently. It intercepts data traffic, replaces sensitive data with tokens, and forwards the modified traffic to destination systems without requiring any changes to client or server applications. The appliance maintains system transparency by presenting itself as a standard network component that does not disrupt existing operations or require users to change their behavior.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11038851B2Tokenizing network appliance and method
Publication Date: 2021.06.15 DATEX
  • US11038851B2 patent drawing
  • US11038851B2 patent drawing
  • US11038851B2 patent drawing

AI summary

An example security device receives a plurality of data units carrying traffic in a message encoded in accordance with an application layer protocol for a server. The message comprises payload. The security device analyzes the plurality of data units to identify the application layer protocol; selects a data extraction algorithm in dependence on the identified application layer protocol; extracts selected data from the payload, in accordance with one or more tokenizing rules; and forwards selected data to a token encoder, to allow the token encoder to store selected data and return at least one token used to identify the selected data. The device receives from the token encoder, at least one token and replaces the selecting data in the payload with the at least one token to form modified payload and forming and forwards a modified message comprising the payload data, in place of the message, thereby securing the original message.