On-Demand Data Masking Service via Virtualization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data masking solutions are inflexible, costly, and pose security risks due to their static nature, requiring extensive deployment and maintenance, and are not well-suited for on-demand access to sensitive data across diverse operating systems and platforms.

Innovation Solution

A method and system for providing on-demand data masking as a software service, where users can subscribe to a data masking service that dynamically applies masking rules to application data based on user credentials, allowing privileged users direct access and unprivileged users to receive masked data, thereby reducing deployment overhead and enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a standalone data masking product is deployed, then data masking functionality is provided, but deployment complexity and hardware requirements increase

Engineering Contradiction:
Improvedata masking functionalityVSAvoiddeployment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements data masking functionality through virtualization by creating a virtual machine that hosts the data masking application. Instead of deploying standalone software on physical hardware, the solution copies the masking functionality into a virtualized environment that can be dynamically allocated and managed, reducing deployment complexity while maintaining functional reliability

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent introduces a virtual machine as an intermediary layer between the physical hardware and the data masking application. This intermediary abstracts the complexity of direct hardware-software integration, allowing the masking functionality to be deployed without direct physical installation while maintaining reliable operation

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a standalone data masking product is physically installed, then data masking is provided, but security risks from physical access increase

Engineering Contradiction:
Improvedata masking functionalityVSAvoidsecurity risks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a virtual machine as an intermediary layer between the physical hardware and the data masking application. This intermediary abstracts the complexity of direct hardware-software integration, allowing the masking functionality to be deployed without direct physical installation while maintaining reliable operation

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements data masking functionality through virtualization by creating a virtual machine that hosts the data masking application. Instead of deploying standalone software on physical hardware, the solution copies the masking functionality into a virtualized environment that can be dynamically allocated and managed, reducing deployment complexity while maintaining functional reliability

Inventive Principle:
Principle #26Copying

3Reliability

If a standalone data masking product is used, then data masking capability is provided, but maintenance and updates become cumbersome

Engineering Contradiction:
Improvedata masking capabilityVSAvoidmaintenance ease
Core Design Contradiction:
ReliabilityVSEase of repair

Solution Approach 1:

The patent implements dynamic data masking where the masking rules and parameters can be modified at runtime without requiring system downtime or complex reconfiguration. The virtualized environment allows flexible updates to masking policies and rules while the application remains operational, significantly improving maintenance ease while preserving data masking capability

Inventive Principle:
Principle #15Dynamics

4Reliability

If extensive data masking deployment is performed, then comprehensive data protection is achieved, but hardware and maintenance overhead increase

Engineering Contradiction:
Improvedata protectionVSAvoidhardware overhead
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent creates a universal data masking platform through virtualization that can serve multiple applications and data sources from a single deployed instance. The virtual machine hosts the data masking application that can dynamically apply masking rules to various data types and formats, eliminating the need for separate hardware deployments for each data source while maintaining comprehensive data protection

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges multiple data masking functions into a single virtualized platform that handles diverse masking requirements through configurable rules. By combining what would traditionally require separate hardware installations into one consolidated virtual environment, the solution reduces hardware overhead while maintaining comprehensive data protection capabilities

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS8881224B2Method and system for providing masking services
Publication Date: 2014.11.04 INFOSYS LTD
  • US8881224B2 patent drawing
  • US8881224B2 patent drawing
  • US8881224B2 patent drawing

AI summary

A system and method for presenting on-demand masking of data as a software service in a distributed environment is provided. An application hosted on a computing device receives request for access to application data from a user. Credentials of the user are first validated in order to determine whether the user is authorized to access the requested application data. For an authorized user, a category of the user is determined to ascertain whether the user is privileged to obtain full access. In case the user is a privileged user, unmasked application data is fetched from a database utility and provided to the user. In case the user is not a privileged user, application data access request is transferred to a data masking service. Application data is fetched from database utility, masked based on pre-defined masking rules and provided to the user.