On-Demand Data Masking Service via Virtualization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data masking solutions are inflexible, costly, and pose security risks due to their static nature, requiring extensive deployment and maintenance, and are not well-suited for on-demand access to sensitive data across diverse operating systems and platforms.
Innovation Solution
A method and system for providing on-demand data masking as a software service, where users can subscribe to a data masking service that dynamically applies masking rules to application data based on user credentials, allowing privileged users direct access and unprivileged users to receive masked data, thereby reducing deployment overhead and enhancing security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a standalone data masking product is deployed, then data masking functionality is provided, but deployment complexity and hardware requirements increase
Solution Approach 1:
The patent implements data masking functionality through virtualization by creating a virtual machine that hosts the data masking application. Instead of deploying standalone software on physical hardware, the solution copies the masking functionality into a virtualized environment that can be dynamically allocated and managed, reducing deployment complexity while maintaining functional reliability
Solution Approach 2:
The patent introduces a virtual machine as an intermediary layer between the physical hardware and the data masking application. This intermediary abstracts the complexity of direct hardware-software integration, allowing the masking functionality to be deployed without direct physical installation while maintaining reliable operation
2Reliability
If a standalone data masking product is physically installed, then data masking is provided, but security risks from physical access increase
Solution Approach 1:
The patent introduces a virtual machine as an intermediary layer between the physical hardware and the data masking application. This intermediary abstracts the complexity of direct hardware-software integration, allowing the masking functionality to be deployed without direct physical installation while maintaining reliable operation
Solution Approach 2:
The patent implements data masking functionality through virtualization by creating a virtual machine that hosts the data masking application. Instead of deploying standalone software on physical hardware, the solution copies the masking functionality into a virtualized environment that can be dynamically allocated and managed, reducing deployment complexity while maintaining functional reliability
3Reliability
If a standalone data masking product is used, then data masking capability is provided, but maintenance and updates become cumbersome
Solution Approach 1:
The patent implements dynamic data masking where the masking rules and parameters can be modified at runtime without requiring system downtime or complex reconfiguration. The virtualized environment allows flexible updates to masking policies and rules while the application remains operational, significantly improving maintenance ease while preserving data masking capability
4Reliability
If extensive data masking deployment is performed, then comprehensive data protection is achieved, but hardware and maintenance overhead increase
Solution Approach 1:
The patent creates a universal data masking platform through virtualization that can serve multiple applications and data sources from a single deployed instance. The virtual machine hosts the data masking application that can dynamically apply masking rules to various data types and formats, eliminating the need for separate hardware deployments for each data source while maintaining comprehensive data protection
Solution Approach 2:
The patent merges multiple data masking functions into a single virtualized platform that handles diverse masking requirements through configurable rules. By combining what would traditionally require separate hardware installations into one consolidated virtual environment, the solution reduces hardware overhead while maintaining comprehensive data protection capabilities
Data Source
AI summary
A system and method for presenting on-demand masking of data as a software service in a distributed environment is provided. An application hosted on a computing device receives request for access to application data from a user. Credentials of the user are first validated in order to determine whether the user is authorized to access the requested application data. For an authorized user, a category of the user is determined to ascertain whether the user is privileged to obtain full access. In case the user is a privileged user, unmasked application data is fetched from a database utility and provided to the user. In case the user is not a privileged user, application data access request is transferred to a data masking service. Application data is fetched from database utility, masked based on pre-defined masking rules and provided to the user.


