On-Premise Application Anonymizing PII for SaaS Privacy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Data protection regulations pose challenges for enterprises using Software as a Service (SaaS) applications, as they need to ensure the privacy of on-premise data when transferring it to cloud-hosted SaaS appliances, and existing solutions require manual and inefficient processes for accessing personally identifiable information for investigative purposes.

Innovation Solution

An on-premise application maps personally identifiable information to anonymous identifications, which are then sent to SaaS appliances, where application-specific analytics are generated, and temporary tokens are used to authorize access, allowing authorized users to retrieve personally identifiable information without direct storage in the SaaS appliance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If personally identifiable information is stored and processed in SaaS applications, then analytical capabilities and data processing efficiency are improved, but data privacy protection and compliance with data protection regulations deteriorate

Engineering Contradiction:
Improvedata processing efficiencyVSAvoiddata privacy risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts personally identifiable information from the data processing flow. PII is identified, separated, and stored in a secure PII store, while only hashed identifiers are sent to the SaaS application for processing. This extraction maintains productivity while eliminating privacy risks in the cloud environment.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a PII store and hashing mechanism as intermediaries between the on-premise environment and SaaS application. The PII store acts as a secure intermediary that holds sensitive data, while hashed identifiers serve as mediators that enable data processing without exposing actual PII to the SaaS application.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If personally identifiable information is anonymized before sending to SaaS applications, then data privacy protection is improved, but the ability to access and investigate specific user data deteriorates

Engineering Contradiction:
Improvedata privacy protectionVSAvoidinvestigative access capability
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The patent implements a feedback mechanism where authorized users can request access to PII through the investigative interface. The system responds by validating authorization credentials, checking permissions, and conditionally revealing PII based on authorization status. This feedback loop maintains privacy protection while enabling legitimate investigative access.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent performs preliminary authorization validation before allowing access to PII. Authorization credentials are verified in advance, and permission checks are conducted before PII is revealed. This preliminary action ensures that only authorized users can access sensitive data, maintaining both privacy and investigative capability.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If manual processes are used to access and transfer personally identifiable information for investigative purposes, then data security control is improved, but operational efficiency and investigative speed deteriorate

Engineering Contradiction:
Improvedata security controlVSAvoidinvestigative efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements a self-service investigative interface that allows authorized users to independently query and access PII without manual administrative intervention. The system automatically handles authorization validation, PII retrieval, and result delivery. This self-service approach maintains security controls while dramatically improving investigative efficiency.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent performs preliminary setup of authorization credentials and permission structures before investigative operations begin. Authorization matrices and credential validations are pre-configured, enabling rapid automated access decisions during investigations. This preliminary action eliminates manual approval delays while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10192071B2Method for integrating applications
Publication Date: 2019.01.29 CA TECH INC
  • US10192071B2 patent drawing
  • US10192071B2 patent drawing
  • US10192071B2 patent drawing

AI summary

In certain embodiments, a method includes mapping, by a first application, personally identifiable information to an anonymous identification, generating, by the first application, a key, and sending, by a first appliance, the anonymous identification and the key to a second appliance, wherein the first appliance comprises the first application. The method also includes receiving, by the first appliance and from a browser, a token generated by a second application of the second appliance, wherein the token is associated with the key. The method further includes sending, by the first appliance, the personally identifiable information to the browser after receiving the token from the browser.