Intercepting Proxy Server for Cloud Data Obfuscation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprises face challenges in adopting cloud-based applications due to the loss of control and governance over sensitive data, which can lead to non-compliance with regulatory requirements, as data resides outside their environment, even with encryption not being sufficient for data protection.

Innovation Solution

A system and method utilizing an intercepting proxy server that obfuscates data by generating tokens, replacing sensitive data elements with sort-order preserving prefixes and random or encrypted token values, ensuring data remains within the enterprise's control while allowing cloud application usage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If enterprises store sensitive data in cloud applications, then they can access cloud-based functionality and services, but they lose control and governance over the data, leading to non-compliance with regulatory requirements

Engineering Contradiction:
Improvecloud application functionalityVSAvoiddata control and compliance
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent extracts sensitive data from the data object before transmitting to the cloud application. The intercepting proxy server identifies and removes sensitive data elements, replacing them with tokens or obfuscated values, thereby preventing sensitive information from leaving the enterprise environment while still allowing cloud application functionality to operate with non-sensitive data

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The intercepting proxy server acts as an intermediary between the client device and the cloud application. It intercepts data objects, processes them by removing or obfuscating sensitive information, and then transmits the modified data to the cloud application. This intermediary layer ensures data control and compliance while enabling cloud service usage

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If enterprises encrypt sensitive data before storing in the cloud, then data confidentiality is improved, but encryption is not sufficient for complete data protection and governance

Engineering Contradiction:
Improvedata confidentialityVSAvoiddata protection sufficiency
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The patent applies preliminary action by removing or obfuscating sensitive data from the data object before it leaves the enterprise environment. This proactive measure ensures that sensitive information never reaches the cloud application, eliminating the need to rely solely on encryption for data protection

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies different quality treatments to different parts of the data object. Sensitive data elements are identified and treated differently (removed or obfuscated) from non-sensitive data elements, which are transmitted normally to the cloud application. This selective processing ensures that only necessary data is exposed to the cloud environment

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP2702723B1System and method for data obfuscation in interception of communication with a cloud
Publication Date: 2017.04.19 GEN DIGITAL INC
  • EP2702723B1 patent drawingFigure 1
  • EP2702723B1 patent drawingFigure 2
  • EP2702723B1 patent drawingFigure 3

AI summary

An intercepting proxy server processes traffic between an enterprise user and a cloud application. The intercepting proxy server provides interception of real data elements in communications from the enterprise to the cloud and replacing them with obfuscating tokens which are randomly generated. To the cloud application real data are only visible as tokens. Tokens included in results returned from the cloud, are intercepted by the intercepting proxy server, and replaced with the corresponding real data elements. The obfuscating tokens are not computationally related to the original sensitive value. Each intercepted real data element is stored in a local persistent storage layer, and indexed by the corresponding obfuscating token, allowing the real data element to be retrieved when the token is returned from the cloud, for delivery to the user.