Proxy Server Data Masking for Secure Software Development
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Organizations face challenges in outsourcing activities involving sensitive customer information, such as financial or healthcare data, due to concerns about third-party safeguards, which can lead to identity theft and regulatory violations, resulting in financial liability.
Innovation Solution
A system utilizing a proxy device that modifies data streams by replacing actual account information with dummy or encoded information during communication between a financial institution and a software engineer, ensuring security while allowing third-party software development.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If actual account information is transmitted to third-party software developers, then software development can proceed, but security of sensitive customer information is compromised
Solution Approach 1:
The patent creates dummy account information that copies the structure and format of actual account information. The dummy data includes placeholder values for account numbers, names, addresses, and other customer information fields, allowing software developers to test and develop applications without accessing real sensitive data. This resolves the contradiction by providing a safe copy that maintains development productivity while eliminating security risks.
Solution Approach 2:
The patent introduces a proxy server as an intermediary between the financial institution's database and the software developer's application. The proxy server receives requests from the developer's application, modifies them to use dummy account information instead of actual customer data, and returns modified responses. This intermediary layer enables software development to proceed while protecting the security of actual account information stored in the database.
2Object-affected harmful factors
If dummy account information is used instead of actual information, then security is maintained, but software development functionality is limited
Solution Approach 1:
The patent applies different qualities of data to different parts of the software development process. Dummy account information is used in testing and development environments where security is paramount, while the system maintains the capability to switch to actual account information when needed for production deployment. The proxy server can selectively apply dummy data to specific requests while allowing other operations to proceed with real data, providing local quality variations that balance security and functionality.
Solution Approach 2:
The patent enables dynamic parameter changes in the account information provided to developers. The dummy account information can be configured with various parameters such as different data formats, validation rules, and response structures that match the expected behavior of the financial institution's systems. This allows software developers to test with realistic parameter variations while still using dummy data, maintaining both security and development versatility.
3Reliability
If third-party developers access real account information, then comprehensive testing can be performed, but risk of data misuse and regulatory violations increases
Solution Approach 1:
The patent creates comprehensive dummy account information that replicates the full structure, format, and relationships of actual account data. This includes dummy customer profiles, account balances, transaction histories, and personal information fields. The copied structure allows developers to perform comprehensive testing of all application features and data processing paths while using only synthetic data, achieving testing accuracy without exposing real customer information to misuse risks.
Solution Approach 2:
The proxy server acts as a mediator that translates between the developer's application requests and the financial institution's data structures. It modifies requests to use dummy account information and transforms responses to maintain the expected data format and relationships. This intermediary enables comprehensive testing of application logic, data processing, and user interactions while ensuring that no actual customer information is exposed to the developer's application, eliminating the risk of data misuse.
Data Source
AI summary
Embodiments of a proxy device, a system that includes the proxy device, a process, and a computer-program product (i.e., software) for use with the proxy device are described. This proxy device may be used to restrict access to account information during communication between a financial institution and a software engineer, such as a third-party software developer. In particular, the proxy device, which is an intermediary between the financial institution and the software engineer, may replace actual account information with dummy or encoded account information during communication from the financial institution to the software engineer. Similarly, the proxy device may replace the dummy or encoded account information with the actual account information during communication from the software engineer to the financial institution. In this way, the proxy device may facilitate software development while maintaining security of the actual account information.


