Real-Time Transactional Data Obfuscation for Privacy and Usability

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data privacy methods, such as access control and encryption, are insufficient in preventing internal data breaches and identity thefts, particularly in real-time transactional data environments, where maintaining data usability while ensuring privacy is a contradicting requirement.

Innovation Solution

A system and method for real-time transactional data obfuscation using different obfuscation functions for various data types, such as GT-ANeNDS, which combines anonymization and NeNDS techniques, to securely obfuscate data while preserving statistical characteristics, ensuring data privacy and usability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data encryption and access control methods are used to protect personal identifiable information, then data privacy is improved, but data usability deteriorates

Engineering Contradiction:
Improvedata privacyVSAvoiddata usability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments data protection into two distinct layers: encrypted storage for security and obfuscated copies for usability. The encryption module stores sensitive PII in encrypted form, while the obfuscation module creates usable but falsified copies for testing and analysis, allowing both privacy and usability requirements to be satisfied simultaneously

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary obfuscation layer between the encrypted data storage and the application layer. This obfuscation module acts as a mediator that provides data in a format suitable for testing and analysis while preventing access to the actual encrypted PII, thus resolving the conflict between security and usability

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If real-time data obfuscation is implemented to maintain data usability, then data usability is improved, but processing time increases

Engineering Contradiction:
Improvedata usabilityVSAvoidprocessing time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent implements preliminary obfuscation of data before it is stored or accessed. By pre-obfuscating PII into falsified but realistic data, the system eliminates the need for complex real-time processing during testing or analysis operations, thus maintaining usability without incurring processing time penalties

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates copies of PII data that are obfuscated rather than the original data itself. These obfuscated copies contain falsified information that maintains the statistical and structural characteristics of the original data, allowing rapid processing and analysis without the computational overhead of real-time encryption/decryption operations

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11544395B2System and method for real-time transactional data obfuscation
Publication Date: 2023.01.03 ORACLE INT CORP
  • US11544395B2 patent drawing
  • US11544395B2 patent drawing
  • US11544395B2 patent drawing

AI summary

A system and method for providing transactional data privacy while maintaining data usability, including the use of different obfuscation functions for different data types to securely obfuscate the data, in real-time, while maintaining its statistical characteristics. In accordance with an embodiment, the system comprises an obfuscation process that captures data while it is being received in the form of data changes at a first or source system, selects one or more obfuscation techniques to be used with the data according to the type of data captured, and obfuscates the data, using the selected one or more obfuscation techniques, to create an obfuscated data, for use in generating a trail file containing the obfuscated data, or applying the data changes to a target or second system.