Reversible Data Masking Agent for Cloud Analytics Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud-based reporting and analysis systems pose a security risk as they require sharing sensitive computing environment information, which can be exploited by malicious parties, leading customers to hesitate in adopting these services despite their efficiency advantages.

Innovation Solution

An intelligent and reversible data masking system that uses a secure masking agent to identify and mask sensitive information, replacing it with anonymized values while preserving contextual information, allowing for detailed analysis without exposing sensitive data to external systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If detailed computing environment information is shared with external cloud-based reporting and analysis systems, then analysis accuracy and reporting quality are improved, but security risk increases due to potential exposure to malicious parties

Engineering Contradiction:
Improveanalysis accuracyVSAvoidsecurity risk
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

A masking agent is introduced as an intermediary component between the computing environment and external reporting systems. This agent masks sensitive information (such as host names, IP addresses, and configuration details) before transmission, allowing analysis to proceed on masked data while preventing direct exposure of sensitive computing environment information to external systems

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system transforms sensitive information parameters into masked representations by replacing identifiable computing environment parameters (host names, network addresses, configuration values) with masked equivalents. This parameter transformation maintains the structural integrity needed for analysis while eliminating security risks associated with exposing actual sensitive values

Inventive Principle:
Principle #35Parameter changes

2Object-affected harmful factors

If sensitive information is masked before sharing with external systems, then security risk is reduced, but analysis quality may deteriorate due to loss of detailed information

Engineering Contradiction:
Improvesecurity riskVSAvoidanalysis quality
Core Design Contradiction:
Object-affected harmful factorsVSMeasurement precision

Solution Approach 1:

The masking agent applies selective masking where different portions of information receive different treatment. Sensitive portions (host names, IP addresses, configuration identifiers) are masked while non-sensitive portions (error types, operational patterns, performance metrics) are preserved in detail. This local differentiation maintains analysis quality for non-sensitive aspects while protecting sensitive information

Inventive Principle:
Principle #3Local quality

3Productivity

If cloud-based reporting systems are adopted for efficiency, then productivity is improved, but data security concerns increase leading to customer hesitation

Engineering Contradiction:
Improveoperational efficiencyVSAvoiddata security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The masking agent serves as a security intermediary that enables customers to adopt cloud-based reporting systems without directly exposing sensitive data. By masking information before transmission to external cloud services, the system maintains productivity benefits while addressing security concerns, allowing customers to confidently use cloud-based analysis tools

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11960623B2Intelligent and reversible data masking of computing environment information shared with external systems
Publication Date: 2024.04.16 EMC IP HLDG CO LLC
  • US11960623B2 patent drawing
  • US11960623B2 patent drawing
  • US11960623B2 patent drawing

AI summary

Described is a system for intelligent and reversible data masking of computing environment information shared with an external system. The system may leverage a secure masking agent that acts as an intermediary between a computing system (or environment) and an analytics component. The masking agent may provide real-time reversible data masking that ensures that sensitive information is not exposed outside of a secure (e.g. on-premises) environment, while at the same time ensuring the analytics component receives sufficient contextual information to perform a detailed analysis with the shared information. For example, the system may identify and mask identifying information of a particular server or host, while still retaining certain contextual information such as a network topology.