Selective Data Anonymization with Search IDs for Secure Cloud Retrieval

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The need for efficient data security measures to protect data stored at third-party locations, particularly in cloud computing environments, where regulatory compliance and client-specific security requirements are paramount, is not adequately addressed by existing technologies.

Innovation Solution

An anonymization system and method that includes an anonymization module to process data before transmission, generating anonymized data with a search ID, and a cross-reference stored in a data store, ensuring secure data transmission and de-anonymization upon retrieval.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If data is transmitted to third-party cloud locations, then data accessibility and cloud computing benefits are improved, but data security and regulatory compliance are compromised

Engineering Contradiction:
Improvedata accessibilityVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary anonymization of data before transmission to cloud locations. The anonymization module processes data in advance, replacing sensitive information with anonymized equivalents, so that when data is stored or accessed in the cloud, the security risk is already mitigated. This preliminary action allows cloud accessibility while preventing security compromises.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The anonymization module acts as an intermediary between the data source and the cloud storage system. It transforms data into an anonymized form that can be safely stored and accessed in the cloud without exposing sensitive information. The cross-reference table serves as another intermediary, allowing data retrieval while maintaining the anonymized state during cloud transmission.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If data is anonymized before transmission, then data security is improved, but data retrieval and de-anonymization capabilities may be compromised

Engineering Contradiction:
Improvedata securityVSAvoiddata retrievability
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system creates a cross-reference table that copies and stores the mapping between anonymized data and original data identifiers. This copy allows the system to retrieve and de-anonymize data when needed, without compromising the security of the actual data stored in anonymized form. The cross-reference table serves as a separate copy that enables data recovery while the main data remains protected.

Inventive Principle:
Principle #26Copying

3Reliability

If an anonymization module is implemented, then data protection capability is improved, but system complexity increases

Engineering Contradiction:
Improvedata protection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The anonymization system is segmented into distinct functional modules: the anonymization module that processes data, the cross-reference table that stores mappings, and the retrieval mechanism that uses the cross-reference. This segmentation allows each component to perform its specific function independently, making the overall complex system manageable and maintainable while providing comprehensive data protection.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12395469B1System and method to anonymize data transmitted to a destination computing device
Publication Date: 2025.08.19 FORTRA LLC
  • US12395469B1 patent drawing
  • US12395469B1 patent drawing
  • US12395469B1 patent drawing

AI summary

A method and system for anonymizing data to be transmitted to a destination computing device is disclosed. Anonymization strategy for data anonymization is provided. Data to be transmitted is received from a user computer. Selective anonymization of the data is performed, based on the anonymization strategy, using an anonymization module. The data includes a plurality of characters. A portion of the anonymized data is selected as a search ID. A cross reference between a search key indicative of a portion of the received data and the corresponding search ID is stored.