Selective Encryption of Outgoing Data Using Sensitive Information Identification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data encryption techniques are resource-intensive and do not allow for selective encryption of sensitive information within larger data sets, leading to potential information leakage and compliance issues, such as PCI non-compliance.
Innovation Solution
A method that monitors outgoing data, identifies sensitive information, encrypts it selectively using a data protection manager, and replaces the sensitive information with encrypted data, allowing for secure transmission while keeping the rest of the data unencrypted, using a combination of data loss prevention and encryption technologies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the entire data set is encrypted to protect sensitive information, then security and compliance are improved, but resource consumption increases significantly
Solution Approach 1:
The patent segments the data set into sensitive and non-sensitive portions, applying encryption only to the sensitive segments. This allows selective protection of critical information while leaving other data unencrypted, thereby maintaining security for sensitive data while reducing the overall resource consumption associated with encryption operations.
Solution Approach 2:
The patent applies different quality levels of protection to different parts of the data set. Sensitive information receives full encryption protection, while non-sensitive information remains unencrypted. This local differentiation of security quality optimizes resource usage by concentrating encryption resources only where they are most needed.
2Reliability
If the entire data set is encrypted to prevent information leakage, then data protection is improved, but processing time and computational resources increase
Solution Approach 1:
The patent divides the data set into sensitive and non-sensitive segments, applying encryption only to the sensitive portions. This segmentation reduces the total amount of data requiring encryption processing, thereby maintaining adequate data protection for sensitive information while significantly reducing the processing time and computational resources required.
Solution Approach 2:
The patent applies partial encryption action by encrypting only the necessary sensitive portions of the data set rather than the entire data set. This partial action approach provides sufficient protection for critical information while avoiding the excessive processing time and resource consumption that would result from encrypting all data.
3Productivity
If selective encryption is implemented to reduce resource usage, then resource efficiency is improved, but system complexity increases due to data monitoring and identification requirements
Solution Approach 1:
The patent implements preliminary action by pre-defining patterns and criteria for identifying sensitive information before the encryption process begins. This preliminary setup includes establishing regex patterns, data classification rules, and sensitivity thresholds that automatically guide the selective encryption process, thereby reducing the complexity of real-time decision-making during data processing.
Solution Approach 2:
The patent enables self-service functionality where the system automatically monitors, identifies, and encrypts sensitive data based on pre-configured patterns and rules without requiring complex manual intervention. The system serves itself by autonomously determining which data portions require encryption based on the established criteria, reducing the operational complexity while maintaining resource efficiency.
Data Source
AI summary
Methods, apparatus and articles of manufacture for selective encryption of outgoing data are provided herein. A method includes monitoring a set of outgoing data from a first user, identifying one or more items of sensitive information from the set of outgoing data, encrypting the one or more items of sensitive information to produce one or more items of encrypted sensitive information, and replacing the one or more items of sensitive information with the one or more items of encrypted sensitive information in the set of outgoing data.


