Sensitive Data Processing via Remote De-protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cloud computing solutions face challenges in handling sensitive data due to compliance issues with data privacy regulations, as encryption methods hinder logical operations and require decryption, which may not be compliant with regional laws, leading to complications in accessing and processing sensitive data within cloud environments.

Innovation Solution

A method and system that identify and execute operations on protected sensitive data by de-protecting it at a remote processor located in a compliant region, allowing operations to be performed securely outside the primary cloud data center, while maintaining encryption within the cloud, thus ensuring compliance with data privacy laws without decrypting sensitive data within the cloud service provider's environment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If sensitive data are encrypted in the cloud to ensure data privacy compliance, then data security is improved, but logical operations and data processing cannot be performed

Engineering Contradiction:
Improvedata securityVSAvoiddata processing capability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments data into sensitive and non-sensitive portions, applying different handling methods. Sensitive data remains encrypted in the cloud while non-sensitive data can be processed freely. The system also segments processing operations, performing only necessary operations on encrypted data or on decrypted portions in controlled environments.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary decryption/encryption layer that allows processing operations to occur on sensitive data without permanently decrypting it in the cloud. The intermediary system can temporarily decrypt data for processing, then re-encrypt it, acting as a mediator between the encrypted storage and processing requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If all data are encrypted when entering the cloud to maintain data privacy, then compliance with data protection rules is improved, but applications cannot perform logical operations on the data

Engineering Contradiction:
Improvedata privacy complianceVSAvoidapplication processing efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies local quality by treating different portions of data differently based on their sensitivity. Sensitive fields remain encrypted while non-sensitive fields are kept in plaintext or decrypted, allowing applications to process non-sensitive data efficiently while maintaining protection on sensitive data. This selective approach enables partial processing without full decryption.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements partial action by decrypting only the specific portions of data that need to be processed, rather than decrypting entire records or datasets. This allows applications to perform necessary operations on specific fields while leaving other sensitive data encrypted, thereby maintaining productivity for required operations while preserving security for protected data.

Inventive Principle:
Principle #16Partial or excessive action

3Adaptability or versatility

If data are decrypted for processing in the cloud, then operational flexibility is improved, but compliance with regional data privacy laws deteriorates

Engineering Contradiction:
Improvedata processing flexibilityVSAvoidregulatory compliance
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements dynamic data protection where the encryption state of data changes based on processing requirements and compliance needs. Data can be temporarily decrypted when processing is required, then automatically re-encrypted when not in use. This dynamic approach allows operational flexibility during processing while ensuring compliance during storage and transmission.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent applies periodic action through repeated encryption and decryption cycles that occur only when necessary for processing. Data are encrypted during storage, temporarily decrypted for specific processing operations, then re-encrypted afterward. This periodic pattern ensures data remain protected most of the time while allowing processing when needed, maintaining both flexibility and compliance.

Inventive Principle:
Principle #19Periodic action

4Reliability

If cloud service providers assist with compliance certification, then data protection reliability is improved, but operational complexity and continuous investment requirements increase

Engineering Contradiction:
Improvecompliance certificationVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service compliance through automated encryption management within the cloud system itself. The encryption and decryption operations are performed automatically by the system based on predefined policies and data sensitivity markers, reducing the need for manual compliance management and external certification assistance. This automation simplifies the compliance process while maintaining high reliability.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10831912B2In a data processing system environment performing an operation on sensitive data
Publication Date: 2020.11.10 KYNDRYL INC
  • US10831912B2 patent drawing
  • US10831912B2 patent drawing
  • US10831912B2 patent drawing

AI summary

A method and system for performing an operation on protected sensitive data. A processor of a data processing system receives, from a computing system: (i) the protected sensitive data, (ii) an identification of an operation that accesses and utilizes the protected sensitive data during performance of the operation, and (iii) a request to perform the operation, wherein the computing system is external to the data processing system. The processor de-protects the received protected sensitive data, which generates unprotected sensitive data from the protected sensitive data. The processor performs the operation, which includes accessing and utilizing the unprotected sensitive data and generating a result. After the operation is performed, the processor re-protects the unprotected sensitive data, which restores the protected sensitive data. The processor sends the result to the computing system.