Source Device Data Scanning and Masking for Federated Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data masking technologies face challenges in efficiently and securely handling large volumes of sensitive data across multiple destination devices due to centralized architectures that are vulnerable to data breaches and resource constraints, and localized solutions are often incompatible with different configurations.

Innovation Solution

A federated architecture that enables scanning and masking of data at the source device using masking configurations and code modules, allowing each application server to perform scanning and masking operations locally, ensuring data security and compatibility with various destination devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If centralized architecture is used for data masking, then data security is improved through centralized control, but system reliability deteriorates due to vulnerability to data breaches and resource constraints

Engineering Contradiction:
Improvedata securityVSAvoidcentralized architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the centralized data masking function into distributed segments at each source device. Each source device performs scanning and masking locally based on received masking configurations, eliminating the single point of failure in centralized architecture while maintaining security through distributed execution of masking operations.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Source devices perform self-service by autonomously scanning and masking their own data using masking configurations received from a management server. This eliminates dependency on centralized processing, improving reliability while reducing the complexity burden on any single centralized system.

Inventive Principle:
Principle #25Self-service

2Reliability

If localized data masking solution is implemented, then system reliability is improved by reducing centralized vulnerability, but adaptability deteriorates due to incompatibility with different destination configurations

Engineering Contradiction:
Improvesystem reliabilityVSAvoidcompatibility with destination configurations
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements a universal masking configuration system where a single management server provides configurations applicable to multiple destination devices with different requirements. The masking configurations are designed to be universally applicable, allowing one set of rules to serve multiple destinations while maintaining compatibility with diverse destination configurations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The management server receives feedback about destination device configurations and uses this information to generate appropriate masking configurations. This feedback mechanism ensures that localized masking solutions remain adaptable to different destination requirements while maintaining system reliability through distributed execution.

Inventive Principle:
Principle #23Feedback

3Reliability

If data scanning and masking is performed at source device, then data security is enhanced by preventing unauthorized disclosures, but computational resource consumption increases

Engineering Contradiction:
Improvedata securityVSAvoidcomputational resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent applies partial action by performing scanning and masking only on data that contains sensitive information, rather than processing all data uniformly. The system scans data for sensitive patterns and applies masking only where needed, reducing unnecessary computational resource consumption while maintaining enhanced security where sensitive data is present.

Inventive Principle:
Principle #16Partial or excessive action

4Reliability

If data masking is applied to all data, then data security is improved, but productivity deteriorates due to processing overhead on large data volumes

Engineering Contradiction:
Improvedata securityVSAvoiddata processing efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs partial masking action by scanning data first to identify sensitive information patterns, then applying masking only to portions of data that contain sensitive information. This selective approach maintains security for sensitive data while improving overall processing efficiency by avoiding unnecessary masking operations on non-sensitive data.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent implements preliminary scanning action before masking by first scanning data to identify sensitive information patterns. This preliminary action allows the system to plan and execute masking operations more efficiently, processing only the necessary portions of data and reducing overall processing overhead while maintaining comprehensive security.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12380241B2Scanning and masking data at a source device
Publication Date: 2025.08.05 CAPITAL ONE SERVICES LLC
  • US12380241B2 patent drawing
  • US12380241B2 patent drawing
  • US12380241B2 patent drawing

AI summary

In some implementations, an application server may receive an indication of one or more masking rules for identifying sensitive data at the application server. The application server may generate data that includes information associated with an application of the application server, where the data is associated with one or more destination devices. The application server may process the data based on the one or more masking rules to identify sensitive data included in the data, where processing the data includes masking any sensitive data included in the data to obtain masked data. The application server may generate output data that includes the data and the masked data in a first data format associated with a first destination device of the one or more destination devices. The application server may transmit, to the first destination device, the output data in the first data format.