Sensitive Personal Information Masking via Extraction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Data storage systems often fail to adequately safeguard sensitive personal information, leading to potential data breaches and corporate liability due to exposure of such information in unauthorized internal or external views.

Innovation Solution

A system that replaces sensitive personal information with generated mask identifiers, using an encryption platform to extract and secure sensitive data, allowing its use only when necessary, while maintaining privacy by masking it from unauthorized users.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If sensitive personal information is stored in database tables and displayed in user interfaces, then data accessibility and operational functionality are improved, but data security and privacy protection deteriorate

Engineering Contradiction:
Improvedata accessibilityVSAvoiddata exposure risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts sensitive personal information from the main database tables and user interfaces, separating it into a secure vault. This extraction eliminates the exposure risk while preserving operational functionality, as the vaulted data can still be accessed when necessary through controlled processes.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a vault as an intermediary layer between the operational system and sensitive data. This intermediary enables controlled access to sensitive information only when business needs arise, preventing unauthorized exposure while maintaining data accessibility for legitimate operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If sensitive personal information is masked from unauthorized users, then data privacy protection is improved, but data utility for legitimate tasks deteriorates

Engineering Contradiction:
Improvedata privacy protectionVSAvoiddata utility
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic data masking where sensitive information is masked by default but can be unmasked temporarily when business needs arise. This dynamic approach ensures data privacy protection while maintaining data utility for legitimate tasks, as the masking state can change based on operational requirements.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent performs preliminary vaulting of sensitive data before it is needed for operations. This preliminary action prepares the data for both protection and future utility, allowing the system to quickly unmask and use the data when legitimate tasks require it, without compromising privacy during normal operations.

Inventive Principle:
Principle #10Preliminary action

3Device complexity

If data storage systems predate or fail to account for regulations, then system simplicity and legacy compatibility are maintained, but compliance with data protection regulations deteriorates

Engineering Contradiction:
Improvesystem simplicityVSAvoidregulatory compliance
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments the data storage system into two distinct parts: the existing operational database and the new secure vault. This segmentation allows the legacy system to remain simple and unchanged while the vault handles regulatory compliance requirements, thus maintaining system simplicity while achieving compliance.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a copy of sensitive data structures in the vault that mirrors the operational database. This copying approach allows the vault to implement compliance measures without altering the original legacy system, maintaining simplicity while ensuring regulatory compliance through the compliant vault structure.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS9122880B2Sensitive personal information data protection
Publication Date: 2015.09.01 CELLCO PARTNERSHIP INC
  • US9122880B2 patent drawing
  • US9122880B2 patent drawing
  • US9122880B2 patent drawing

AI summary

A computing device may be configured to provide operations related to providing additional security for sensitive personal information (SPI) in data records of an enterprise. The SPI is extract from the data records and mask sequence values associated with the SPI are generated. A master translation table is updated with the association of the mask sequence values to the entries of SPI and the mask sequence values are merged into the data records to be used in place of the SPI to safeguard the SPI. The table containing the mask sequence values is stored separately.