Vault-Based Sensitive Data Protection in Communications

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing digital communication systems fail to protect sensitive data after it reaches the intended recipient, as they decrypt communications, making the data vulnerable to unauthorized access.

Innovation Solution

A method where sensitive information is identified and replaced with reference tags or placeholders, stored in a vault, and only accessible to authorized recipients, ensuring data protection by using a vault system that manages access and encryption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If communications are encrypted in transit using SSL/TLS, then data protection during transmission is improved, but data becomes vulnerable after decryption at the destination

Engineering Contradiction:
Improvedata protection during transmissionVSAvoidunauthorized access at destination
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the sensitive data from the communication content and stores it separately in a secure vault. The communication contains only a reference token, while the actual sensitive data is removed and stored in a protected environment, preventing unauthorized access even if the communication is compromised at the destination.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a vault as an intermediary component between the communication system and the sensitive data. The vault acts as a mediator that stores the sensitive data securely and provides controlled access, separating the communication flow from the actual data storage and access control.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If sensitive data is stored in a vault with access control, then data security is improved, but system complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidvault system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses reference tokens or placeholders that copy only the essential identifying information needed for access, rather than storing or transmitting the complete sensitive data. These reference tokens serve as simplified representations that maintain security while reducing the complexity of data management in the vault.

Inventive Principle:
Principle #26Copying

3Object-affected harmful factors

If data is replaced with reference tags, then unauthorized access is prevented, but data usability for authorized recipients may be affected

Engineering Contradiction:
Improveunauthorized access preventionVSAvoiddata usability
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The vault serves as an intermediary that resolves reference tokens into actual sensitive data for authorized recipients. This mediator approach maintains security by keeping data in token form during transmission, while ensuring usability by automatically providing the actual data to authorized users through the vault's controlled access mechanism.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9177174B1Systems and methods for protecting sensitive data in communications
Publication Date: 2015.11.03 GOOGLE LLC
  • US9177174B1 patent drawing
  • US9177174B1 patent drawing
  • US9177174B1 patent drawing

AI summary

Systems and methods for protecting sensitive data in communications are described, including identifying first information in content created by a user for a communication; sending the first information to a vault; receiving, from the vault, an identifier associated with the first information; replacing the first information in the content with second information that is associated with the first information and does not provide any indication of the content of the first information; and sending the communication comprising the content with the second information and the identifier.