On-the-fly Web Application Data Anonymization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current performance testing methods for web applications cannot effectively use production data due to confidentiality concerns, leading to complex and time-consuming dataset creation and long response times, while existing solutions for data anonymization do not guarantee confidentiality and result in overhead.
Innovation Solution
A method for on-the-fly anonymization of production data, where sensitive data is identified and encoded in real-time as it is transmitted, ensuring confidentiality and maintaining data consistency for performance testing, using a processing unit with a sensitive data identification repository and an anonymization repository.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If production data is used for performance testing, then test accuracy and relevance are improved, but data confidentiality is compromised
Solution Approach 1:
The patent introduces an intermediary anonymization layer between production data and performance testing. This intermediary process transforms sensitive production data into anonymized test data while preserving the structural and functional characteristics needed for accurate performance testing, thus resolving the conflict between test accuracy and data confidentiality
Solution Approach 2:
The patent creates anonymized copies of production data that retain the necessary characteristics for performance testing while removing sensitive information. These copies serve as substitutes for original production data, enabling accurate testing without exposing confidential information
2Object-affected harmful factors
If test dataset is created to ensure data confidentiality, then data security is improved, but test preparation time and complexity increase
Solution Approach 1:
The patent implements preliminary anonymization of production data to create a reusable anonymized dataset. This preliminary action eliminates the need for repeated anonymization processes during different testing phases, significantly reducing test preparation time while maintaining data security
Solution Approach 2:
The patent transforms production data by changing specific parameters (anonymizing sensitive fields) while preserving other parameters (structural relationships, data types, patterns). This selective parameter transformation enables efficient dataset creation that balances security requirements with testing needs
3Object-affected harmful factors
If existing anonymization solutions are applied, then data confidentiality is partially improved, but response time increases due to overhead
Solution Approach 1:
The patent applies partial anonymization by selectively anonymizing only the sensitive portions of data that require protection, while leaving non-sensitive data unchanged. This partial action approach reduces processing overhead and improves response time compared to complete anonymization, while still achieving the necessary confidentiality protection
Data Source
AI summary
The invention relates to a device and a method for analyzing performances of a web application capable of performing a process of on-the-fly anonymization (400) of production data, said production data being generated following a benchmark request message (MR1, MR2′) transmitted to said web application, said anonymization process (400) being carried out by a first electronic communication device (10) capable ofIdentifying, from a sensitive data identification repository (14), data to be anonymized in the response message (MRR1, MRR2);Generating, from an anonymization repository (15), anonymized data from previously identified data to be anonymized; andGenerating, from the anonymized data and from the response message (MRR2), an anonymized response message (MRR2′).


