US2017083722A1PendingUtilityA1

Dynamic data masking system and method

Assignee: HEXATIER LTDPriority: Feb 21, 2012Filed: Apr 10, 2016Published: Mar 23, 2017
Est. expiryFeb 21, 2032(~5.6 yrs left)· nominal 20-yr term from priority
Inventors:David Maman
G06F 21/6218G06F 16/24G06F 16/25G06F 16/2443G06F 21/6227G06F 17/30415G06F 17/30557
40
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A system and method for providing dynamic data masking for databases through a data masking apparatus.

Claims

exact text as granted — not AI-modified
1 . A system for providing data masking comprising:
 a) a database operated by computational hardware;   b) an accessing application operated by a computer;   c) a data masking apparatus operated by a computer for handling requests between said accessing application and said database; for retrieving at least one stored procedure from said database, for analyzing said stored procedure to determine whether a sensitive field is present; wherein when said sensitive field is present, for changing said stored procedure to mask said sensitive field according to dynamic data masking; for storing said changed procedure is stored in said database.   
     
     
         2 . The system of  claim 1 , wherein when receiving a request for a stored procedure from said accessing application; said apparatus executes said changed procedure at said database; and wherein said apparatus provides a result of said executing to said accessing application. 
     
     
         3 . The system of  claim 2 , wherein said database comprises a plurality of databases and said accessing application comprises a plurality of accessing applications, said data masking apparatus further comprising a plurality of query interfaces for communicating with said accessing applications and a plurality of database connection interfaces for communicating with said databases, such that said retrieving is performed through said database connection interface and said providing said result is performed through said query interface. 
     
     
         4 . The system of  claim 3 , wherein said stored procedure has a previous name, such that said storing said changed procedure in said database comprises storing said changed procedure under a new name, while maintaining said stored procedure under said previous name. 
     
     
         5 . The system of  claim 3 , wherein said stored procedure has a previous name, such that said storing said changed procedure in said database comprises storing said changed procedure under said previous name. 
     
     
         6 . A system for providing data masking comprising:
 a. a database operated by computational hardware;   b. an accessing application operated by a computer;   c. a data masking apparatus operated by a computer comprising a procedure analyzer for handling requests between the accessing applications and the databases; for retrieving at least one stored procedure from said database prior to receiving a request from said accessing application; for analyzing said stored procedure to determine whether a sensitive field is present; when said sensitive field is present, for changing said stored procedure to mask said sensitive field according to dynamic data masking; for storing said changed stored procedure in said database; wherein when said apparatus receives a request for the stored procedure from said accessing application; for executing said changed stored procedure at said database; and for providing a result of said executing to said accessing application;   
       wherein said analyzing said stored procedure comprises: decomposing said stored procedure to detect each field; and determining a sensitiveness category for each field;
 wherein for a field involving a variable that is dependent upon a prior result, categorizing said dependent field by said analyzer as potentially sensitive, and further analyzing said potentially sensitive field by said procedure analyzer at run time. 
 
     
     
         7 . The system of  claim 6 , wherein said database comprises a plurality of databases and said accessing application comprises a plurality of accessing applications, said data masking apparatus further comprising a plurality of query interfaces for communicating with said accessing applications and a plurality of database connection interfaces for communicating with said databases, such that said retrieving is performed through said database connection interface and said providing said result is performed through said query interface. 
     
     
         8 . The system of  claim 7 , wherein said stored procedure has a previous name, such that said storing said changed procedure in said database comprises storing said changed procedure under a new name, while maintaining said stored procedure under said previous name. 
     
     
         9 . The system of  claim 7 , wherein said stored procedure has a previous name, such that said storing said changed procedure in said database comprises storing said changed procedure under said previous name. 
     
     
         10 . A method for providing data masking in a system having a database operated by computational hardware and an accessing application operated by a computer, the method comprising:
 a. providing a data masking apparatus comprising a procedure analyzer for handling requests between the accessing applications and the databases, wherein said apparatus is operated by a computer;   b. retrieving at least one stored procedure from said database by said data masking apparatus prior to receiving a request from an accessing application;   c. analyzing said stored procedure by said procedure analyzer to determine whether a sensitive field is present; wherein said analyzing for said stored procedure comprises: decomposing said stored procedure to detect each field; and determining a sensitiveness category for each field; wherein for a field involving a variable that is dependent upon a prior result, categorizing said dependent field by said analyzer as potentially sensitive, and further analyzing said potentially sensitive field by said procedure analyzer at run time;   d. wherein when said sensitive field is present, changing said stored procedure by said procedure analyzer to mask said sensitive field according to dynamic data masking;   e. storing said changed stored procedure in said database by said procedure analyzer; and   f. by said data masking apparatus, receiving the request for the stored procedure from said accessing application; executing said changed stored procedure at said database; and providing a result of said executing to said accessing application;   
       wherein said data masking apparatus further comprises a translator and wherein said translator translates said requests and said results. 
     
     
         11 . A method for providing data masking in a system having a database operated by computational hardware and an accessing application operated by a computer, the method comprising:
 a. providing a data masking apparatus comprising a procedure analyzer for handling requests between the accessing applications and the databases, wherein said apparatus is operated by a computer;   b. retrieving at least one stored procedure from said database by said data masking apparatus prior to receiving a request from an accessing application;   c. analyzing said stored procedure by said procedure analyzer to determine whether a sensitive field is present; wherein said analyzing for said stored procedure comprises: decomposing said stored procedure to detect each field; and determining a sensitiveness category for each field; wherein for a field involving a variable that is dependent upon a prior result, categorizing said dependent field by said analyzer as potentially sensitive, and further analyzing said potentially sensitive field by said procedure analyzer at run time;   d. wherein when said sensitive field is present, changing said stored procedure by said procedure analyzer to mask said sensitive field according to dynamic data masking;   e. storing said changed stored procedure in said database by said procedure analyzer; and   f. by said data masking apparatus, receiving the request for the stored procedure from said accessing application; executing said changed stored procedure at said database; and providing a result of said executing to said accessing application;   
       wherein said data masking apparatus further comprises a caching module and wherein said caching module temporarily stores said request and said result. 
     
     
         12 . A method for providing data masking in a system having a database operated by computational hardware and an accessing application operated by a computer, the method comprising:
 a. providing a data masking apparatus comprising:
 a. a data masking module 
 b. a procedure analyzer for handling requests between the accessing applications and the databases, 
 wherein said apparatus is operated by a computer; 
   b. retrieving at least one stored procedure from said database by said data masking module prior to receiving a request from an accessing application;   c. analyzing said stored procedure by said procedure analyzer to determine whether a sensitive field is present; and   d. when said stored procedure is queried by said accessing application performing data masking of said sensitive fields by said procedure analyzer before providing the result to said accessing application.   
     
     
         13 . The method of  claim 12 , wherein said database comprises a plurality of databases and said accessing application comprises a plurality of accessing applications, said data masking apparatus further comprising a plurality of query interfaces for communicating with said accessing applications and a plurality of database connection interfaces for communicating with said databases, such that said retrieving is performed through said database connection interface and said providing said result is performed through said query interface.

Join the waitlist — get patent alerts

Track US2017083722A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.