Obfuscation of content based upon context of and pattern of data within the content
A system, method, and program product are presented for causing a processor of a computing device to receive content, determine a context of the content, and when the determined context is relevant for obfuscation, scan the content to identify information that matches, within the context, one of a plurality of data patterns indicative of being sensitive information. The processor further executes to assign a confidence value to the identifying process. When the sensitive information is identified with the confidence value above a confidence threshold, the processor executes to generate an obfuscated version of the sensitive information within the content, replace the sensitive information with the obfuscated version to form updated content, and output the updated content. The context may include at least one of a feature or a subject, a manner of use, and/or a determination of a user accessing, transmitting, or receiving the received content.
1 . A computer program product comprising a non-transitory computer readable storage medium having a computer readable program stored therein, wherein the computer readable program, when executed on a computing device, causes the computing device to operate to:
receive content;
determine a context of the received content, wherein the computing device is configured to determine the context by a subject of the received content and a manner of use of the received content by the computing device including an action to be performed with the received content unrelated to whether the received content is obfuscated when output;
wherein when the determined context of the received content is relevant for obfuscation, scan the received content to identify information therein that matches, within the determined context, one of a plurality of data patterns indicative of the information being sensitive information;
assign a confidence value to the identifying of sensitive information; and
wherein when the scanned content includes sensitive information identified with the assigned confidence value at or above one of a plurality of predetermined confidence thresholds defining an acceptable match, the computer readable program executes to cause the computing device to:
generate an obfuscated version of the identified sensitive information within the received content;
replace the identified sensitive information with the obfuscated version of the identified sensitive information within the received content to form updated content; and
output the updated content;
wherein the plurality of predetermined confidence thresholds defining the acceptable match include a first confidence threshold and a second confidence threshold below the first confidence threshold, wherein when the assigned confidence value is at or above the first confidence threshold the computer readable program further executes to cause the computing device to automatically generate and to store a new one of the plurality of data patterns as one of a plurality of learned data patterns; and
wherein when the assigned confidence value is at or above the second confidence threshold and below the first confidence threshold, the computer readable program further executes to cause the computing device to automatically generate a proposed new one of the plurality of data patterns as one of the plurality of learned data patterns subject to review and approval.
2 . The computer program product of claim 1 , wherein the context further includes a feature of the received content.
3 . The computer program product of claim 2 , wherein the feature is indicative of a relationship of the received content to one or more persons and entities.
4 . The computer program product of claim 3 , wherein the feature and the relationship of the received content are indicative of at least one of personally identifiable information, biometric information, financial information, health information, authentication credential information, encryption key and certificate information, or location information.
5 . The computer program product of claim 1 , wherein the manner of use of the received content by the computing device that defines the context is the action including at least one of use within a confidential communication, within a confidential storage of the information, within a legal proceeding, within an educational record, within a governmental record, use of business systems data including the sensitive information in a programming development environment, or use to determine a pattern of behavior of an individual operating the computer device.
6 . The computer program product of claim 1 , wherein the computer readable program further causes the computing device to operate to store a value in a context type field to identify the determined context of the content being processed by the computing device.
7 . The computer program product of claim 1 , wherein the plurality of data patterns is each definable in one of a plurality of template formats.
8 . The computer program product of claim 7 , wherein the plurality of template formats includes user definable template formats.
9 . The computer program product of claim 7 , wherein the plurality of template formats includes template formats automatically defined by the computing device based upon a relationship of information within the received content.
10 . The computer program product of claim 9 , wherein the relationship of information includes at least one of a detected variation within the content from the template format or a learned data pattern derived from one or more machine-learning algorithms that draw inferences from patterns of data within the received content.
11 . The computer program product of claim 1 , wherein the plurality of data patterns includes at least one of a date format, an address format, a social security number format, a financial account number format, an insurance policy number format, a credit card number format, an electronic mail address format, a phone number format, agender format, a race format, or a healthcare data format.
12 . The computer program product of claim 1 , wherein the obfuscated version of the identified sensitive information is selectively un-obfuscated by the computing device.
13 . The computer program product of claim 1 , wherein the updated content includes the obfuscated version of the identified sensitive information and un-obfuscated information.
14 . The computer program product of claim 1 , wherein the computing device generates the obfuscated version of the identified sensitive information by at least one of anonymizing, encrypting, hashing, or masking the identified sensitive information within the received content.
15 . The computer program product of claim 1 , wherein the computing device is operatively coupled to a display device, and wherein the computer readable program further includes display instructions that when executed on the computing device cause the computing device to:
when the updated content is outputted, un-obfuscate the obfuscated version of the identified sensitive information within the outputted updated content; and
exhibit the output updated content with the un-obfuscated sensitive information on the display device.
16 . The computer program product of claim 15 , wherein the display instructions are executable by a predetermined subset of operators of the computing device.
17 . The computer program product of claim 16 , wherein the computer readable program further includes audit instructions that when executed on the computing device cause the computing device to record at least one of a date, a time, or a respective one of the predetermined subset of operators that retrieved the updated content and was presented with the updated content exhibited on the display device.