IP Library Granted Patent US 12,026,280
Granted Patent B2
US 12,026,280 · App. 17/164,056 · Granted Jul 2, 2024

Automated data anonymization

Inventors: Gyana Ranjan Dash (San Jose, CA); Antonio Nucci (San Jose, CA); Donald Mark Allen (Colorado Springs, CO); Kabeer Noorudeen (Artarmon, AU); Tatiana Alexandrovna Gaponova (Moscow, RU); Konstantin Grechishchev (Moscow, RU)
Assignee: Cisco Technology, Inc.
G06F21/6254G06F21/604H04L41/0813
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,026,280
App. No.
17/164,056
Granted
Jul 2, 2024
Kind
B2
Abstract

In one example embodiment, a server that is in communication with a network that includes a plurality of network elements obtains, from the network, a service request record that includes sensitive information related to at least one of the plurality of network elements. The server parses the service request record to determine that the service request record includes a sequence of characters that is repeated in the service request record, and tags the sequence of characters as a particular sensitive information type. Based on the tagging, the server identically replaces the sequence of characters so as to preserve an internal consistency of the service request record. After identically replacing the sequence of characters, the server publishes the service request record for analysis without revealing the sequence of characters.

Claims (67)

1. A method comprising:

at a server that is in communication with a network that includes a plurality of network elements:

obtaining, from the network, information related to at least one of the plurality of network elements;

parsing the information to identify a first occurrence of a sequence of characters and a second occurrence of the sequence of characters included in the information;

determining, by a process running on the server, that a first tagging algorithm identifies the sequence of characters as being of a first information type;

determining that a second tagging algorithm identifies the sequence of characters as being of second information type, the second information type being different than the first information type;

selecting the first information type rather than the second information type;

tagging the sequence of characters with a tag indicating that the sequence of characters is of the first information type;

based on the tag indicating that the sequence of characters is of the first information type, replacing each of the first and second occurrences of the sequence of characters with replacement characters that are in a format corresponding to the information such that a structure of the information is semantically maintained; and

subsequent to replacing each of the first and second occurrences of the sequence of characters with the replacement characters, publishing the information for analysis without publishing the sequence of characters.

2. The method of claim 1 , wherein the tagging includes:

tagging the first occurrence of the sequence of characters based on the structure of the information.

3. The method of claim 2 , wherein the tagging further includes:

in response to tagging the first occurrence of the sequence of characters, tagging the second occurrence of the sequence of characters in an unstructured portion of the information.

4. The method of claim 1 , wherein the first information type is one information type of a plurality of information types.

5. The method of claim 4 , further comprising:

mapping a plurality of replacement rules to the plurality of information types; and

identifying a particular replacement rule mapped to the first information type; and

determining that the particular replacement rule indicates that each of the first and second occurrences of the sequence of characters are to be replaced with a same replacement characters.

6. The method of claim 1 , further comprising:

processing the information to determine one or more changes to be made to a configuration of the at least one of the plurality of network elements.

7. An apparatus comprising:

a network interface configured to obtain, from a network that includes a plurality of network elements, information related to at least one of the plurality of network elements;

one or more non-transitory computer-readable media storing computer-executable instructions; and

one or more hardware processors coupled to the network interface, wherein the one or more processors are configured to execute the computer-executable instructions to:

parse the information to identify a first occurrence of a sequence of characters and a second occurrence of the sequence of characters included in the information;

determine, by a process running on a server, that a first tagging algorithm identifies the sequence of characters as being of a first information type;

determine that a second tagging algorithm identifies the sequence of characters as being of second information type, the second information type being different than the first information type;

select the first information type rather than

the second information type;

tag the sequence of characters with a tag indicating the sequence of characters is of the first information type;

based on the tag indicating that the sequence of characters is of the first information type, replace each of the first and second occurrences of the sequence of characters with replacement characters that are in a format corresponding to the information such that a structure of the information is semantically maintained; and

subsequent to replacing each of the first and second occurrences of the sequence of characters with replacement characters, publishing the information for analysis without publishing the sequence of characters.

8. The apparatus of claim 7 , wherein the one or more hardware processors are configured to tag the sequence of characters by:

tagging the first occurrence of the sequence of characters based on a structure of the information.

9. The apparatus of claim 8 , wherein the one or more hardware processors are further configured to tag the sequence of characters by:

in response to tagging the first occurrence of the sequence of characters, tagging the second occurrence of the sequence of characters in an unstructured portion of the information.

10. The apparatus of claim 7 , wherein the first information type is one information type of a plurality of information types.

11. The apparatus of claim 10 , wherein the one or more hardware processors are configured to:

map a plurality of replacement rules to the plurality of information types;

identify a particular replacement rule mapped to the sensitive first information type; and

determine that the particular replacement rule indicates that each of the first and second occurrences of the sequence of characters are to be replaced with a same replacement characters.

12. The apparatus of claim 7 , wherein the one or more hardware processors are configured to:

process the information to determine one or more changes to be made to a configuration of the at least one of the plurality of network elements.

13. The apparatus of claim 7 , wherein

the information for analysis without revealing the sequence of characters includes sending the information to a third-party resolution system configured to analyze the information.

14. One or more non-transitory computer readable storage media encoded with instructions that, when executed by a processor of a server that is in communication with a network that includes a plurality of network elements, cause the processor to:

obtain, from the network, information related to at least one of the plurality of network elements;

parse the information to identify a first occurrence of a sequence of characters and a second occurrence of the sequence of characters included in the information;

determining, by a process running on the server, that a first tagging algorithm identifies the sequence of characters as being of a first information type;

determining that a second tagging algorithm identifies the sequence of characters as being of second information type, the second information type being different than the first information type;

selecting the first information type rather than the second information type;

tagging the sequence of characters with a tag indicating that the sequence of characters is of the first information type;

based on the tag indicating that the sequence of characters is of the first information type, replace each of the first and second occurrences of the sequence of characters with replacement characters that are in a format corresponding to the information such that a structure of the information is semantically maintained; and

subsequent to replacing each of the first and second occurrences of the sequence of characters with replacement characters, publishing the information for analysis without publishing the sequence of characters.

15. The one or more non-transitory computer readable storage media of claim 14 , wherein the instructions that cause the processor to tag include instructions that cause the processor to:

tag the first occurrence of the sequence of characters based on a structure of the information.

16. The one or more non-transitory computer readable storage media of claim 15 , wherein the instructions that cause the processor to tag include instructions that cause the processor to:

in response to tagging the first occurrence of the sequence of characters, tag the second occurrence of the sequence of characters in an unstructured portion of the information.

17. The one or more non-transitory computer readable storage media of claim 14 , wherein the first information type is one information type of a plurality of information types, wherein the instructions further cause the processor to:

map a plurality of replacement rules to the plurality of the information types;

identify a particular replacement rule mapped to the first information type; and

determine that the particular replacement rule indicates that each of the first and second occurrences of the sequence of characters are to be replaced with a same replacement characters.

18. The one or more non-transitory computer readable storage media of claim 14 , wherein the instructions further cause the processor to:

process the information to determine one or more changes to be made to a configuration of the at least one of the plurality of network elements.

19. The one or more non-transitory computer readable storage media of claim 14 , wherein

the information for analysis without revealing the sequence of characters includes sending the information to a third-party resolution system configured to analyze the information.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 1, 2021
From: DASH, GYANA RANJAN; NUCCI, ANTONIO; ALLEN, DONALD MARK; NOORUDEEN, KABEER; GAPONOVA, TATIANA ALEXANDROVNA; GRECHISHCHEV, KONSTANTIN
To: CISCO TECHNOLOGY, INC.
Reel/Frame 055099/0015 →
Continuity (2)
Continuation 15964876 · Apr 27, 2018
Related Publication 20210150060A1 · May 20, 2021
Cited By (1)
US 12,333,236