Dynamic Data Masking (DDM)

Protection of DB and file PII during runtime

Dynamic Data Masking

In dynamic data masking (DDM), or data masking in transit, data is masked only at the display level in applications that are connected to a database or file (where it remains unchanged). A DDM solution prevents unauthorized users from seeing the original plaintext values in columns.

Compare this to real-time data masking, where source data values are modified in a single RDB via SQL triggers, or where values are masked as they move from source to destination as source values change. Dynamic data masking also differs from static data masking (SDM), which protects data at rest, whether in sources typically used in highly secure production environments or in lower environments where data is anonymized for development, testing, or analysis.

The best data masking tools allow all three operating modes and offer multiple options to cover different use cases.

The IRI FieldShield Data masking package for relational databases and flat files, which IRI DarkShield Package for semi- and unstructured text files, PDF / MS documents, images, and NoSQL – or the IRI Voracity platform, both of which and many Related functions includes – can offer you dynamic data masking and protection in a variety of ways:

Embed IRI FieldShield features via .NET or JavaSDK-Calls library functions from applications to encrypt, decrypt, hack, or redact. Or call a DarkShield text, file, RDB, or NoSQL DBRPC-API from your application (in Python, PowerShell, Java, etc.) for RESTful search and masking services. 

In 2025, IRI will launch new middleware leveraging RI DarkShield APIs to analyze logged-in users in relational and NoSQL databases and mask classes of sensitive data based on RBAC settings.

You can feed your own data feeds and formats to/from FieldShield static data masking jobs into storage by using input or output routines written in C. Your routine would address RBAC logic and allow you to leverage FieldShield’s capabilities for data classification, discovery, masking, re-ID risk assessment, quasi-anonymization, and audit reporting.

Redirect, mask, and virtualize/feed PII from pipes, URLs, and MQTT or Kafka topics, i.e., mask data for recipients on the fly, streaming from a dynamic source.

Regardless of which dynamic data masking tool or option you choose above, you can with IRI Professional Services collaborate to get a customized implementation for your use case.