ASCII character encryption

Another IRI de/re-identification function

Challenges

You must remove personally identifiable features from data. At the same time, this data must be anonymized so that it can flow securely through different departments and be re-identified if necessary.

De-identified data should also correspond to the original format. Its length, data type, or even a realistic but different value will be needed for ongoing operations and testing. The Field encryption does not reach this goal when the ciphertext length exceeds the original field length and data realism is lost. Format-Preserving Encryption (FPE) Conversely, it can be a desirable option, but in some cases, it can also be excessive or time-consuming.

Solutions

The data masking product IRI FieldShield and the data management platform IRI Voracity, which also includes FieldShield) has many features for masking static data, including the ability to „roll“ your own data. Built-in features for de-identifying ASCII data include a character-level scramble or substitute routine called ASCII de-ID. You can use this less secure data encryption feature when speed is critical and you simply want to obscure the column value in a unique and reversible way.

ASCII De-ID: One of several data masking dialogs in the IRI Workbench GUI for FieldShield, built on Eclipse.™

Like the other field-level de-identification techniques in FieldShield, this function can be applied to less sensitive, but perhaps quasi-identifying data to help you comply with data privacy regulations while keeping your non-sensitive data available for further processing. The use of this function, like all others, will be recorded in FieldShield's XML audit log to ensure regulatory compliance.

See the other features listed in this section if you are looking for other ways to identify data. See the HIPAA Page for PHI de-identification and the possibilities for dynamic data masking.

If you need secure, realistic test data, use FieldShield-compatible IRI RowGen-software in the IRI Data Protection Suite, to create test databases, files, and report targets.