Automated detection of protected field manipulation in support of joint search
By monitoring and configuring cloud-based applications through data security providers, identifying protected fields and performing corresponding actions, the issues of data security and confidentiality in the cloud environment are resolved, and regulatory compliance and convenience are achieved for secure storage and processing of data in the cloud.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- ORACLE INT CORP
- Filing Date
- 2016-10-21
- Publication Date
- 2026-05-05
AI Technical Summary
Existing technologies face data security and confidentiality issues when using public cloud storage and processing, especially when transmitting data across borders and accessing government data. They are difficult to meet regulatory requirements such as HIPAA and PCI DSS, and tokenization methods are limited in application in cloud environments.
By monitoring communication between cloud-based applications and client devices through data security providers, protected fields can be identified and corresponding actions configured to enable automatic operation detection and tokenization of data models, and federated search can be supported to ensure data security and confidentiality.
It enables secure storage and processing of data in a cloud environment, meets regulatory requirements, reduces the risk of data leakage, and improves the convenience and security of data use in the cloud.
Smart Images

Figure CN114491639B_ABST
Abstract
Description
[0001] This application is a divisional application of the invention patent application filed on October 21, 2016, with application number 201680068166.4 and entitled "Automatic Operation Detection of Protected Fields Supporting Joint Search".
[0002] Cross-references to related applications
[0003] This application claims priority and benefit to U.S. Provisional Application No. 62 / 245,608, filed October 23, 2015, entitled “AUTOMATICOPERATION DETECTION ON PROTECTED FIELD”, and U.S. Provisional Application No. 62 / 245,574, filed October 23, 2015, entitled “FEDERATED SEARCH”, the entire contents of which are incorporated herein by reference for all purposes. Background Technology
[0004] There exists a complex web of regulations and policies governing data privacy. The most frequently cited are the Health Insurance Portability and Accountability Act (HIPAA) and the Payment Card Industry Data Security Standard (PCI DSS). European data protection laws often go further, prohibiting the movement of any personally identifiable information outside the European Union (EU) or national borders. This imposes some clear limitations on the unrestricted use of public clouds. Organizations also worry that law enforcement agencies or government officials could potentially access data directly from their cloud service providers, completely bypassing the company.
[0005] For example, European data protection laws prohibit the movement of personal data that can be linked to specific individuals outside the European Union (EU) or even specific national borders. These laws can also prohibit organizations from storing or processing data in the cloud, as infrastructure providers may store, process, or back up data in multiple global locations. In the United States, regulations such as the Health Insurance Portability and Accountability Act (HIPAA) require the security and confidentiality of Personal Health Information (PHI). The complexity of doing so may prevent healthcare providers from using cost-saving public cloud-based solutions that reduce rising healthcare costs.
[0006] One way to address data security, residency, and confidentiality issues is to obfuscate data entering the cloud. Two common obfuscation methods are encryption and tokenization. Using either method ensures that data remains difficult to decipher for eavesdroppers while organizations enjoy the benefits of cloud-based applications. Encryption uses an algorithmic scheme to transform plaintext information into unreadable ciphertext. A key (or algorithm) is needed to decrypt the information and return it to its original plaintext format. Tokenization is an increasingly popular method for protecting sensitive data. Tokenization involves replacing the actual value with a data substitute that has a token (or alias). Unlike encryption, which uses mathematical processing to transform data, tokenization uses random characters to replace the actual data. There is no "key" that can decipher the token and turn it back into the real data.
[0007] In tokenization, sensitive data is sent to a centralized, highly secure server called a "vault," where it is securely stored. Simultaneously, a set of random, unique characters (tokens) is generated and returned to replace the real data. The vault manager maintains a reference database that allows the token value to be exchanged for the real data when it is needed again. Meanwhile, token values that are meaningless to eavesdroppers can be used in various cloud-based applications as a reliable replacement for the real data.
[0008] Merchants often use tokenized data as a substitute for sensitive credit card information after a sale. This allows merchants to perform sales analytics on customer transactions without putting real card data at risk. Furthermore, the PCI prohibits the use of live card data for any purpose other than payment transactions. By tokenizing post-transaction data, merchants can reduce their PCI burden because sensitive data is not present in their back-end systems.
[0009] The same approach can be applied to other types of sensitive data, including patient records, customer account records, and human resources information. Tokenizing real data protects it from harm and addresses requirements for security, residency, and confidentiality. Tokenized data can be stored and used anywhere—even in the cloud—because if tokenized data is lost or stolen, it cannot be converted back to real data. Summary of the Invention
[0010] The following portions of this disclosure present a simplified summary of one or more innovations, embodiments, and / or examples found within this disclosure, at least for the purpose of providing a basic understanding of the subject matter. This disclosure does not attempt to provide an exhaustive overview of any particular embodiment or example. Furthermore, this disclosure is not intended to identify key / determining elements of any embodiment or example or to depict the scope of the subject matter of this disclosure. Accordingly, one purpose of this disclosure may be to present, in a simplified form, some innovations, embodiments, and / or examples found within this disclosure as a prelude to the more detailed description that follows.
[0011] In an exemplary embodiment, a method is provided to be performed by a computing device. The method includes receiving a data model configuration indicating one or more attributes of a data model used by a cloud-based application, such as one protected by a data security provider that monitors communication between the cloud-based application and a client device; using the data model configuration to determine one or more protected fields; determining one or more actions that can be performed using the one or more protected fields; and configuring the cloud-based application based on the one or more actions that can be performed using the one or more protected fields.
[0012] In some embodiments, receiving data model configuration includes receiving information from a data security provider. Optionally, using the data model configuration to determine one or more protected fields includes determining which attributes of the data model have been designated as protected fields. Optionally, determining one or more actions that can be performed using one or more protected fields includes determining supported actions. Optionally, determining one or more actions that can be performed using one or more protected fields includes determining unsupported actions.
[0013] In some embodiments, configuring a cloud-based application based on one or more actions that can be performed using one or more protected fields includes enabling features. Optionally, configuring a cloud-based application based on one or more actions that can be performed using one or more protected fields includes disabling features.
[0014] In an exemplary embodiment, a non-transient machine-readable storage medium having instructions stored thereon is provided, which, when executed by one or more processors, cause the one or more processors to perform a method. The method includes receiving a data model configuration indicating one or more attributes of a data model used by a cloud-based application, such as one protected by a data security provider monitoring communication between the cloud-based application and a client device; using the data model configuration to determine one or more protected fields; determining one or more actions that can be performed using the one or more protected fields; and configuring the cloud-based application based on the one or more actions that can be performed using the one or more protected fields.
[0015] In some embodiments, configuring a cloud-based application based on one or more actions that can be performed using one or more protected fields includes enabling features. Optionally, configuring a cloud-based application based on one or more actions that can be performed using one or more protected fields includes disabling features.
[0016] In some embodiments, configuring a cloud-based application based on one or more actions that can be performed using one or more protected fields includes enabling features. Optionally, configuring a cloud-based application based on one or more actions that can be performed using one or more protected fields includes disabling features.
[0017] In an exemplary embodiment, a system is provided including a processor and a memory storing a set of instructions that, when executed by the processor, cause the processor to perform a method. The method includes receiving a data model configuration indicating one or more attributes of a data model used by a cloud-based application, such as one protected by a data security provider monitoring communication between the cloud-based application and a client device; determining one or more protected fields using the data model configuration; determining one or more actions that can be performed using the one or more protected fields; and configuring the cloud-based application based on the one or more actions that can be performed using the one or more protected fields.
[0018] In some embodiments, configuring a cloud-based application based on one or more actions that can be performed using one or more protected fields includes enabling features. Optionally, configuring a cloud-based application based on one or more actions that can be performed using one or more protected fields includes disabling features.
[0019] In some embodiments, configuring a cloud-based application based on one or more actions that can be performed using one or more protected fields includes enabling features. Optionally, configuring a cloud-based application based on one or more actions that can be performed using one or more protected fields includes disabling features.
[0020] In an exemplary embodiment, a method performed by a computing device is provided. The method includes receiving a first search criterion from a search initiated by a client device for data of a cloud-based application being used by a user of the client device. The first search criterion is determined to be a portion of data applied to a cloud-based application not protected by a data security provider that monitors communications of the client device. The method also includes receiving a first search result based on the data of the cloud-based application performed using the first search criterion; receiving a second search result based on the data of the data security provider performed using a second search criterion; combining the first and second search results into a third search result; and transmitting the third search result to the client device.
[0021] In some embodiments, receiving a second search result based on data from a data security provider performing a second search includes receiving information identifying replacement data used by the data security provider in the data of a cloud-based application. Optionally, receiving a second search result based on data from a data security provider performing a second search includes receiving a set of row keys identifying one or more rows in the data of the cloud-based application. Optionally, combining a first search result and a second search result into a third search result includes filtering the first search result using the second search result. Optionally, combining a first search result and a second search result into a third search result includes merging the first search result and the second search result.
[0022] In some embodiments, transmitting a third search result to a client device includes transmitting one or more tokens from data of a cloud-based application representing data stored by a data security provider that meets the second search criteria. Optionally, transmitting a third search result to a client device includes transmitting one or more encrypted data from data of a cloud-based application representing data stored by a data security provider that meets the second search criteria.
[0023] In an exemplary embodiment, a non-transient machine-readable storage medium having instructions stored thereon is provided, which, when executed by one or more processors, cause one or more processors to perform a method. The method includes receiving a first search criterion from a search initiated by a client device for data of a cloud-based application being used by a user of the client device. The first search criterion is determined to be part of data applied to a cloud-based application not protected by a data security provider that monitors communications of the client device. The method also includes receiving a first search result based on performing the first search on the data of the cloud-based application using the first search criterion; receiving a second search result based on performing a second search on data of the data security provider using a second search criterion; combining the first search result and the second search result into a third search result; and transmitting the third search result to the client device.
[0024] In some embodiments, receiving a second search result based on data from a data security provider performing a second search includes receiving information identifying replacement data used by the data security provider in the data of a cloud-based application. Optionally, receiving a second search result based on data from a data security provider performing a second search includes receiving a set of row keys identifying one or more rows in the data of the cloud-based application. Optionally, combining a first search result and a second search result into a third search result includes filtering the first search result using the second search result. Optionally, combining a first search result and a second search result into a third search result includes merging the first search result and the second search result.
[0025] In some embodiments, transmitting a third search result to a client device includes transmitting one or more tokens from data of a cloud-based application representing data stored by a data security provider that meets the second search criteria. Optionally, transmitting a third search result to a client device includes transmitting one or more encrypted data from data of a cloud-based application representing data stored by a data security provider that meets the second search criteria.
[0026] In an exemplary embodiment, a system is provided including a processor and a memory storing a set of instructions that, when executed by the processor, cause the processor to perform a method. The method includes receiving a first search criterion from a search initiated by a client device for data of a cloud-based application being used by a user of the client device. The first search criterion is determined to be part of data applied to a cloud-based application not protected by a data security provider that monitors communications of the client device. The method also includes receiving a first search result based on the data of the cloud-based application performed using the first search criterion; receiving a second search result based on the data of the data security provider performed using a second search criterion; combining the first and second search results into a third search result; and transmitting the third search result to the client device.
[0027] In some embodiments, receiving a second search result based on data from a data security provider performing a second search includes receiving information identifying replacement data used by the data security provider in the data of a cloud-based application. Optionally, receiving a second search result based on data from a data security provider performing a second search includes receiving a set of row keys identifying one or more rows in the data of the cloud-based application. Optionally, combining a first search result and a second search result into a third search result includes filtering the first search result using the second search result. Optionally, combining a first search result and a second search result into a third search result includes merging the first search result and the second search result.
[0028] In some embodiments, transmitting a third search result to a client device includes transmitting one or more tokens from data of a cloud-based application representing data stored by a data security provider that meets the second search criteria. Optionally, transmitting a third search result to a client device includes transmitting one or more encrypted data from data of a cloud-based application representing data stored by a data security provider that meets the second search criteria.
[0029] In addition to the foregoing, a further understanding of the nature and equivalents of the subject matter of this disclosure (as well as any inherent or explicit advantages and improvements provided) should be achieved by referring to the remainder of this disclosure, any accompanying drawings, and the claims. Attached Figure Description
[0030] Reference may be made to one or more accompanying drawings for the reasonable description and illustration of the innovations, embodiments, and / or examples found within this disclosure. Additional details or examples used to describe one or more drawings should not be considered as a limitation on the scope of the best mode of any claimed invention presented within this disclosure, any currently described embodiments and / or examples, or any innovation as currently understood.
[0031] Figure 1 This is a block diagram of a system environment for developing cloud-based applications according to one embodiment of the present invention.
[0032] Figure 2 This is a block diagram of a system that utilizes cloud-based applications to provide confidentiality, residency, and security, according to one embodiment of the present invention.
[0033] Figure 3A This is an illustration of a user interface (UI) page associated with a cloud-based application when viewed using a client device from within an enterprise infrastructure system, according to one embodiment of the invention.
[0034] Figure 3B This is an illustration of a UI page when viewed from within a cloud infrastructure system, as described in one embodiment of the invention, when the UI page is associated with a cloud-based application.
[0035] Figure 4 This is a block diagram illustrating attributes shared between entities according to an embodiment of the present invention.
[0036] Figure 5 The illustration shows a message sequence diagram of a self-describing configuration that provides a confidentiality, residency, and security server according to one embodiment of the invention.
[0037] Figure 6 The illustration shows a message sequence diagram utilizing a self-describing configuration in one embodiment of the invention.
[0038] Figure 7 This is an illustration depicting the various layers used by a cloud-based application with a self-describing configuration according to an embodiment of the present invention.
[0039] Figure 8 This is a flowchart of a method for supporting the sharing of the same table for encrypted text columns and plaintext text columns, according to one embodiment of the present invention.
[0040] Figure 9 This is a flowchart of a method for automatic operation detection of protected fields according to an embodiment of the present invention.
[0041] Figure 10 This is a flowchart of a method for joint search according to an embodiment of the present invention.
[0042] Figure 11 A simplified diagram of a distributed system for implementing one embodiment of the embodiments is depicted.
[0043] Figure 12 The illustration shows an exemplary computer system in which various embodiments of the present invention can be implemented. Detailed Implementation
[0044] I. Introduction
[0045] In the following description, specific details are set forth for purposes of explanation in order to provide a thorough understanding of embodiments of the invention. However, it will be apparent, however, that various embodiments may be practiced without these specific details. For example, circuits, systems, networks, processes, and other components may be shown as components in block diagram form in order not to obscure the embodiments with unnecessary detail. In other instances, well-known circuits, processes, algorithms, structures, and techniques may be shown without unnecessary detail in order to avoid obscuring the embodiments. The figures and descriptions are not intended to be limiting. Rather, the subsequent description of exemplary embodiments will provide those skilled in the art with an enabling description for implementing the exemplary embodiments. It should be understood that various changes may be made to the arrangement and function of the elements without departing from the spirit and scope of the invention as set forth in the appended claims.
[0046] Furthermore, it should be noted that the various embodiments can be described as processes, which can be depicted as flowcharts, flow diagrams, data flow diagrams, structure diagrams, or block diagrams. While flowcharts can describe operations as sequential processes, many operations can be executed in parallel or concurrently. Moreover, the order of operations can be rearranged. When a process completes its operations, the process terminates, but may have additional steps not included in the diagram. Processes can correspond to methods, functions, procedures, subroutines, subroutines, etc. When a process corresponds to a function, the termination of the process can correspond to the function returning to the calling function or the main function.
[0047] The terms "machine-readable medium" or "computer-readable medium" include, but are not limited to, portable or non-portable storage devices, optical storage devices, wireless channels, and various other media capable of storing, containing, or carrying (one or more) instructions and / or data. Code segments or machine-executable instructions can represent procedures, functions, subroutines, programs, routines, subroutines, modules, software packages, classes, or any combination of instructions, data structures, or program statements. A code segment can be coupled to another code segment or hardware circuit by passing and / or receiving information, data, arguments, parameters, or memory contents. Information, arguments, parameters, data, etc., can be passed, forwarded, or transmitted via any suitable means, including memory sharing, message passing, token passing, network transmission, etc.
[0048] Additionally, the embodiments can be implemented using hardware, software, firmware, middleware, microcode, hardware description languages, or any combination thereof. When implemented in software, firmware, middleware, or microcode, the program code or code segments that perform the necessary tasks can be stored in a machine-readable or computer-readable medium. One or more processors can perform the necessary tasks.
[0049] The systems depicted in some of the figures can be provided in various configurations. In some embodiments, the system can be configured as a distributed system, wherein one or more components of the system are distributed across one or more networks in a cloud computing system. In a further embodiment, the system can be configured as a single system, wherein one or more components of the system are incorporated into a single structure or package.
[0050] II. Cloud-based Application Development
[0051] An application is a software program that performs a specific, expected task during execution. Generally, it includes one or more operating systems (“OS”) and virtual machines (e.g., those supporting Java). TM Applications execute within a runtime environment that includes programming languages, device drivers, and other components. Developers often use Application Development Frameworks (“ADFs”) (ADFs themselves are applications) to implement / develop desired applications. ADFs provide a set of predefined code / data modules that can be used directly or indirectly in application development. ADFs may also provide tools such as Integrated Development Environments (“IDEs”), code generators, debuggers, etc. Generally, ADFs simplify application development by providing reusable components that application developers can use to define user interfaces (“UIs”) and application logic, for example, by selecting components to perform desired tasks and defining the appearance, behavior, and interactions of the selected components. Some ADFs, such as Oracle ADF from Oracle Corporation, are based on the Model-View-Controller (“MVC”) design pattern, which promotes loose coupling and easier application development and maintenance.
[0052] Figure 1This is a block diagram of a system environment 100 for developing cloud-based applications according to one embodiment of the present invention. In the illustrated embodiment, system environment 100 includes a cloud infrastructure system 102 that provides cloud services to one or more client computing devices 104, 106, and 108. Client computing devices 104, 106, and 108 can be used by users to interact with cloud infrastructure system 102. Client computing devices 104, 106, and 108 can be configured to operate client applications, such as web browsers, proprietary client applications (e.g., Oracle Forms), or some other application, which can be used by users of the client computing devices to interact with cloud infrastructure system 102 to use the services provided by cloud infrastructure system 102.
[0053] The cloud infrastructure system 102 may have components other than those described. Additionally, Figure 1 The illustrated embodiment is merely one example of a cloud infrastructure system that can be incorporated into embodiments of the present invention. In some other embodiments, the cloud infrastructure system 102 may have a greater... Figure 1 It can show more or fewer components, can combine two or more components, or can have different component configurations or arrangements.
[0054] Client computing devices 104, 106, and 108 can be portable handheld devices (e.g., Cellular phone Computing tablets, personal digital assistants (“PDAs”), or wearable devices (e.g., Google) Head-mounted display), running software (such as Microsoft Windows) ) and / or various mobile operating systems (such as iOS, Windows Phone, Android, BlackBerry 10, Palm OS, etc.), and with internet, email, and short message service (“SMS”) enabled. Or other communication protocols. Client computing devices 104, 106, and 108 can be general-purpose personal computers, such as those running various versions of Microsoft... Apple Personal computers and / or laptops running Linux OS. Client computing devices 104, 106, and 108 can run various commercially available operating systems. Workstation computers running any OS, including but not limited to various GNU / Linux OSes such as, for example, Google Chrome OS. Alternatively or additionally, client computing devices 104, 106, and 108 may be any other electronic devices capable of communicating via one or more networks 110, such as thin client computers, internet-enabled gaming systems (e.g., with or without...). The gesture input device is the Microsoft Xbox game console and / or a personal messaging device.
[0055] While an exemplary system environment 100 with three client computing devices is shown, any number of client computing devices can be supported. Other devices, such as devices with sensors, can interact with the cloud infrastructure system 102.
[0056] One or more networks 110 may facilitate communication and data exchange between clients 104, 106, and 108 and cloud infrastructure system 102. One or more networks 110 may be any type of network familiar to those skilled in the art, and may use any of a variety of commercially available protocols, including but not limited to Transmission Control Protocol / Internet Protocol (“TCP / IP”), System Network Architecture (“SNA”), Internet Packet Switching (“IPX”), AppleTalk, etc., to support data communication. By way of example only, one or more networks 110 may be a local area network (“LAN”), such as a LAN based on Ethernet, Token Ring, etc. One or more networks 110 may be a wide area network and the Internet. Network 110 may include virtual networks, including but not limited to Virtual Private Networks (“VPN”), intranets, extranets, Public Switched Telephone Networks (“PSTN”), infrared networks, wireless networks (e.g., those compliant with the IEEE 802.11 protocol suite), (Bluetooth) and / or any other wireless protocol operating on a network; and / or any combination of these networks and / or other networks.
[0057] Cloud infrastructure system 102 may include one or more computers and / or servers. These computer systems or servers may consist of one or more general-purpose computers, dedicated server computers (including, for example, personal computer (“PC”) servers), etc. The cloud infrastructure system 102 may consist of a server, a mid-range server, a mainframe computer, a rack-mounted server, etc., a server farm, a server cluster, or any other suitable arrangement and / or combination. In various embodiments, one or more computer systems or servers associated with the cloud infrastructure system 102 may be adapted to run one or more services or software applications described in the foregoing disclosure. For example, one or more computer systems or servers associated with the cloud infrastructure system 102 may correspond to servers used to perform the processes described herein according to embodiments of this disclosure.
[0058] One or more computer systems or servers associated with cloud infrastructure system 102 may run operating systems including any of the OSes discussed above, as well as any commercially available server OS. One or more computer systems or servers associated with cloud infrastructure system 102 may also run any of a variety of additional server applications and / or middleware applications, including Hypertext Transfer Protocol (“HTTP”) servers, File Transfer Protocol (“FTP”) servers, Common Gateway Interface (“CGI”) servers, etc. Servers, database servers, etc.
[0059] In some embodiments, the services provided by cloud infrastructure system 102 may include a variety of services available on demand to users of cloud infrastructure system 102, such as online data storage and backup solutions, web-based email services, hosted office suites and document collaboration services, database processing, managed technical support services, etc. The services provided by cloud infrastructure system 102 can be dynamically scaled to meet the needs of users of cloud infrastructure system 102. A specific instantiation of the services provided by cloud infrastructure system 102 is referred to herein as a “service instance.” Generally, any service available to users from a cloud service provider’s system via a communication network (such as the Internet) is referred to as a “cloud service.” Typically, in a public cloud environment, the servers and systems constituting the cloud service provider’s system differ from the customer’s own on-premises servers and systems. For example, the cloud service provider’s system may host applications, and users may subscribe to and use applications on demand via a communication network such as the Internet.
[0060] In some examples, service instances instantiated by cloud infrastructure 102 may include protected computer network access to storage devices, hosted databases, hosted web servers, software applications, or other services provided to users by the cloud provider, or as otherwise known in the art. For example, service instances instantiated by cloud infrastructure 102 may include password-protected access to remote storage devices in the cloud via the Internet. As another example, service instances instantiated by cloud infrastructure 102 may include web service-based hosted relational databases and scripting language middleware engines for private use by networked developers. As yet another example, service instances instantiated by cloud infrastructure 102 may include access to email software applications hosted on a cloud provider's website.
[0061] In some embodiments, cloud infrastructure system 102 may include a suite of application, middleware, development services, and database service providers delivered to customers in a self-service, subscription-based, elastically scalable, reliable, highly available, and secure manner. An example of such a cloud infrastructure system embodied in cloud infrastructure service 102 is Oracle Public Cloud from Oracle Corporation.
[0062] Cloud infrastructure system 102 can provide cloud services through different deployment models. For example, services can be provided based on a public cloud model, where cloud infrastructure system 102 is owned by an organization selling cloud services (e.g., owned by Oracle Corporation), and the services are available to the general public or businesses in different industries. As another example, services can be provided based on a private cloud model, where cloud infrastructure system 102 operates only for a single organization and can provide services to one or more entities within that organization. Cloud services can also be provided based on a community cloud model, where cloud infrastructure system 102 and the services provided by cloud infrastructure system 102 are shared by several organizations in the relevant community. Cloud services can also be provided based on a hybrid cloud model, which is a combination of two or more different models.
[0063] In some embodiments, the services provided by the cloud infrastructure system 102 may include one or more services offered under the Software as a Service (“SaaS”) category, Platform as a Service (“PaaS”) category, Infrastructure as a Service (“IaaS”) category, MBaaS category, or other service categories that include hybrid services. In some embodiments, the services provided by the cloud infrastructure system 102 may include, but are not limited to, application services, platform services, infrastructure services, backend services, etc. In some examples, application services may be provided by the cloud infrastructure system 102 via a SaaS platform. The SaaS platform may be configured to provide cloud services falling into the SaaS category. For example, a SaaS platform may provide the ability to build and deliver on-demand application suites on an integrated development and deployment platform. The SaaS platform may manage and control the underlying software and infrastructure used to provide SaaS services. By utilizing the services provided by the SaaS platform, customers can leverage applications running on the cloud infrastructure system. Customers can obtain application services without purchasing separate licenses and support. A variety of different SaaS services may be provided. Examples include, but are not limited to, services providing solutions for sales performance management, enterprise integration, and business flexibility for large organizations.
[0064] In some embodiments, platform services may be provided by cloud infrastructure system 102 via a PaaS platform. The PaaS platform may be configured to provide cloud services falling into the PaaS category. Examples of platform services may include, but are not limited to, services that enable organizations (such as Oracle) to integrate existing applications on a shared, public architecture and to leverage the shared services provided by the platform to build new applications. The PaaS platform can manage and control the underlying software and infrastructure used to provide PaaS services. Customers can access PaaS services provided by cloud infrastructure system 102 without having to purchase separate licenses and support. Examples of platform services include, but are not limited to, Oracle Java Cloud Service (“JCS”) and Oracle Database Cloud Service (“DBCS”) from Oracle Corporation.
[0065] By leveraging services provided by the PaaS platform, customers can employ programming languages and tools supported by the cloud infrastructure system 102 and also control the deployed services. In some embodiments, the platform services provided by the cloud infrastructure system 102 may include database cloud services, middleware cloud services (e.g., Oracle Fusion Middleware Service), and Java cloud services. In one embodiment, the database cloud service may support a shared services deployment model that enables organizations to aggregate database resources and provide database-as-a-service to customers in the form of a database cloud. The middleware cloud service can provide customers with a platform for developing and deploying various business applications, and the Java cloud service can provide customers with a platform for deploying Java applications within the cloud infrastructure system.
[0066] Various infrastructure services can be provided by the IaaS platform within the cloud infrastructure system 102. Infrastructure services facilitate the management and control of underlying computing resources (such as storage devices, networks, and other basic computing resources) for customers to utilize services provided by SaaS and PaaS platforms.
[0067] In some embodiments, cloud infrastructure system 102 can provide comprehensive management of cloud services (e.g., SaaS, PaaS, IaaS, and MBaaS services) within the cloud infrastructure system. In one embodiment, cloud management functionality may include the ability to provision, manage, and track customer subscriptions received by cloud infrastructure system 102. In various embodiments, cloud infrastructure system 102 may be adapted to automatically provision, manage, and track customer subscriptions to services provided by cloud infrastructure system 102. A customer may subscribe to one or more services provided by cloud infrastructure system 102 via a subscription order. Cloud infrastructure system 102 then performs processing to provide the services in the customer's subscription order.
[0068] In one embodiment, cloud management functionality may be provided by one or more modules, such as order management and monitoring module 114. These modules may include one or more computers and / or servers, or one or more computers and / or servers may be provided, which may be general-purpose computers, dedicated server computers, server farms, server clusters, or any other suitable arrangement and / or combination.
[0069] In exemplary operation, a customer using client computing devices 104, 106, or 108 can interact with cloud infrastructure system 102 by requesting one or more services provided by cloud infrastructure system 102. The customer can use various means to issue service request 134 to cloud infrastructure system 102. Service request 134 may include placing an order for subscription to one or more services provided by cloud infrastructure system 102, accessing one or more services provided by cloud infrastructure system 102, etc. In some embodiments, the customer can access cloud UIs 132, 134, and 138 and place subscription orders via these UIs. Order information received by cloud infrastructure system 102 in response to a customer's order may include information identifying the customer and the one or more services provided by cloud infrastructure system 102 that the customer intends to subscribe to. Order information is received via cloud UIs 132, 134, and / or 138 after the customer has placed an order.
[0070] In this example, the order management and monitoring module 112 sends information received from the customer to the order database to store the orders placed by the customer. The order database can be one of several databases operated by the cloud infrastructure system 102 and in conjunction with other system components. The order management and monitoring module 112 can forward all or part of the information, including order information stored in the order database, to the order management module. In some cases, the order management module can be configured to perform order-related billing and accounting functions, such as verifying orders and, after verification, booking them.
[0071] In some embodiments, cloud infrastructure system 100 may include an identity management module 114. Identity management module 114 may be configured to provide identity services, such as access management and authorization services in cloud infrastructure system 102. In some embodiments, identity management module 114 may control information about customers who wish to utilize services provided by cloud infrastructure system 102. This information may include information authenticating the identities of these customers and information describing what actions these customers are authorized to perform relative to various system resources (e.g., files, directories, applications, communication ports, memory segments, etc.). Identity management module 114 may also include management of descriptive information about each customer and how and by whom this descriptive information can be accessed and modified.
[0072] In some embodiments, the cloud infrastructure system 102 may also include infrastructure resources 116 for providing resources for offering various services to customers of the cloud infrastructure system 102. In one embodiment, infrastructure resources 116 may include a pre-integrated and optimized combination of hardware (such as servers, storage devices, and network resources) to perform services provided by PaaS platforms and SaaS platforms.
[0073] In some embodiments, resources in the cloud infrastructure system 102 can be shared by multiple users and dynamically reallocated as needed. Furthermore, resources can be allocated to users in different time zones. For example, the cloud infrastructure system 102 can enable a first set of users in a first time zone to utilize the resources of the cloud infrastructure system for a specified number of hours, and then enable the same resources to be reallocated to another set of users located in a different time zone, thereby maximizing resource utilization.
[0074] In some embodiments, multiple internal shared services 118 may be provided, shared by different components or modules of the cloud infrastructure system 102 and by services provided by the cloud infrastructure system 102. These internal shared services 118 may include, but are not limited to, security and identity services, integration services, enterprise repository services, enterprise manager services, virus scanning and whitelisting services, high availability, backup and recovery services, services for enabling cloud support, email services, notification services, file transfer services, etc.
[0075] In some embodiments, multiple external shared services 120 may be provided, shared by different components or modules of the cloud infrastructure system 102 and by services provided by the cloud infrastructure system 102. These external shared services 120 may include, but are not limited to, security and identity services, integration services, enterprise repository services, enterprise manager services, virus scanning and whitelisting services, high availability, backup and recovery services, services for enabling cloud support, email services, notification services, file transfer services, etc.
[0076] In various embodiments, external shared service 120 may include one or more components that provide access, data transformation, automation, etc., to one or more enterprise computer systems 126. Access to one or more enterprise computer systems 126 may be shared by different components or modules of cloud infrastructure system 102 and by services provided by cloud infrastructure system 102. In some embodiments, access to one or more enterprise computer systems 126 may be shared by service instances provided by cloud infrastructure system 102 that are limited to one or more subscribers.
[0077] In a further embodiment, external shared services 120 may include external application programming interface (“API”) services 128 shared by different components or modules of the cloud infrastructure system 102 and shared by services provided by the cloud infrastructure system 102. These external API services 128 may include, but are not limited to, APIs provided by other third-party services or entities.
[0078] Various mobile cloud services can be provided by the MCS 122 in the cloud infrastructure system 102. According to some embodiments of the invention, the MCS 122 facilitates communication between mobile computing devices and enterprise computer systems (e.g., enterprise computer systems 124 and 126). The MCS 122 may include one or more memory storage devices (“local storage devices”) for storing enterprise data and authentication information. Enterprise data may be received from the enterprise computer system 126 or from client computing devices 104, 106, or 108, or may include enterprise data or combinations thereof transformed by the cloud infrastructure system 102. Authentication information may be received from the identity management system 116 and / or generated by the cloud infrastructure system 102. In some embodiments, the authentication information may include information indicating secure authentication of a user requesting a service.
[0079] Enterprise computer systems (such as enterprise computer system 126) may be physically located outside the firewall of cloud infrastructure system 102 at a different geographical location (e.g., a remote geographical location) than cloud infrastructure system 102. In some embodiments, enterprise computer system 126 may include one or more different computers or servers. In some embodiments, enterprise computer system 126 may be part of a single computer system.
[0080] In some embodiments, enterprise computer system 126 may communicate with cloud infrastructure system 102 using one or more different protocols. Each enterprise computer system in enterprise computer system 126 may communicate with cloud infrastructure system 102 using a different communication protocol. Enterprise computer system 126 may support the same or different security protocols. In some embodiments, MCS 122 may include a proxy system to handle communications with enterprise computer system 126.
[0081] Protocols may include communication protocols such as SPeeDY (“SPDY”). Protocols may include application protocols such as HTTP-based protocols. In some embodiments, enterprise computer system 126 may communicate with cloud infrastructure system 102 using communication protocols such as REST or Simple Object Access Protocol (“SOAP”). For example, the REST protocol may support formats including Uniform Resource Identifiers (“URIs”) or Uniform Resource Locators (“URLs”). Enterprise data formatted for communication using the REST protocol can be easily converted to data formats such as JavaScript Object Markup (“JSON”), comma-separated values (“CSV”), and True Simple Aggregate (“RSS”). Enterprise computer system 126 and cloud infrastructure system 102 may communicate using other protocols such as Remote Procedure Call (“RPC”) (e.g., Extended Markup Language (“XML”) RPC).
[0082] In some embodiments, MCS 122 may include adapter interfaces configured to support communication with one or more services provided by cloud infrastructure service 102, some of which may support different protocols or technologies for communication. In some embodiments, MCS 122 may include adapter interfaces configured to support communication with enterprise computer system 126, some of which may support different protocols or technologies for communication. MCS 122 may include one or more adapters, each of which may be configured to communicate based on a communication protocol, the type of enterprise computer system, the type of application, the type of service, or a combination thereof. The communication protocols supported by the adapters may be specific to the service or one or more enterprise computer systems in enterprise computer system 126.
[0083] In some embodiments, client computing devices 104, 106, and 108 may each implement an application that can provide a specific UI to communicate with MCS 122. The specific UI may be configured to communicate using a specific communication protocol. In some embodiments, the specific UI may include callable interfaces, functions, routines, methods, and / or operations that can be invoked to communicate with MCS 122. The specific UI may accept input parameters for communicating with services provided by cloud infrastructure service 102 or with enterprise computer system 126, as well as input parameters for enterprise data and / or requesting services. In some embodiments, communication via MCS 122 may be converted to communicate using a custom communication protocol. In some embodiments, the specific UI may correspond to a custom client within an application.
[0084] MCS 122 may include one or more callable interfaces, such as APIs. Callable interfaces associated with MCS 122 enable applications on mobile computing devices to send requests to MCS 122. Callable interfaces associated with MCS 122 may support public or standard interfaces that allow requests, including their parameters, to be received from applications (apps) according to standardized protocols, architectural styles, and / or formats (e.g., the REST protocol). Callable interfaces associated with MCS 122 may be configured by a user of any of computing devices 104, 106, or 108. Callable interfaces associated with MCS 122 may receive requests for services according to communication protocols. Device application developers can connect to MCS 122 for their custom applications. In some embodiments, callable interfaces associated with MCS 122 may be configured by the same person developing the application, enabling that person to implement custom applications to communicate with MCS 122.
[0085] The callable interfaces associated with MCS 122 also enable enterprise computer systems 126 to communicate with MCS 122 according to standardized protocols or formats. Similar to application developers, those managing enterprise computer systems can implement code (e.g., an agent system) configured to communicate with MCS 122 via one or more callable interfaces. The callable interfaces associated with MCS 122 can be implemented based on the type of computing device, the type of enterprise computer system, the application, the agent system, the service, the protocol, or other criteria. In some embodiments, the callable interfaces associated with MCS 122 can support requests for services, including authentication, compression, encryption, paging using cursors, client-based throttling, non-repudiation, logging, and metric collection. In some embodiments, the callable interfaces associated with MCS 122 can be implemented for customized business-related services, such as authentication, policy enforcement, response caching, throttling of calls to MCS 122, switching between asynchronous and synchronous modes, logging of calls to underlying services, or combinations thereof. In some embodiments, the callable interfaces associated with MCS 122 may enable users to load custom code implemented by cloud infrastructure system 102. The custom code may implement one or more callable interfaces associated with MCS 122 of cloud infrastructure system 102, which may enable users to access custom services or other enterprise computer systems.
[0086] The protocol translator associated with MCS 122 can process messages to determine the communication protocol used for the message and / or convert the message into a communication protocol for the destination. The protocol translator associated with MCS 122 can convert requests received from client computing devices 104, 106, or 108. Requests can be converted from the format of a communication protocol supported by client computing devices 104, 106, or 108 to the format of a communication protocol supported by the service provided by cloud infrastructure service 102 or enterprise computer system 126. The protocol translator associated with MCS 122 can convert responses received from services provided by cloud infrastructure service 102 or enterprise computer system 126. Responses can be converted from the format of a communication protocol supported by the service provided by cloud infrastructure service 102 or enterprise computer system 126 to the format of a communication protocol supported by client computing devices 104, 106, or 108.
[0087] The security services associated with MCS 122 can manage the security authentication of requests received from any client computing device 104, 106, or 108. The security services associated with MCS 122 can protect the integrity of client processing and enterprise data. To prevent system or data corruption, security authentication can occur when a request is received from client computing devices 104, 106, or 108. Security authentication can be performed before the request is dispatched for processing by cloud infrastructure system 102. Security authentication determined for a user enables the user associated with a mobile computing device to have authorization to request services via MCS 122. Security authentication can reduce the effort required for users to authenticate different requests and / or services requested via MCS 122. The security services associated with MCS 122 can be implemented as one or more functional blocks or modules configured to perform various operations to authenticate the security of requests.
[0088] The authentication service associated with MCS 122 can manage the security authentication of requests received from client computing devices 104, 106, or 108. The authentication service associated with MCS 122 can determine the security authentication of the user associated with the computing device that sent the request to MCS 122. Security authentication can be determined based on a time period, which can be bound to an application operation (e.g., launching an application), the request, the computing device, the enterprise computer system, other criteria associated with the request, or a combination thereof. Security authentication can be verified and authorized against any of the following: such as a personal request, one or more enterprise computer systems, a specific service, a service type, a user, a computing device, other criteria used to determine security authentication, or a combination thereof. In some embodiments, cloud infrastructure system 102 can store authentication information of users received from enterprise computer systems or authentication systems supporting enterprise computer systems. Cloud infrastructure system 102 can determine authentication by performing a lookup function to determine whether the identity of the user associated with the request is authorized to make such a request. The stored authentication information may include information that the user can be authorized to access, such as the type of request, function, enterprise computer system, enterprise data, etc. In some embodiments, the infrastructure system 102 may initiate communication with the requesting computing device to determine authentication.
[0089] In some embodiments, security authentication may be determined based on the role associated with the user requesting the service. A role may be associated with a user requesting access to MCS 122. In some embodiments, a user may request services as a subscriber or tenant of MCS 122, and these subscribers or tenants may be authorized to access resources and / or services provided by MCS 122. Authentication may correspond to a user's subscription to MCS 122, enabling the user to be authorized to request services via MCS 122 as a subscriber. In some embodiments, the subscription may be limited to a specific set of resources provided by MCS 122. Security authentication may be based on resources and / or services accessible to the user of MCS 122. In some embodiments, a template may be supplied for the request during execution, referred to as a "runtime environment." The runtime environment may be associated with resources allocated to the request, user, or device.
[0090] In some embodiments, the authentication service associated with MCS 122 may request the identity management system to determine security authentication for a user. The identity management system may be implemented by cloud infrastructure system 102 (e.g., as identity management 114) or by another computer system external to cloud infrastructure system 102. Identity management 116 may determine user security authentication based on the user's role or subscription to access MCS 122. Privileges and / or rights may be assigned to roles or subscriptions regarding enterprise computer systems, services provided by enterprise computer systems, the functions or characteristics of enterprise computer systems, other criteria for controlling access to enterprise computer systems, or combinations thereof.
[0091] Various ADF 124 implementations can be provided within the cloud infrastructure system 102. ADF 124 provides infrastructure code for implementing agile SOA-based applications. ADF 124 also provides a visual and declarative approach to development through one or more development tools, such as the Oracle JDeveloper 11g development tool. One or more frameworks provided by ADF 124 can implement the MVC design pattern. This framework provides integrated solutions covering all layers of the MVC architecture, as well as solutions for these areas, such as object / relational mapping, data persistence, reusable controller layers, rich web UI frameworks, data binding to the UI, security, and customization. Extending outwards from the core web-based MVC approach, this framework also integrates with Oracle SOA and the WebCenter Portal framework, simplifying the creation of complete composite applications.
[0092] In some embodiments, ADF 124 facilitates the development of agile applications that expose data as a service by coupling service interfaces to built-in business services provided by cloud infrastructure system 102. This separation of business service implementation details is performed in ADF 124 via metadata. The use of this metadata-driven architecture allows application developers to focus on business logic and user experience, rather than the details of how services are accessed. In some embodiments, ADF 124 stores service implementation details in metadata within the model layer. This allows developers to exchange services without modifying the UI, making the application highly agile. Furthermore, UI developers do not need to worry about the details of business service access. Instead, developers can focus on developing application interfaces and interaction logic. Creating a user experience can be as simple as dragging and dropping the desired business service onto a visual page designer and indicating which type of component should represent that data.
[0093] In various embodiments, developers interact with ADF 124 to create modules that form enterprise applications. The enterprise applications can execute within the context of cloud infrastructure system 102. In various embodiments, developers interact with ADF 124 to create modules that form mobile applications. The mobile applications can execute within the context of cloud infrastructure system 102. The features of the invention described below can be implemented using any desired combination of programming languages and application development frameworks, as will be apparent to those skilled in the art from the disclosure provided herein.
[0094] In one example, one or more frameworks provided by ADF 124 can be represented as Oracle ADF. Accordingly, the frameworks in ADF 124 can be based on the MVC design pattern. The MVC application is separated into: 1) a model layer that handles interaction with the data source and runs business logic; 2) a view layer that handles the application UI; and 3) a controller that manages application flow and acts as the interface between the model and view layers. Separating the application into these three layers simplifies the maintenance and reuse of components across the application. The independence of each layer from the others results in loosely coupled SOA.
[0095] In various embodiments, ADF 124 provides tools and resources that allow developers to create applications in a multi-layered manner, each layer containing code modules / files that implement the desired logic according to predefined specifications. Thus, in one embodiment, ADF 124 enables an application to be developed as a four-layered system: a view layer containing code modules / files that provide the application's UI; a controller layer containing code modules that control the application's flow; a model layer containing data / code modules that provide an abstraction layer for the underlying data; and a business services layer containing code modules that provide access to data from various sources and process business logic.
[0096] In some embodiments, ADF 124 allows developers to choose the technologies they prefer to use when implementing each layer. Enterprise JavaBeans (“EJB”), Web services, JavaBeans, JPA / EclipseLink / TopLink objects, and many other services can be used as business services for ADF 124. The view layer can include web-based interfaces implemented using Java Server Faces (“JSF”), desktop Swing applications, and Microsoft Office front-ends, as well as interfaces for mobile devices.
[0097] In one aspect, the view layer represents the UI of the application being developed. The view layer can include desktop, mobile, and browser-based views, each providing all or part of the UI and accessible in various ways corresponding to the view type. For example, a web page can be sent by an application in response to receiving a client request containing a corresponding URL. The web page can then be displayed by a browser on a display unit (not shown) associated with the requesting client system, enabling the user of the requesting client system to interact with the enterprise application. ADF 124 supports multi-channel access to business services, allowing for the reuse of business services and access from web clients, client-server Swing desktop applications, Microsoft Excel spreadsheets, mobile devices such as smartphones, etc.
[0098] The code files / modules that form the view layer (such as web pages) can be implemented using one or more of Hypertext Markup Language (“HTML”), Java Server Pages (“JSP”), and JSF. Alternatively, the UI can be implemented using Java components such as Swing and / or XML. As further described, the UI can take full advantage of the user’s experience and familiarity with desktop applications (such as Microsoft Word and Excel).
[0099] As mentioned above, each layer provides relevant user-developed code / data modules. However, each layer typically contains additional predefined code / data modules provided by ADF 124. Some predefined modules can be used during development, for example, as templates for developing web pages, or to include desired functionality in the developed code. Other predefined modules (such as URL rewriting modules) can be deployed with the developed application and can provide additional functionality to users during the execution of the enterprise application (mapping requested URLs to internal names).
[0100] The controller layer contains code modules / files that control the application flow. Each controller object contains software instructions and / or data implemented according to the desired manner in which information is presented in the view layer. The desired manner may include a specific web page to display when a user clicks / selects a link in another web page, a page to display when an error occurs during execution, specific data to be stored / retrieved, etc.
[0101] In one aspect, the controller layer manages application flow and handles user input. For example, when a search button is clicked on a page, the controller determines what action to perform (perform a search) and where to navigate to (the results page). JDeveloper offers two controller options for web-based applications: the standard JSF controller or the ADF controller, which extends the functionality of JSF controllers. Regardless of which controller is used, application flow is typically designed by laying out pages and navigation rules on a diagram. Application flow can be broken down into smaller, reusable task flows; including non-visual components such as method calls and decision points within the flow; and creating "page fragment" flows that operate within a single area containing the page.
[0102] The code modules / files that form the controller layer are often implemented as Java servlets that receive client requests and send the desired web page as the corresponding response. Controller objects can also be implemented as, for example, Apache Jakarta Struts controllers, or according to the JSF standard.
[0103] The model layer contains data / code modules that connect various business services to objects that use these services in other layers, such as connecting to the controller objects discussed above or directly to desktop applications. Each abstract data object in the model layer provides a corresponding interface that can be used to access any type of business service executed in the underlying business service layer. Data objects can abstract the business service implementation details of the service from the client and / or expose data control methods / properties to view components, thereby providing separation between the view layer and the data layer.
[0104] In one aspect, the model layer comprises two components—data control and data binding—with interfaces defined using metadata files. Data control abstracts the implementation details of business services from the client. Data binding exposes data control methods and properties to UI components, thus providing a clean separation between the view and the model. Due to the metadata architecture of the model layer, developers enjoy the same development experience when binding any type of business service layer implementation to the view and controller layers.
[0105] In some embodiments, ADF 124 emphasizes the use of a declarative programming paradigm throughout the development process, allowing users to focus on the logic of application creation without having to deal with implementation details. At a high level, the development process for Fusion web applications typically involves creating an application workspace. Using a wizard, the necessary libraries and configurations for the technologies selected by the developer are automatically added, and the application is structured as a project with packages and directories.
[0106] By modeling database objects, you can create online or offline copies of any database, edit definitions, and update schemas. Using the Unified Modeling Language (“UML”) modeler, you can then create use cases for your application. Application controls and navigation can also be designed. A diagrammer can be used to visually define the flow of application controls and navigation. The underlying XML files describing this flow can then be automatically created. Libraries can be used to allow developers to view and use imported libraries simply by dragging and dropping them into the application. Entity objects can be created from database tables using wizards or dialogs. From these entity objects, view objects can be created for use on pages within the application. Validation rules and other types of business logic can be implemented.
[0107] In this example, the Business Services layer manages the interaction with the Data Persistence layer. The Business Services layer provides services such as data persistence, object / relational mapping, transaction management, and business logic execution. The Business Services layer can be implemented as any of the following options: a simple Java class, EJB, Web service, JPA object, or Oracle ADF Business Component. Furthermore, data can be consumed directly from files (XML or CSV) and REST. Therefore, each Business Service manages the interaction with its corresponding Data Persistence layer and provides services such as object / relational mapping, transaction management, and business logic execution. The Business Services layer can be implemented using one or more of the following: simple Java classes, Enterprise Java Beans, Web services, etc.
[0108] A business component refers to a business service implemented using, for example, Oracle's "Oracle ADF Business Components" to provide interaction with databases, web services, legacy systems, application servers, etc. In one embodiment, a business component in the business service layer comprises a mix of application modules, view / query objects, and entity objects that work together to provide the business service implementation. Application modules can be transactional components / code modules that a UI client communicates with to work with the application / transactional data. Application modules can provide an updatable data model and procedures / functions (often referred to as service methods) related to user transactions.
[0109] Entity objects can represent corresponding rows in a database table and simplify the manipulation (updates, deletions, etc.) of the data stored in those rows. Entity objects typically encapsulate the business logic of the corresponding row to ensure that desired business rules are consistently enforced. Entity objects can also be associated with other entity objects to reflect the relationships that exist between rows stored in the underlying database.
[0110] III. Confidentiality, Residency, and Security
[0111] Confidentiality, residency, and security (PRS) involves addressing the problem of obfuscating data entering the cloud. Two common obfuscation methods are encryption and tokenization. Using either of these methods ensures that data remains difficult to decipher for snooping while the organization enjoys the benefits of cloud-based applications provided by the cloud infrastructure system 102.
[0112] Figure 2 This is a block diagram of a system 200 that utilizes cloud-based applications to provide confidentiality, residency, and security, according to some embodiments of this disclosure. Figure 2 In the illustrated embodiment, system 200 includes one or more client computing devices 205, 210, and 215, which can be used by a user to interact with a cloud infrastructure system 220 that provides cloud services (e.g., regarding...). Figure 1 The described cloud infrastructure system 102 interacts with cloud services, including services for providing access to data that may or may not be obfuscated. It should be understood that system 200 may have components other than those depicted. Furthermore, Figure 2 The illustrated embodiment is merely one example of a system that utilizes cloud-based applications that can be combined with some of the embodiments to provide confidentiality, residency, and security. In some other embodiments, system 200 may have more or fewer components than shown in the figure, may combine two or more components, or may have different component configurations or arrangements.
[0113] In this example, system 200 includes enterprise infrastructure system 225, PRS system 230, and cloud infrastructure system 220. Enterprise infrastructure system 225 may include one or more client devices, servers, networking devices, routers, proxies, gateways, etc. As shown, enterprise infrastructure system 225 includes one or more client computing devices 205, 210, and 215 that communicate with PRS system 230 and cloud infrastructure system 220. As shown, PRS system 230 includes PRS server 235 and private database 240, and cloud infrastructure system 220 includes cloud-based application 245 and cloud database 250.
[0114] Client computing devices 205, 210, and 215 can be compatible with the above-mentioned... Figure 1The devices shown in Figures 104, 106, and 108 are similar to those described. Client computing devices 205, 210, and 215 can be configured to operate client applications, such as web browsers, proprietary client applications (e.g., Oracle Forms), or other applications, which can be used by users of the client computing devices to interact with cloud infrastructure system 220 to use services provided by cloud infrastructure system 220. Although the exemplary system environment 200 is shown as having three client computing devices, any number of client computing devices can be supported. Other devices, such as devices with sensors, can interact with cloud infrastructure system 220.
[0115] Client computing devices 205, 210, and 215 can be portable handheld devices (e.g., Cellular phone Computing tablets, personal digital assistants (“PDAs”), or wearable devices (e.g., Google) Head-mounted display), running software (such as Microsoft Windows) ) and / or various mobile operating systems (such as iOS, Windows Phone, Android, BlackBerry 10, Palm OS, etc.), and with internet, email, and short message service (“SMS”) enabled. Or other communication protocols. Client computing devices 205, 210, and 215 can be general-purpose personal computers, such as those running various versions of Microsoft... Apple Personal computers and / or laptops running Linux OS. Client computing devices 205, 210, and 215 can run various commercially available operating systems. Workstation computers running any OS, including but not limited to various GNU / Linux OSes such as Google Chrome OS. Alternatively or additionally, client computing devices 205, 210, and 215 can be any other electronic device capable of communicating over one or more networks, such as thin client computers, internet-enabled gaming systems (e.g., with or without...). The gesture input device is the Microsoft Xbox game console and / or a personal messaging device.
[0116] PRS server 235 may include one or more computers and / or servers. These computer systems or servers may consist of one or more general-purpose computers, dedicated server computers (including, for example, personal computer (“PC”) servers), etc. Servers, mid-range servers, mainframe computers, rack-mounted servers, etc., server farms, server clusters, or any other suitable arrangement and / or combination thereof. One or more computer systems or servers associated with PRS Server 235 may run any of the OSes discussed above, as well as any commercially available server OS. One or more computer systems or servers associated with PRS Server 235 may also run any of a variety of additional server applications and / or middleware applications, including Hypertext Transfer Protocol (“HTTP”) servers, File Transfer Protocol (“FTP”) servers, Common Gateway Interface (“CGI”) servers, etc. Servers, database servers, email servers, reverse proxies, etc.
[0117] In some embodiments, the services provided by PRS server 235 may include a variety of services such as data confidentiality, residency, and security. PRS server 235 can be graphically installed, and it can be configured to support cloud application-specific needs using an application-specific adapter. In some examples, PRS server 235 can provide data confidentiality by protecting data leaving enterprise infrastructure system 225 (e.g., through encryption or tokenization). PRS server 235 can seamlessly intercept data transfers between client computing devices 205, 210, and 215 and cloud-based application 245, replacing sensitive data with alternative data (e.g., tokens or encrypted data). Sensitive data that, as defined by the organization, cannot or should not leave enterprise infrastructure system 225, remains in a private database 240, for example, behind a firewall of PRS system 230, while regardless of where the sensitive data resides, the user experience of client computing devices 205, 210, and 215 enjoys virtually all the functionality of cloud-based application 245. PRS server 235 can perform "instant encryption," where sensitive data is not stored and managed locally, but rather encrypted or tokenized before being sent to cloud-based application 245, and decrypted or replaced upon return. If accessed directly without the PRS system 230, sensitive data received by cloud-based application 245 and optionally stored in cloud database 250 itself will only appear as an encrypted list of values or tokens.
[0118] PRS server 235 provides data residency by preventing data that meets certain conditions (e.g., sensitive data) from leaving enterprise infrastructure system 225. PRS server 235 can identify specific data fragments that meet the conditions from data transmission, save the specific data fragments to a private database 240, generate replacement values (e.g., encrypted values or tokens) for the real values of the identified specific data fragments, and send the generated replacement values to cloud-based application 245. The real values of the identified specific data fragments remain locally resided in the private database 240, which may be governed by local regulations and operated according to company policies. Therefore, cloud-based application 245 operates with replacement data that can be stored in cloud database 250. PRS server 235 can categorize cloud application data, such as using categories like tokens, sortable tokens, encrypted values, and plaintext. In some embodiments, obfuscation countermeasures, as discussed in detail herein, can be used to protect data on a field-by-field basis.
[0119] PRS server 235 provides data confidentiality, residency, and security by managing access to data stored in private database 240. PRS server 235 ensures that authorized access to cloud-based application 245 occurs only from within the organization. PRS server 235 can create a secure authentication link between enterprise infrastructure system 225 and cloud infrastructure system 220. In one embodiment, PRS server 235 is configured to use an encryption algorithm scheme to transform plaintext information detected in network transmission into unreadable ciphertext. PRS server 235 can provide key management that allows PRS server 235 to encrypt and decrypt data within network transmission. Key management may include the ability to generate, distribute, store, rotate, and revoke / destroy cryptographic keys as needed to protect sensitive data associated with the cryptographic keys. In other embodiments, PRS server 235 is configured to use tokenization to protect sensitive data. PRS server 235 can use data substitution with a token (or alias) as a replacement for the real value. In the tokenization process, PRS server 235 intercepts sensitive data and sends the data to private database 235 in which the data is securely stored. Meanwhile, the PRS server 235 can generate a random, unique set of characters (token) and return the token to replace the real data. The PRS server 235 (or private database 240) can maintain a reference database that allows the token value to be exchanged for the real data when the real data value is needed again.
[0120] Accordingly, PRS server 235 can allow encrypted values or token values that are meaningless to snooping to be used as a reliable substitute for real data in various cloud-based applications (such as cloud-based application 245). Cloud-based application 245 can represent the use of, for example, regarding Figure 1 The ADF 124 discussed here refers to one or more enterprise applications developed. These enterprise applications can execute within the context of cloud infrastructure system 220. Cloud-based application 245 may include an MVC application, which is separated into 1) a model layer that handles interaction with cloud database 250 and runs business logic, 2) a view layer that handles the application UI delivered to one or more client devices 205, 210, and 215, and 3) a controller that manages application flow and acts as the interface between the model layer and the view layer.
[0121] In one aspect, the view layer represents the UI of the application being developed. The view layer can include desktop, mobile, and browser-based views, each providing all or part of the UI and accessible in various ways corresponding to the view type. For example, a web page can be sent by a cloud-based application 245 in response to receiving a client request containing a corresponding URL from one or more client devices 205, 210, and 215. The web page can then be displayed by a browser on a display unit (not shown) associated with one or more client devices 205, 210, and 215, enabling users of one or more client devices 205, 210, and 215 to interact with the cloud-based application 245. The code files / modules forming the view layer (such as web pages) can be implemented using one or more of Hypertext Markup Language (“HTML”), Java Server Pages (“JSP”), and JSF. Alternatively, the UI can be implemented using Java components such as Swing and / or XML. As further described, the UI can leverage the user's experience and familiarity with desktop applications such as Microsoft Word and Excel.
[0122] As described above, PRS server 235 can monitor (e.g., intercept) network traffic and enforce confidentiality, residency, and security policies. Regarding communication between one or more client devices 205, 210, and 215 and the cloud-based application 245, PRS server 235 can intercept transmissions originating from one or more client devices 205, 210, and 215 to enforce confidentiality, residency, and security policies. In the example shown, one or more client devices 205, 210, and 215 may send a network transmission to cloud infrastructure system 220 containing the following information fragments: ADDRESS = "123MAIN" and CONTACT = "JOHN". PRS server 235 can intercept the network transmission and examine its content to determine whether any information fragments are subject to confidentiality, residency, and security policies. For example, PRS server 235 may determine that the "Contact" information fragment is sensitive data subject to confidentiality, residency, and security policies and should not be transmitted to cloud infrastructure system 220. PRS server 235 can modify network transmissions to encrypt or tokenize information where a "contact" information fragment is designated as sensitive or private data: address = "123MAIN" [public data] and contact = "JIDL45" [private data]. PRS server 235 can store the password key and / or raw data along with the token mapping in a private database 240. PRS server 235 can then forward the modified network transmission along with a replacement value (e.g., an encrypted value or token) to cloud-based application 245.
[0123] Regarding communication between one or more client devices 205, 210, and 215 and the cloud-based application 245, the PRS server 235 can intercept transmissions destined for one or more client devices 205, 210, and 215 in a process contrary to the implementation of confidentiality, residency, and security policies. In the example shown, the PRS server 235 can determine that a "contact" message fragment has been encrypted or tokenized, and the PRS server 220 can modify the network transmission to decrypt or detoxify the message using a cryptographic key and / or the original data along with a token mapping retrieved from the private database 240. The PRS server 235 can then forward the modified network transmission to one or more client devices 205, 210, and 215.
[0124] Figure 3AThis is an illustration of UI 300 when viewed using one or more client devices 205, 210, and 215 from within enterprise infrastructure system 225, and associated with cloud-based application 245. As shown, the "Contacts" page 305 is displayed with one or more contact cards 310. Each contact's name 315 is visible along with other UI elements, such as a photo and other data fields including an address. As described in detail herein, the administrator of PRS server 235 can designate the name field of UI page 300 as protected data. Figure 3B This is an illustration of the UI 300' associated with the cloud-based application 245 when viewed from within the cloud infrastructure system 220 or when accessed from outside the enterprise infrastructure system 225 using a computing device. As shown, the "Contacts" page 305' is displayed with the same contact cards 310'; however, the name of each contact 315' is encrypted or replaced with tokenized data, while other UI elements (such as photos and other data fields including addresses) retain their real values.
[0125] IV. Self-describing Configuration
[0126] In some embodiments, the model layer associated with the cloud-based application 245 includes data / code modules that connect various business services to objects that use these business services in other layers, such as connecting to the controller objects discussed above or directly connecting to the desktop application. Each abstract data object in the model layer provides a corresponding interface that can be used to access any type of business service executed in the underlying business service layer. Data objects can abstract the business service implementation details of the service from the client and / or expose data control methods / attributes to view components, thus providing separation between the view layer and the data layer.
[0127] In one aspect, the model layer includes two components that define the UI using metadata files—data control and data binding. Data control abstracts the details of business service implementation from the client. Data binding exposes data control methods and properties to UI components, thus providing a clean separation between the view and the model. By modeling database objects, a cloud database 250 can be created for use with cloud applications 245. Based on the database tables, entity objects can be created using wizards or dialogs. Based on these entity objects, view objects are created for use by pages in the application. Validation rules and other types of business logic can be implemented.
[0128] Entity objects can represent corresponding rows in a database table and simplify the manipulation (updates, deletions, etc.) of the data stored in those rows. Entity objects typically encapsulate the business logic of the corresponding row to ensure that desired business rules are consistently enforced. Entity objects can also be associated with other entity objects to reflect the relationships that exist between rows stored in the underlying database.
[0129] Therefore, an entity object can be an ADF (Advanced Development Function) business component that represents a row in cloud database 250 and simplifies the modification of the associated attributes of that row. An entity object can be defined by specifying a database table in cloud database 250, where the entity object will represent a row in that cloud database table. Associations can then be created to reflect the relationships between entity objects. At runtime, entity rows are managed by the associated entity definition objects, and each entity row is identified by an associated row key. Entity rows are retrieved and modified within the context of the application module that provides database transactions to cloud database 250, associated with cloud-based application 245.
[0130] Figure 4 This is a block diagram illustrating attributes shared between entities according to an embodiment of the present invention. Figure 4 Entity objects are shown, such as account object 405, contact object 410, contact object 415, and employee object 420. Figure 4 Database tables, such as address table 425, telephone / email table 430, and people table 435, are also shown, each including various attributes 440, 445, and 450 shared between entities. As shown, the address attribute 440 of account object 405 and contact object 410 can be stored in the same database table (e.g., address table 425). Each row can be identified by an associated row key to specify whether the row retains the value of the address attribute 440 of account object 405 and / or contact object 410. Similarly, the telephone / email attribute 445 of account object 405 and contact object 410 can be stored in the same database table (e.g., telephone / email table 430). As further shown, contact object 415 and employee object 420 can be subtypes of people objects with attributes 450 stored in people table 435. Each row can be identified by a row key to specify the type of people object that the row retains, such as whether it is a contact person or an employee person.
[0131] Since the typical approach of PRS servers is to sniff or monitor wired traffic and perform data encryption or tokenization on protected fields, it may be difficult to integrate this functionality with exploits such as... Figure 4The diagram illustrates the integration of cloud-based applications that share various entity objects. Typically, users might have to configure every UI page of each cloud-based application to tag sensitive fields they wish to protect. For example, even if users share the same underlying database tables or attributes, they might need to configure UI pages for contact object 415 and employee object 420. This becomes extremely challenging in the case of large and complex applications. Even using regular expressions to reduce the workload for administrators, users might still have to traverse all possible UI pages and configure each one individually. Furthermore, because cloud-based applications may have shared and reused components, the same field identifiers might be used on multiple UIs, even if they don't necessarily reflect the actual "meaning" of the field. Using regular expressions is not only cumbersome but can also lead to potential sensitive data leaks or unnecessary performance overhead when protecting non-sensitive data.
[0132] To overcome these problems, in some embodiments, cloud infrastructure system 220 may provide one or more services for self-describing the configuration of entity objects, UI pages, etc., of cloud-based application 245 relative to PRS server 235. Cloud infrastructure system 220 may provide an API that allows administrators of PRS server 235 (e.g., at the request of an organization associated with enterprise infrastructure system 225) to identify sensitive data at the data or component level of cloud-based application 245. For example, an administrator may tag an entity object's Social Security Number attribute 450 at the data level, such that any and all contact objects 415 and employee objects 420 that include the Social Security Number attribute 450 have their data protected, regardless of where the sensitive data is used outside of enterprise infrastructure system 225. In another example, an administrator may tag only certain types of entity objects (e.g., employee object 420) with a Name attribute 450 at the component level, such that only those entity objects used by a given component that includes the Name attribute 450 are protected when used by a given component outside of enterprise infrastructure system 225. The cloud infrastructure system 220 can then dynamically generate mappings between UI elements and tag fields as identified by the PRS server 235. In this way, the cloud infrastructure system 220 can protect shared components regardless of where they are used or what values are associated with identifiers. This reduces the need for the PRS server 235 to maintain multiple entries.
[0133] In one embodiment, once a sensitive data object is identified using PRS server 235, an administrator can (1) add a hint to the underlying data layer of the component and (2) add a protectionKey attribute to the component. When cloud-based application 245 uses protected entity objects to generate UI pages, any data involving these protected components is sent in the payload of network transmission along with a mapping between fields and identifiers recognizable by PRS server 235 to perform necessary data encryption / tokenization. Therefore, when configuring a component, a new attribute named protectionKey can be added to the EditableValue component, which controls whether the component's value should be protected. The value of the attribute can be the name of the component recognizable by PRS server 235. Logic can be added at the data binding layer of cloud-based application 245 to extract the protection hint, which includes the value recognizable by PRS server 235. If protectionKey does not exist at the component level, cloud-based application 245 can retrieve the protectionKey attribute from the data binding layer. For requests sent to cloud-based application 245, if protected data is involved, the build ID mapped to the protectionKey can be included in the payload of the network transmission. Therefore, instead of directly mapping component client identifiers to objects / fields recognizable by the PRS server 235, mappings can be generated on-the-fly based on static configuration.
[0134] Figure 5The diagram illustrates a message sequence diagram providing a self-describing configuration for PRS server 235 in some embodiments. In block 502, cloud infrastructure system 220 provides an API to a data model used by cloud-based application 245, from which PRS server 235 can access the configuration. Providing the API may include providing a server-side endpoint that the application or designer can hit with a request (typically an HTTP request, SOAP request, XML message, etc.). The server-side endpoint can be implemented using an HTTP endpoint with a well-defined URL scheme (e.g., www.enterpirse.com / contacts). In block 504, PRS server 235 uses the provided API to request configuration data for the data model from cloud infrastructure system 220. The configuration data may include a set of protectable attributes / components of entities modeled using the data model (e.g., information about attributes / components that can be configured to withstand confidentiality, residency, and security policies). Request 506 may include HTTP requests, SOAP requests, XML messages, etc. In box 508, cloud infrastructure system 220 provides configuration data that includes a set of protectable attributes / components of entities modeled using a data model. In some embodiments, the configuration data also includes a protection type (e.g., tokenizable or cryptographic) that can be applied to each attribute within the set of protectable attributes.
[0135] In one embodiment, cloud infrastructure system 220 maintains a list of protectable attributes / components used by cloud-based application 245. Cloud infrastructure system 220 may additionally send hints about the list of protectable attributes / components (such as type information of protected fields) to PRS server 220. The hints may provide information about parameters of the protectable data. Cloud infrastructure system 220 returns a response 510 with the following format:
[0136]
[0137]
[0138] In block 512, PRS server 235 uses information received from cloud infrastructure system 220 regarding protectable attributes / components to generate a user interface. The user interface allows an administrator of PRS server 235 to configure one or more protectable attributes / components of an entity modeled as a protected attribute / component. In block 514, an administrator of PRS server 235 (e.g., at the request of an organization associated with enterprise infrastructure system 225) configures one or more protectable attributes / components of an entity modeled in the user interface to be marked as a protected attribute / component, such as the field "fname" in the object "emp". In some embodiments, marking an attribute / component as protected may also include an indication of the type of protection (e.g., tokenization or encryption) to be applied to the attribute / component. In block 516, PRS server 235 notifies cloud infrastructure system 220 of protected attributes / components by sending the protected attribute / component information generated using the user interface to cloud infrastructure system 220. In one embodiment, PRS server 220 sends a message 518 with the following format:
[0139]
[0140] In box 520, cloud infrastructure system 220 marks the specified component or entity object attribute as protected. In box 522, cloud infrastructure system 220 may send confirmation information for the protected field to PRS server 220. Cloud infrastructure system 210 may return a response 524 with the following format:
[0141]
[0142] Figure 6 The diagram illustrates a message sequence diagram utilizing a self-describing configuration in one embodiment of the invention. In block 602, one or more of client devices 205, 210, and 215 request a UI page or client component from cloud infrastructure system 220. Request 604 may include HTTP requests, SOAP requests, XML messages, etc. In block 608, cloud infrastructure system 220 determines an identifier for each protected attribute. In one embodiment, the UI or component runtime associated with cloud-based application 245 (e.g., Oracle ADF Faces rendering) queries the data model level for a tokenized identifier for each protected field. In block 610, cloud infrastructure system 220 generates a UI or client component and tags the protected fields. In response 612, cloud infrastructure system 210 may return the generated UI or client component with the tagged protected fields. The tagged protected fields generated in block 610 are included in the payload of response 612. For example, tagging protected fields may have the following format:
[0143]
[0144] for = "it3::content">Ename <td valign="top"nowrap
[0145] class="xve"> <input id="it3::content"name="it3"style="width:auto"
[0146] class="x25" size="10" maxlength="10" type="text" value="testname"
[0147] protectionKey="EMP_OBJ / Ename_FLD">
[0148] Furthermore, the generated UI or client-side components can have the following formats:
[0149] AdfPage.PAGE.addComponents(newAdfRichInputText('it3',{'columns':10,'maximumLength':10,'protectionKey':'EMP_OBJ / Ename_FLD'));
[0150] Furthermore, subsequent payloads in response 612 may include mapping information in the following format:
[0151] oracle.adf.view.rich.TOKENIZED={'it3':{'EMP_OBJ / Ename_FLD'}'}
[0152] In box 614, PRS server 235 intercepts response 612 and uses the mapping included in the payload of response 612 to populate the UI or client component with any protected data from private database 240. For example, PRS server 235 uses the mapping to...<field name=“fname”protect=“protect”tokenize=“tokenize” / > The randomized tokenized value is stored in private database 240 for the same protected field:<field name=“fname”protect=“protect”tokenize=“tokenize” / > The sensitive data values are replaced. Then, the PRS server 235 forwards the modified response 616 to one or more client devices 205, 210, and 215. In box 618, one or more client devices 205, 210, and 215 display the generated UI or client component, which includes any protected data from the private database 240 in protected fields.
[0153] In block 620, one or more client devices 20, 210, and 215 can publish data to cloud infrastructure system 220. The published data may include changes or updates to sensitive data concerning protected fields within the UI or client components. In one embodiment, the client runtime (e.g., an ADF Faces client) uses tokenized information from the UI or client components to push a feed map to PRS server 235 using a well-known field (e.g., ProtectionKey). For example, PRS server 235 can use this well-known field to look up the PRS server's configuration and find the corresponding action (e.g., encryption or tokenization). In block 622, one or more client devices 205, 210, and 215 insert a mapping into request 624 (e.g., generating an ID->protectionKey mapping, such as...).
[0154] oracle.adf.view.rich.TOKENIZED = {'r1:0:foo:it1':{'object':'emp','field':'fname'}}). One or more client devices 205, 210, and 215 may generate a request 624 as follows to include the mapping from box 622:
[0155] r1:0:foo:it1=SecretFirstName
[0156] r1:0:foo:it5=PublicLastName
[0157] r2:1:bar:it1=publicemail@oracle.com
[0158] javax.faces.ViewState=! -12t5t4tf7q
[0159] org.apache.myfaces.trinidad.faces.FORM=f1
[0160] Adf-Page-Id = 0
[0161] event=b5
[0162] event.b5 = <m xmlns="http: / / oracle.com / richClient / comm"><k
[0163] v = "type"> <s> action< / s>
[0164] oracle.adf.view.rich.PROCESS=f1,b5
[0165] oracle.adf.view.rich.TOKENIZED={'r1:0:foo:it1':{'object':'emp',
[0166] 'field':'fname'}}
[0167] In box 626, PRS server 235 intercepts request 624 and uses a mapping (e.g., ID->protectionKey mapping) to replace any protected data with an encrypted or tokenized value, storing the protected data in private database 225. PRS 235 then forwards the modified request 628 to cloud infrastructure system 220.
[0168] Therefore, the administrator of PRS server 235 can identify sensitive data at the data model / component level and tag them in a self-descriptive manner. Any generated UI elements associated with cloud-based applications can be dynamically mapped to object / field tokens identified by PRS server 235. In this way, shared components will always be protected, regardless of where they are used or what ID value they have. Moreover, there is no need to add multiple entries to PRS server 235.
[0169] V. Supports sharing protected and unprotected data columns within the same table.
[0170] Cloud Database 250 can contain encrypted or tokenized versions of sensitive data. As mentioned above, entity objects can share the same structure and the same database tables. Some entity objects can be protected, while others are not. Traditionally, different database tables are needed to serve different protection configurations, hence the need to replicate database tables.
[0171] To overcome these issues, in some embodiments, when the administrator of the PRS server 235 configures protection rules for components or data objects at the data object layer, they can define distinguishing flags to identify which component or data object a particular row belongs to. Therefore, all components or data objects sharing the same structure but with different protection rules can still share the same database tables. This simplifies the management of maintaining multiple similar database tables, but also allows for the reuse of common logic operating on structurally similar components or data objects without causing any security problems.
[0172] Figure 7 This is an illustration depicting various layers used by a cloud-based application 245 according to an embodiment of the present invention. Layer 710 represents a data table stored in a cloud database 250 used by the cloud-based application 245. The illustrated database table includes at least one column designated as a distinguishing identifier for a component or data object (e.g., a discriminator attribute "TYPE"). The illustrated database table can be configured to support a superset of attributes shared among multiple components or data objects used by the cloud-based application 245. Using the distinguishing identifier, the component or data object to which a particular row belongs can be identified, such as an employee object and a contact object. It should be understood that multiple components or data objects can share the same database table while having different protection rules, such as tokenization, encryption, or unprotected.
[0173] Security configurations (i.e., protection rules for components or data objects) can be placed in a layer above the database tables, such as the data model layer 720. Attributes for each data model, such as TYPE, can be explicitly defined or implied. Because distinguishing markers are built into the data objects, when a data object is used in a cloud-based application 245 (e.g., such as being bound to various UI components), only rows belonging to that data object should be picked up. For example, in the "Emp" object, the "A" attribute is protected, so it has two hints in the data model layer: protectionState and protectionKey. These do not exist for the "A" attribute in the "Contact" object. Furthermore, in the "Contact" object, the "B" attribute is protected, so it has two hints in the data model layer: protectionState and protectionKey. These do not exist for the "B" attribute in the "Emp" object. Therefore, data protection is configured at the data object level, so only rows belonging to the data object will undergo encryption / tokenization.
[0174] Data objects can be bound to one or more UI components in UI layer 730. Typically, a data object is bound to a UI component used to render one or more properties of the data object. For example, a data object from data model layer 720 can be rendered through a UI component such as...<af:inputText id="FIELD1"value="#{EMPbinding.A.inputValue}" / > The standard expression language is exposed to the UI layer 730. In the Document Object Model layer 740, the rendered UI components may include identifiers indicating that certain Document Object Model (DOM) elements are protected fields. As mentioned above, the identifiers may include token identifiers generated by the PRS server 235.
[0175] Figure 8 This is a flowchart of a method 800 for supporting the sharing of the same table for protected and unprotected data columns, according to one embodiment of the present invention. Figure 8 The implementation of method 800 or the processing in method 800 can be executed by software (e.g., instructions or code modules) when executed by the central processing unit (CPU or processor) of a logic machine (such as a computer system or information processing device), by hardware components of an application-specific integrated circuit or electronic device, or by a combination of software and hardware components. Figure 8 The method 800 drawn in the middle starts from step 810.
[0176] In step 810, a database table definition supporting multiple data objects is received. The database table can be defined to support multiple data objects. For example, a personnel table may include columns corresponding to a superset of attributes shared among the multiple data objects. In step 820, at least one column is designated as a distinguishing identifier for the data objects. In some embodiments, predefined columns of the database table can be used, or new columns can be created for the distinguishing identifier.
[0177] In step 830, attributes of data objects backed at least by database tables are designated as protected fields. As discussed above regarding providing self-describing configuration, the administrator of PRS server 235 can request a list of data objects used by cloud-based application 245. The administrator can select which data objects (and / or their individual attributes) are subject to security policies and send this information to cloud-based application 245. Cloud-based application 245 can then configure any database tables, data models, and components that require protection.
[0178] In step 840, the data is stored in a database table that merges protected and unprotected data. Therefore, when the administrator of PRS server 235 configures protection rules for components or data objects at the data object level, they can define distinguishing flags to identify which component or data object a particular row belongs to. Thus, all components or data objects sharing the same structure but with different protection rules can still share the same database table. This simplifies the management of maintaining multiple similar database tables, but also allows for the reuse of common logic operating on structurally similar components or data objects without causing any security issues.
[0179] VI. Automatic operation detection for protected fields
[0180] Because different data objects can have different protected fields, some operations performed by the cloud-based application 245 may become invalid if operations are performed on protected fields. In some embodiments, the cloud-based application 245 can automatically identify operations that may not be supported to avoid user confusion. For example, the cloud-based application 245 can test all possible operators on the protected data and make intelligent decisions about enabling / disabling these operators. This can greatly reduce the amount of work required to avoid generating incorrect results when performing certain operations on protected data. Self-describing configuration is useful in this case because when the protection status of a field is changed, the cloud-based application 245 is aware of the change and can automatically enable / disable any relevant operators. Some examples of operations that can be enabled / disabled include server-side validation of protected data, automatic suggestion of behavior for protected data, allowing exact matches when searching protected data, sorting protected data, etc.
[0181] Figure 9 This is a flowchart of a method 900 for automatic operation detection of protected fields according to an embodiment of the present invention. Figure 9 The implementation of method 900 or the processing in method 900 can be executed by software (e.g., instructions or code modules) when executed by the central processing unit (CPU or processor) of a logic machine (such as a computer system or information processing device), by hardware components of an application-specific integrated circuit or electronic device, or by a combination of software and hardware components. Figure 9 The method 900 shown in the diagram starts from step 910.
[0182] In step 910, a data model layer configuration is generated in the data model layer and received at the PRS server 235. For example, the PRS server 235 can utilize the API of the cloud infrastructure system 220 to obtain data model attributes subject to security policies. The data model layer configuration can have the following format:
[0183]
[0184] In step 920, one or more protected fields are identified. As discussed above regarding providing self-describing configuration, the administrator of PRS server 235 can request a list of data objects used by cloud-based application 245. The administrator can select which data objects (and / or their individual attributes) are subject to security policies and send this information to cloud-based application 245. Cloud-based application 245 can then determine which fields are protected.
[0185] In step 930, operations that can be performed on the protected field are determined. This may include determining whether the protected field is searchable, used in autocomplete, etc. In step 940, the cloud-based application 245 is configured based on the determined operations that can be performed on the protected field. In one embodiment, the cloud-based application 245 may be configured to process only the necessary checks and skip any other validators when processing validators for the protected data. The cloud-based application 245 may be configured to add logic to control the autosuggestion behavior of the protected data. The cloud-based application 245 may be configured to allow only exact match search operators when rendering a query page. The cloud-based application 245 may be configured to disable sorting for columns from the protected data object when rendering a table.
[0186] VII. Joint Search
[0187] One operation that might become ineffective when operating on protected fields, and which can be performed by cloud-based application 245, is searching. Searching becomes challenging when a field is protected. Traditionally, search functionality has been compromised to support only exact matches, or the PRS server 235 must have a complete copy of every single searchable row, with data replication established between cloud database 250 and private database 240. The PRS server 235 then needs to perform searches on both the sensitive data and the rendering logic to render the final results.
[0188] In some embodiments, one or more client devices 205, 210, and 215 can jointly or centrally search search results generated from the private search database 240 and the cloud database 250. Rendering pages associated with the cloud-based application 245 can be very complex. For example, if the PRS server 235 must render the cloud-based application 245, integrating the cloud-based application 245 with the PRS server 235 can be a huge task for users. By using client-side federated search, the integration workload can be reduced, and the cloud-based application 245 can fully render the final result pages, so all pages will have the same look and feel and be consistent. Therefore, federated search makes searches transparent to the end user for both protected and unprotected fields. Furthermore, there is no compromise on searchability regarding sensitive data.
[0189] In various embodiments, one or more client devices 205, 210, and 215 split the original search into two searches. Since each of the one or more client devices 205, 210, and 215 knows which fields are protected and which are not, the one or more client devices 205, 210, and 215 base their searches on... Figure 6 The protected field mapping marked in box 610 is used to separate the original search. A first search is performed using private database 240 against the protected fields (e.g., the search request payload has information for PRS server 235 to perform a client-side search only against the protected fields), and a second search is performed using cloud database 250 against all other fields, including the unprotected fields (e.g., PRS server 235 can then modify the payload information so that cloud-based application 245 knows about new search terms with protection tokens). The first search is performed using PRS server 235 against the protected fields, and the result set (in addition to the original search) is passed to cloud-based application 245. Cloud-based application 245 can assemble the final result set from the first and second searches and render the combined search results page.
[0190] For example, the "firstName" property of the "Emp" object can be protected with `protectKey EMP_OBJ / Ename_FLD`. When a user does search for "FirstName starting with 'B'", the original search request contains all the necessary information. PRS server 235 intercepts the request, searches for "FirstName" in private database 240, updates the request payload with the tokenized values of all matching "FirstNames", and passes the request to cloud-based application 245. Cloud-based application 245 then uses the tokenized values from PRS server 235 to search cloud database 250 and generates the final result dataset used in the final page rendering. The rendered page is sent back to one or more client devices 205, 210, and 215. PRS server 235 intercepts the response and converts the tokenized values to real text before sending it to one or more client devices 205, 210, and 215. The search results for protected fields from PRS server 235 and the search results for unprotected fields directly completed in cloud-based application 245 are combined in the final dataset.
[0191] In various embodiments, when a user initiates a search, if any search criteria are for protected fields, the PRS server 235 can apply the search to the private database 240. The PRS server 235 can generate a result set as a qualified set of rows identified by a row key. The row key set is then sent to the search request to the cloud-based application 245. When the cloud-based application 245 processes the search request, it uses the qualified row key set to filter out the final search results. For example, the row key is used to identify tokenized or encrypted data that matches the search criteria, and the tokenized or encrypted data is added to the search results obtained from running search criteria on unprotected data in the cloud database 250. The final search results are rendered and sent back to one or more client devices 205, 210, and 215 to appear as a response to the original search request.
[0192] Figure 10 This is a flowchart of a method 1000 for joint search according to an embodiment of the present invention. Figure 10 The implementation of method 1000 or the processing in method 1000 can be executed by software (e.g., instructions or code modules) when executed by the central processing unit (CPU or processor) of a logic machine (such as a computer system or information processing device), by hardware components of an application-specific integrated circuit or electronic device, or by a combination of software and hardware components. Figure 10 Method 1000, as shown in the diagram, begins with step 1010.
[0193] In step 1010, a query is received. For example, one or more client devices 205, 210, and 215 may construct a query from information provided by a user, and a cloud-based application 245 may receive the query from one or more client devices 205, 210, and 215. The query may include search criteria applicable to both protected and unprotected fields, such as searching for a person's first and last name, where the first name is unprotected data but the last name is protected data. In step 1020, the search criteria related to the protected fields are sent to a data security provider such as a PRS server 235. In one embodiment, one or more client devices 205, 210, and 215 send the entire query to a PRS server 220 for processing of the protected fields. The PRS server 235 may then send the search results along with the original query to the cloud-based application 230. For example, in step 1030, the search criteria related to public fields are sent along with the results of the protected field search to the cloud-based application. In some embodiments, the search criteria for each private database 225 and cloud database 235 may be sent independently.
[0194] In step 1040, the protected field results and cloud search results are used to render any final search results. In one embodiment, when a user initiates a search, if any search criteria are for protected fields, the PRS server 220 can apply the search to the private database 225. The PRS server can generate a result set as a qualified set of rows identified by a row key. The row key set is then sent to the search request to the cloud-based application 230. When the cloud-based application 230 processes the request, it uses the qualified row key set to filter out the final search results. Only the final search results are rendered and sent back to the client device 215 for display.
[0195] The final search results include a combination of cloud data and tokenized / encrypted data that meet the search criteria for private database 240. The tokenized / encrypted data can be replaced with data from private database 240 before being displayed by one or more client devices 205, 210, and 215. Accordingly, search results from both private database 240 and cloud database 250 can be combined to provide users with a more seamless search experience.
[0196] VIII. Hardware Environment
[0197] In the following description, specific details are set forth for purposes of explanation in order to provide a thorough understanding of embodiments of the invention. However, it will be apparent, however, that various embodiments may be practiced without these specific details. These figures and descriptions are not intended to be limiting.
[0198] The systems depicted in some diagrams can be provided in various configurations. In some embodiments, the system can be configured as a distributed system, wherein one or more components of the system are distributed across one or more networks within a cloud computing system.
[0199] Figure 11 A simplified diagram of a distributed system 1100 for implementing one embodiment of the embodiments is shown. In the illustrated embodiment, the distributed system 1100 includes one or more client computing devices 1102, 1104, 1106, and 1108, which are configured to execute and operate client applications, such as web browsers, proprietary clients (e.g., Oracle Forms), via one or more networks 1110. A server 1112 may be communicatively coupled to remote client computing devices 1102, 1104, 1106, and 1108 via network 1110.
[0200] In various embodiments, server 1112 may be adapted to run one or more services or software applications provided by one or more components of the system. In some embodiments, these services may be provided as web-based services or cloud services or under a Software as a Service (SaaS) model to users of client computing devices 1102, 1104, 1106, and / or 1108. Users operating client computing devices 1102, 1104, 1106, and / or 1108 may then use one or more client applications to interact with server 1112 to utilize the services provided by these components.
[0201] In the configuration illustrated in the figures, software components 1118, 1120, and 1122 of system 1100 are shown as being implemented on server 1112. In other embodiments, one or more components of system 1100 and / or the services provided by these components may also be implemented by one or more of client computing devices 1102, 1104, 1106, and / or 1108. A user operating the client computing device can then utilize one or more client applications to use the services provided by these components. These components may be implemented in hardware, firmware, software, or a combination thereof. It should be recognized that various different system configurations are possible and may differ from the distributed system 1100. The embodiments shown in the figures are therefore an example of a distributed system for implementing the system of the embodiments and are not intended to be limiting.
[0202] Client computing devices 1102, 1104, 1106, and / or 1108 can be portable handheld devices (e.g., Cellular phone Computing tablets, personal digital assistants (PDAs), or wearable devices (e.g., Google) Head-mounted displays (or similar devices) that run Microsoft Windows And / or software for various mobile operating systems (such as iOS, Windows Phone, Android, BlackBerry 10, Palm OS, etc.), and with internet access, email, and SMS services enabled. Or other communication protocols. The client computing device can be a general-purpose personal computer, for example, including those running various versions of Microsoft... Apple Personal computers and / or laptops running Linux operating systems. Client computing devices can be running various commercially available operating systems. Workstation computers operating systems such as UNIX-like operating systems (including, but not limited to, various GNU / Linux operating systems, such as, for example, Google Chrome OS). Alternatively or additionally, client computing devices 1102, 1104, 1106, and 1108 may be any other electronic devices capable of communicating via one or more networks 1110, such as thin client computers, internet-enabled gaming systems (e.g., with or without...). The gesture input device is the Microsoft Xbox game console and / or a personal messaging device.
[0203] Although an exemplary distributed system 1100 with four client computing devices is shown, any number of client computing devices can be supported. Other devices (such as devices with sensors) can interact with server 1112.
[0204] The distributed system 1100 may contain one or more networks 1110, which may be any type of network familiar to those skilled in the art and which may use any of the various commercially available protocols to support data communication, including but not limited to TCP / IP (Transmission Control Protocol / Internet Protocol), SNA (System Network Architecture), IPX (Internet Packet Switching), AppleTalk, etc. By way of example only, the network(s) 1110 may be a local area network (LAN), such as a LAN based on Ethernet, Token Ring, etc. The network(s) 1110 may be a wide area network (WAN) and the Internet. The network 1110 may include virtual networks, including but not limited to Virtual Private Networks (VPNs), intranets, extranets, Public Switched Telephone Networks (PSTN), infrared networks, and wireless networks (e.g., those based on the IEEE 802.11 protocol suite). (and / or any other wireless protocol operating on any network); and / or any combination of these networks and / or other networks.
[0205] Server 1112 may consist of one or more general-purpose computers, dedicated server computers (as an example, including PC (personal computer) servers), Servers can be configured as servers, mid-range servers, mainframe computers, rack-mounted servers, server farms, server clusters, or any other suitable arrangement and / or combination. In various embodiments, server 1112 may be adapted to run one or more services or software applications described in the foregoing disclosure. For example, server 1112 may correspond to a server used to perform the processes described above according to embodiments of this disclosure.
[0206] Server 1112 can run any operating system discussed above, as well as any commercially available server operating system. Server 1112 can also run any of a variety of additional server applications and / or middleware applications, including HTTP (Hypertext Transfer Protocol) servers, FTP (File Transfer Protocol) servers, CGI (Common Gateway Interface) servers, etc. Servers, database servers, etc. Exemplary database servers include, but are not limited to, those commercially available database servers from Oracle, Microsoft, Sybase, IBM, etc.
[0207] In some implementations, server 1112 may include one or more applications to analyze and integrate data feeds and / or event updates received from users of client computing devices 1102, 1104, 1106, and 1108. As an example, data feeds and / or event updates may include, but are not limited to, feed, The server 1112 may receive real-time updates from one or more third-party information sources and continuous data streams. These real-time updates may include real-time events related to sensor data applications, financial tickers, network performance measurement tools (e.g., network monitoring and traffic management applications), clickstream analysis tools, vehicle traffic monitoring, and the like. The server 1112 may also include one or more applications to display data feeds and / or real-time events via one or more display devices of client computing devices 1102, 1104, 1106, and 1108.
[0208] Distributed system 1100 may also include one or more databases 1114 and 1116. Databases 1114 and 1116 may reside in various locations. As an example, one or more of databases 1114 and 1116 may reside on non-transient storage media local to server 1112 (and / or within server 1112). Alternatively, databases 1114 and 1116 may be located remotely from server 1112 and communicate with server 1112 via a network-based connection or a dedicated connection. In one set of embodiments, databases 1114 and 1116 may reside in a storage area network (SAN). Similarly, any necessary files for performing the functions of server 1112 may be appropriately stored locally on server 1112 and / or remotely. In one set of embodiments, databases 1114 and 1116 may include relational databases, such as those provided by Oracle, adapted to store, update, and retrieve data in response to commands in SQL format.
[0209] Figure 12 An exemplary computer system 1200 in which various embodiments of the present invention can be implemented is illustrated. System 1200 can be used to implement any of the computer systems described above. As shown, computer system 1200 includes a processing unit 1204 that communicates with a plurality of peripheral subsystems via a bus subsystem 1202. These peripheral subsystems may include a processing acceleration unit 1206, an I / O subsystem 1208, a storage subsystem 1218, and a communication subsystem 1224. Storage subsystem 1218 includes a tangible computer-readable storage medium 1222 and system memory 1210.
[0210] Bus subsystem 1202 provides a mechanism for enabling various components and subsystems of computer system 1200 to communicate with each other as intended. While bus subsystem 1202 is schematically shown as a single bus, alternative embodiments of the bus subsystem may utilize multiple buses. Bus subsystem 1202 can be any of several types of bus architectures, including memory buses or memory controllers, peripheral buses, and local buses using any architecture across various bus architectures. For example, such architectures may include Industry Standard Architecture (ISA) buses, Micro Channel Architecture (MCA) buses, Enhanced ISA (EISA) buses, Video Electronics Standards Association (VESA) local buses, and Peripheral Component Interconnect (PCI) buses, which may be implemented as Mezzanine buses manufactured according to the IEEE P1386.1 standard.
[0211] A processing unit 1204, which may be implemented as one or more integrated circuits (e.g., a conventional microprocessor or microcontroller), controls the operation of the computer system 1200. One or more processors may be included in the processing unit 1204. These processors may include single-core or multi-core processors. In some embodiments, the processing unit 1204 may be implemented as one or more independent processing units 1232 and / or 1234, each including a single-core or multi-core processor. In other embodiments, the processing unit 1204 may also be implemented as a quad-core processing unit formed by integrating two dual-core processors into a single chip.
[0212] In various embodiments, processing unit 1204 can execute various programs in response to program code and can maintain multiple concurrently executing programs or processes. At any given time, some or all of the program code to be executed can reside in processor(s) 1204 and / or storage subsystem 1218. With appropriate programming, processor(s) 1204 can provide the various functions described above. Computer system 1200 may additionally include processing acceleration unit 1206, which may include digital signal processor (DSP), dedicated processor, etc.
[0213] I / O subsystem 1208 may include user interface input devices and user interface output devices. User interface input devices may include keyboards, pointing devices such as mice or trackballs, touchpads or touchscreens integrated into displays, scroll wheels, click wheels, dials, buttons, switches, keypads, audio input devices with voice command recognition systems, microphones, and other types of input devices. User interface input devices may include, for example, motion sensing and / or gesture recognition devices, such as Microsoft… A motion sensor that enables users to control devices such as Microsoft products using a natural user interface with gestures and voice commands. The 360 game controller's input device interacts with the input device. The user interface input device may also include eye gesture recognition devices, such as detecting eye activity from the user (e.g., "blinking" when taking a photo and / or making menu selections) and translating the eye gesture into the input device (e.g., Google). Google input in ) Blink detector. Additionally, the user interface input device may include enabling the user to interact with a voice recognition system (e.g., ...) via voice commands. Voice recognition sensing devices for interaction with navigators.
[0214] User interface input devices may also include, but are not limited to: 3D mice, joysticks or pointing sticks, game panels and drawing tablets, as well as audio / visual devices such as speakers, digital cameras, digital camcorders, portable media players, webcams, image scanners, fingerprint scanners, barcode readers, 3D scanners, 3D printers, laser rangefinders, and eye-tracking devices. Furthermore, user interface input devices may include, for example, medical imaging input devices such as computed tomography (CT), magnetic resonance imaging (MRI), positron emission tomography (PET), and medical ultrasound equipment. User interface input devices may also include, for example, audio input devices such as MIDI keyboards, digital musical instruments, etc.
[0215] User interface output devices may include display subsystems, indicator lights, or non-visual displays such as audio output devices. Display subsystems may be cathode ray tubes (CRTs), flat panel devices such as those using liquid crystal displays (LCDs) or plasma displays, projection devices, touchscreens, etc. Generally, the term "output device" is used to encompass all possible types of devices and mechanisms for outputting information from computer system 1200 to a user or other computer. For example, user interface output devices may include, but are not limited to, various display devices that visually convey text, graphics, and audio / video information, such as monitors, printers, speakers, headphones, car navigation systems, plotters, voice output devices, and modems.
[0216] Computer system 1200 may include a storage subsystem 1218 containing software elements, shown as currently located within system memory 1210. System memory 1210 may store loadable and executable program instructions on processing unit 1204, as well as data generated during the execution of these programs.
[0217] Depending on the configuration and type of the computer system 1200, the system memory 1210 may be volatile (such as random access memory (RAM)) and / or non-volatile (such as read-only memory (ROM), flash memory, etc.). RAM typically contains data and / or program modules that can be immediately accessed by the processing unit 1204 and / or are currently being operated and executed by the processing unit 1204. In some implementations, the system memory 1210 may include various different types of memory, such as static random access memory (SRAM) or dynamic random access memory (DRAM). In some implementations, such as during startup, a basic input / output system (BIOS) containing basic routines that facilitate the transfer of information between components within the computer system 1200 may typically be stored in ROM. By way of example, but not limitation, the system memory 1210 also includes application programs 1212, program data 1214, and an operating system 1216, which may include client applications, web browsers, middleware applications, relational database management systems (RDBMS), etc. As an example, the operating system 1216 may include various versions of Microsoft... Apple and / or Linux operating system, and various commercially available... Or a UNIX-like operating system (including but not limited to various GNU / Linux operating systems, Google...) OS, etc.) and / or such as iOS, Phone OS 12OS and A mobile operating system based on the OS operating system.
[0218] The storage subsystem 1218 may also provide a tangible computer-readable storage medium for storing basic programming and data structures that provide the functionality of some embodiments. Software (programs, code modules, instructions) that provides the above-described functionality when executed by a processor may be stored in the storage subsystem 1218. These software modules or instructions may be executed by the processing unit 1204. The storage subsystem 1218 may also provide a repository for storing data used according to the present invention.
[0219] Storage subsystem 1200 may also include a computer-readable storage medium reader 1220 that can be further connected to computer-readable storage medium 1222. Together with and optionally in conjunction with system memory 1210, computer-readable storage medium 1222 can generally represent a remote, local, fixed, and / or removable storage device plus storage medium for temporarily and / or more persistently containing, storing, transmitting, and retrieving computer-readable information.
[0220] The computer-readable storage medium 1222 containing code or a portion thereof may also include any suitable medium known or used in the art, including storage and communication media, such as, but not limited to, volatile and non-volatile, removable and non-removable media implemented by any method or technology for storing and / or transmitting information. This may include tangible computer-readable storage media such as RAM, ROM, electrically erasable programmable ROM (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile disc (DVD) or other optical storage, magnetic tape cassettes, magnetic tape, disk storage devices or other magnetic storage devices, or other tangible computer-readable media. This may also include non-tangible computer-readable media such as data signals, data transmissions, or any other media that can be used to transmit desired information and can be accessed by the computing system 1200.
[0221] As an example, computer-readable storage medium 1222 may include a hard disk drive that reads from or writes to a non-removable non-volatile magnetic medium, a disk drive that reads from or writes to a removable non-volatile disk, and a disk drive that reads from or writes to a removable non-volatile disk, such as a CD-ROM, DVD, and [other media]. An optical disc drive that reads from or writes to a removable, non-volatile optical disc (such as a Blu-ray disc or other optical media). Computer-readable storage medium 1222 may include, but is not limited to: Disk drives, flash memory cards, Universal Serial Bus (USB) flash drives, Secure Digital (SD) cards, DVDs, digital audio tapes, etc. Computer-readable storage media 1222 may also include: solid-state drives (SSDs) based on non-volatile memory (such as flash memory-based SSDs, enterprise flash drives, solid-state ROMs, etc.), volatile memory-based SSDs (such as solid-state RAM, dynamic RAM, static RAM, DRAM-based SSDs, magnetoresistive RAM (MRAM) SSDs), and hybrid SSDs using a combination of DRAM-based and flash memory-based SSDs. Disk drives and their associated computer-readable media can provide non-volatile storage of computer-readable instructions, data structures, program modules, and other data for computer system 1200.
[0222] The communication subsystem 1224 provides an interface to other computer systems and networks. The communication subsystem 1224 serves as an interface for receiving data from other systems and sending data from computer system 1200 to other systems. For example, the communication subsystem 1224 enables computer system 1200 to connect to one or more devices via the Internet. In some embodiments, the communication subsystem 1224 may include a radio frequency (RF) transceiver component (e.g., using cellular phone technology, advanced data network technologies such as 3G, 4G, or EDGE (Enhanced Data Rates for Global Evolution), WiFi (IEEE 802.11 series standards), or other mobile communication technologies, or any combination thereof), a global positioning system (GPS) receiver component, and / or other components for accessing wireless voice and / or data networks. In some embodiments, as an addition to or alternative to the wireless interface, the communication subsystem 1224 may provide a wired network connection (e.g., Ethernet).
[0223] In some embodiments, the communication subsystem 1224 may also represent one or more users who can use the computer system 1200 to receive input communications in the form of structured and / or unstructured data feeds 1226, event streams 1228, event updates 1230, etc.
[0224] As an example, the communication subsystem 1224 can be configured to receive data feeds 1226 from users of social networks and / or other communication services in real time, such as... feed, Updates, web feeds such as rich site summary (RSS) feeds, and / or real-time updates from one or more third-party information sources.
[0225] Furthermore, the communication subsystem 1224 can also be configured to receive data in the form of a continuous data stream, which may include event streams 1228 and / or event updates 1230 that are essentially continuous or unbounded real-time events without a clearly defined termination. Examples of applications that generate continuous data may include, for example, sensor data applications, financial price reporting systems, network performance measurement tools (e.g., network monitoring and traffic management applications), clickstream analysis tools, vehicle traffic monitoring, etc.
[0226] The communication subsystem 1224 can also be configured to output structured and / or unstructured data feeds 1226, event streams 1228, event updates 1230, etc. to one or more databases, which can communicate with one or more streaming data source computers coupled to the computer system 1200.
[0227] Computer system 1200 can be one of a variety of types, including handheld portable devices (e.g., Cellular phone Computing tablets, PDAs), and wearable devices (e.g., Google). Head-mounted displays, PCs, workstations, mainframes, kiosks, server racks, or any other data processing systems.
[0228] Due to the ever-evolving nature of computers and networks, the description of the computer system 1200 depicted in the figures is intended only as a concrete example. Many other configurations with more or fewer components than the system depicted in the figures are possible. For example, custom hardware may be used and / or specific elements may be implemented in hardware, firmware, software (including applets), or combinations thereof. Additionally, connections to other computing devices, such as network input / output devices, may be employed. Based on the disclosure and teachings provided herein, those skilled in the art will recognize other ways and / or methods for implementing the various embodiments.
[0229] In the foregoing specification, various aspects of the invention have been described with reference to specific embodiments thereof; however, those skilled in the art will recognize that the invention is not limited thereto. The various features and aspects of the invention described above can be used individually or in combination. Furthermore, embodiments can be used in any number of environments and applications other than those described herein without departing from the broader spirit and scope of this specification. Accordingly, this specification and the accompanying drawings should be considered illustrative rather than restrictive.
Claims
1. A method for performing a joint search, comprising: The computing device receives a first search criterion from a search initiated by a client device for data of a cloud-based application being used by a user of the client device, wherein the first search criterion applies to protected and unprotected fields of the data of the cloud-based application, the data being protected by or not by a data security provider that monitors the communications of the client device; The computing device sends the search criteria related to the protected field of the first search criterion to the data security provider; The computing device receives a first search result for performing a first search on the data of the data security provider based on a search criterion related to the protected field using the first search criterion, wherein the first search result includes tokenized or encrypted data representing data within the protected field of the first search criterion; The computing device sends the first search result and the first search criteria to the cloud-based application. The computing device receives a second search result based on data from the cloud-based application, performed using the first search result and a first search criterion, wherein the second search result includes data from unprotected fields of the first search criterion; The computing device combines the first search result and the second search result into a third search result; as well as The computing device transmits the third search result to the client device.
2. The method of claim 1, wherein receiving the first search result based on data from the data security provider for which the first search was performed includes receiving information identifying replacement data used by the data security provider in the data of the cloud-based application.
3. The method of claim 1, wherein receiving the first search result based on data targeting the data security provider includes receiving a set of row keys that identify one or more rows of data from the cloud-based application.
4. The method of claim 1, wherein combining the first search result and the second search result into the third search result includes filtering the second search result using the first search result.
5. The method of claim 1, wherein combining the first search result and the second search result into the third search result includes merging the second search result and the first search result.
6. A non-transient machine-readable storage medium having instructions stored thereon, the instructions, when executed by one or more processors, causing the one or more processors to perform a method comprising: Receive a first search criterion from a search initiated by a client device for data of a cloud-based application being used by a user of the client device, wherein the first search criterion applies to protected and unprotected fields of the data of the cloud-based application, the data being protected by or not by a data security provider that monitors the communications of the client device; Send the search criteria related to the protected field of the first search criteria to the data security provider; Receive a first search result for performing a first search on the data of the data security provider based on a search criterion related to the protected field using the first search criterion, wherein the first search result includes tokenized or encrypted data representing data within the protected field of the first search criterion; Send the first search result and the first search criteria to the cloud-based application; Receive a second search result based on data from the cloud-based application performed using the first search result and the first search criteria, wherein the second search result includes data from unprotected fields of the first search criteria; Combine the first search result and the second search result into a third search result; as well as The third search result is transmitted to the client device.
7. The non-transient machine-readable storage medium of claim 6, wherein receiving the first search result based on data against the data security provider to perform the first search includes receiving information identifying replacement data used by the data security provider in the data of the cloud-based application.
8. The non-transient machine-readable storage medium of claim 6, wherein receiving the first search result based on data against the data security provider to perform the first search includes receiving a set of row keys that identify one or more rows of data from the cloud-based application.
9. The non-transient machine-readable storage medium of claim 6, wherein combining the first search result and the second search result into the third search result includes filtering the second search result using the first search result.
10. The non-transient machine-readable storage medium of claim 6, wherein combining the first search result and the second search result into the third search result includes merging the first search result and the second search result.
11. A system for performing a joint search, comprising: processor; as well as A memory that stores a set of instructions, which, when executed by the processor, cause the processor to perform the method as described in any one of claims 1-5.
12. An apparatus for performing a joint search, comprising components for performing the method as described in any one of claims 1-5.
Citation Information
Patent Citations
Federated search implemented across multiple search engines
CN101641694A
Method for carrying out a distributed search
CN102057376A