Access Revocation Messaging via Separate Channel
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In a multitenant environment, especially in cloud computing, there is a need for customers to control and revoke access to their data shared with service providers, as per GDPR regulations, ensuring secure and compliant data handling.
Innovation Solution
A system and method that includes a data access revocation mechanism, where a customer can send an access revocation message through a separate channel, causing decryption and scrubbing of customer data from storage, using symmetric key pairs and secure messaging channels like Apache Kafka, ensuring secure and compliant data access control.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If customer data is stored in a multitenant cloud environment for service provider access, then data sharing and service delivery are enabled, but data security and access control become compromised
Solution Approach 1:
The patent segments data storage by creating separate encrypted data stores for each customer within the multitenant environment. Each customer's data is isolated in its own encrypted namespace, allowing multiple customers to share the same cloud infrastructure while maintaining individual data security and access control. This resolves the contradiction by enabling data sharing at the infrastructure level while preventing unauthorized access at the data level.
Solution Approach 2:
The patent introduces encryption keys and key management mechanisms as intermediaries between customer data and service providers. The encryption keys act as a mediator that controls access to customer data, allowing service providers to access encrypted data stores without having direct access to the actual customer data. This intermediary layer enables data sharing while maintaining security and compliance with GDPR access control requirements.
2Reliability
If access control mechanisms are implemented for customer data, then data security is improved, but system complexity increases
Solution Approach 1:
The patent implements self-service access control where customers have direct control over their own encryption keys and can independently manage access to their data. The system automatically handles key generation, storage, and rotation without requiring complex centralized key management infrastructure. This self-service approach maintains high data security while reducing system complexity by eliminating the need for sophisticated centralized access control mechanisms.
Solution Approach 2:
The patent changes the fundamental parameter of access control from managing user permissions to managing encryption keys. Instead of implementing complex permission-based access control systems, the solution transforms the problem into key management, where security is achieved through cryptographic parameters rather than access control lists and permission matrices. This parameter change simplifies the system architecture while maintaining strong security guarantees.
3Productivity
If customer data is distributed across multiple data centers for service providers, then service availability is improved, but data access control becomes difficult
Solution Approach 1:
The patent creates a universal encrypted data store architecture that functions identically across all data centers and service providers. The same encryption and access control mechanisms are applied uniformly regardless of which data center or service provider is accessing the data. This universal approach enables data to be distributed across multiple locations for improved availability while maintaining consistent and simplified access control management across the entire distributed system.
Data Source
AI summary
An access revocation system for removing user data from a service provider device includes a processing device and a memory storing instructions for performing an access revocation method. The method includes receiving user data from a user device via a data channel, storing the user data in a data storage module, and receiving an access revocation message via a request channel separate from the data channel. The method also includes decrypting the access revocation message and performing at least one action defined by the access revocation message, the at least one action including scrubbing of user data from the data storage module.


