Classified Cloud Region Bootstrapping With Air-Gapped Data Sync

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Building a new data center in a region is a complex and time-consuming process, especially when it involves heightened security restrictions, leading to inefficiencies and errors due to manual coordination and lack of access to restricted data by cloud service providers.

Innovation Solution

A method involving the creation of a virtual bootstrap environment (ViBE) using an orchestration service to automate the bootstrapping process, allowing for the provisioning of a first region with unrestricted data, isolating it, and then air-gapping it before transmitting restricted data to a second classified region, while maintaining data synchronization between regions using data diodes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If each desired region is generated at the same time with unclassified information, then bootstrapping is simplified, but security restrictions and data classification requirements are not properly addressed

Engineering Contradiction:
Improvebootstrapping simplicityVSAvoidsecurity compliance
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent segments the region generation process into distinct phases: unclassified bootstrapping phase and classified data integration phase. This allows the system to first establish regions with unclassified information using simplified processes, then separately handle the secure integration of classified data through controlled data ingress channels, resolving the contradiction between bootstrapping simplicity and security compliance.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies preliminary action by first generating regions with unclassified information before introducing classified data. This preliminary bootstrapping establishes the regional infrastructure without the complexity of classified data handling, allowing security measures to be applied systematically in subsequent phases when classified data is ingested through controlled channels.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If regions are built at different times with manual coordination, then security restrictions can be addressed, but computing resources and man-hours are wasted on replication issues

Engineering Contradiction:
Improvesecurity complianceVSAvoidregion deployment efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements feedback mechanisms through data sync connections that continuously monitor and synchronize data between regions. When regions are built at different times, the feedback system automatically detects and resolves replication issues by synchronizing classified data from the source region to the new region, eliminating manual coordination while maintaining security compliance.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent introduces data sync connections as intermediaries between regions built at different times. These intermediaries automatically manage data replication and synchronization, eliminating the need for manual coordination while ensuring that classified data is properly replicated across regions with different timing, thus improving productivity without compromising security.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If cloud service providers do not have access to restricted data, then security is maintained, but coordination complexity and errors increase

Engineering Contradiction:
Improvedata securityVSAvoidcoordination complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent enables self-service by allowing regions to autonomously ingest and manage their own classified data through controlled data ingress channels. Instead of requiring cloud service providers to manually coordinate data distribution, each region can independently receive classified data through automated sync connections, reducing coordination complexity while maintaining security through the controlled access architecture.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20250385922A1Merging a new region into classified realms
Publication Date: 2025.12.18 ORACLE INT CORP
  • US20250385922A1 patent drawing
  • US20250385922A1 patent drawing
  • US20250385922A1 patent drawing

AI summary

A method may include generating a first cloud network associated with a first security level and including data associated with a service. The method may include generating a second cloud network associated with the first security level and deploying the service and the data associated with the service to the second cloud network and generating a first ingress channel to permit data to be transmitted to the second cloud network. Restricted data associated with a tenant may be deployed to the second cloud network. The method may include generating a third cloud network associated with the first security level and including the service and the data associated with the service and generating a second ingress channel to permit data to be transmitted to the third cloud network. A data sync may be implemented between the second and third cloud networks to deploy the restricted data to the third cloud network.