Cloud Data Management via On-Premise Storage Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Migrating secure data to a cloud-based environment is impractical due to the lack of permanent storage and regulatory restrictions on disclosing sensitive information, making it difficult to manage secure data in cloud-based networks while maintaining data integrity and compliance with regulations like HIPPA and Sarbanes-Oxley.
Innovation Solution
A cloud management system allows virtual machines to access and update secure data stored on-premise by using translation and encryption mechanisms, ensuring data integrity and compliance, where secure data is masked and encrypted for transmission, and processed without being stored permanently in the cloud.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If secure data is migrated to cloud-based environment, then data processing capability is improved, but data security and regulatory compliance deteriorate due to lack of permanent storage and potential data disclosure
Solution Approach 1:
The system segments the data processing function from data storage. Virtual machines in the cloud perform processing operations on data, while the actual secure data remains stored in the on-premise data store. This separation allows processing capability to be enhanced in the cloud without compromising data security or regulatory compliance by storing sensitive information outside the secure on-premise environment.
Solution Approach 2:
The system introduces an intermediary mechanism where virtual machines access and process data through controlled interfaces with the on-premise data store. Data is transmitted to and from the cloud environment through secure channels with proper authentication and authorization, acting as a mediator that enables cloud processing while maintaining data security and compliance.
2Adaptability or versatility
If virtual machines are instantiated in cloud environment, then computing resource flexibility is improved, but permanent storage capability deteriorates due to transient nature of cloud resources
Solution Approach 1:
The system separates computing resources from storage resources. Virtual machines provide flexible computing power that can be instantiated and terminated as needed, while data persistence is maintained in the on-premise data store. This segmentation allows the system to enjoy cloud-based computing flexibility without relying on transient cloud storage.
Solution Approach 2:
The system extracts the storage function from the cloud-based virtual machines and places it in the on-premise data store. This extraction ensures that permanent storage capability is maintained independently of the transient cloud computing resources, allowing virtual machines to be flexibly instantiated without compromising data persistence.
3Productivity
If secure data is accessed in cloud environment, then processing efficiency is improved, but data integrity and regulatory compliance deteriorate due to potential unauthorized disclosure
Solution Approach 1:
The system uses an intermediary security layer between the cloud virtual machines and the on-premise data store. Data is transmitted through secure channels with authentication and authorization mechanisms that ensure only authorized processing operations can access the data, maintaining data integrity and regulatory compliance while enabling efficient cloud-based processing.
Solution Approach 2:
The system extracts sensitive data from the cloud environment and keeps it in the on-premise data store. Only necessary data is transmitted to cloud virtual machines for processing, and it is deleted or returned to the secure store after use. This extraction approach maintains data integrity and regulatory compliance by ensuring sensitive information does not remain in the cloud environment.
Data Source
AI summary
A processor receives a request to access secure data. The processor translates the request in order to locate the secure data in a secure data store. The processor retrieves the secure data from the secure data store. The processor encodes the secure data to generate protected secure data. The processor transmits the protected secure data from the secure data store to at least one instantiated virtual machine in a cloud-based network.


