Cloud Data Protection System Using Intermediary Mediator

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprises using cloud storage face challenges in controlling and protecting their data, including data loss risks, as they relinquish control over data backup frequencies and types, and cannot perform certain operations like detecting malicious software, especially for sensitive data like healthcare enterprises.

Innovation Solution

A computer-implemented method and system that receives a protection policy from enterprises to specify types of cloud data protection, accesses cloud data from remote services, and performs protection actions such as backup, archiving, and data loss prevention, allowing enterprises to regain control over their data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Area of stationary object

If enterprises use cloud services to store data remotely, then data accessibility and storage capacity are improved, but control over data protection and backup frequency is lost

Engineering Contradiction:
Improvedata storage capacityVSAvoiddata protection control
Core Design Contradiction:
Area of stationary objectVSReliability

Solution Approach 1:

The patent introduces a data protection system as an intermediary between the enterprise and the cloud service provider. This intermediary system retrieves cloud data, performs protection operations (backup, archiving, malware detection), and manages compliance, thereby restoring enterprise control over data protection while maintaining cloud storage benefits

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The data protection functionality is segmented from the cloud storage service itself. Instead of relying on the cloud provider's built-in protection, the enterprise deploys a separate protection system that operates independently, allowing customized backup frequencies and types without compromising cloud storage accessibility

Inventive Principle:
Principle #1Segmentation

2Reliability

If enterprises rely on cloud service backup capabilities, then data redundancy is improved, but customization of backup frequency and types is lost

Engineering Contradiction:
Improvedata redundancyVSAvoidbackup customization
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The protection system implements dynamic backup strategies where the enterprise can specify different backup frequencies and types for different data categories. The system adapts its behavior based on enterprise-defined policies, allowing flexible customization rather than relying on fixed cloud provider defaults

Inventive Principle:
Principle #15Dynamics

3Reliability

If enterprises host data locally on premises, then control over data protection operations is maintained, but data accessibility and storage capacity are limited

Engineering Contradiction:
Improvedata protection controlVSAvoiddata storage capacity
Core Design Contradiction:
ReliabilityVSArea of stationary object

Solution Approach 1:

The data protection system acts as an intermediary layer between local control requirements and cloud storage capabilities. It retrieves data from cloud services, performs protection operations with full enterprise control, and maintains the ability to detect and respond to security threats that would be impossible with purely cloud-hosted data

Inventive Principle:
Principle #24Intermediary (Mediator)

4Ease of operation

If enterprises use cloud storage services, then data accessibility is improved, but ability to perform security operations like malware detection is lost

Engineering Contradiction:
Improvedata accessibilityVSAvoidmalware detection capability
Core Design Contradiction:
Ease of operationVSDifficulty of detecting and measuring

Solution Approach 1:

The protection system retrieves cloud data and performs security operations locally, acting as an intermediary that enables malware detection and other security measures. This approach maintains cloud data accessibility while restoring the ability to perform comprehensive security operations that require direct data access

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9654511B1Cloud data protection
Publication Date: 2017.05.16 COHESITY INC
  • US9654511B1 patent drawing
  • US9654511B1 patent drawing
  • US9654511B1 patent drawing

AI summary

A cloud data protection system protects cloud data of an enterprise. A protection policy for the enterprise is established by an administrator of the enterprise. The protection policy describes one or more types of cloud data protection to provide to the enterprise's cloud data. The cloud data protection system examines the protection policy to identify cloud data associated with the enterprise to access in order to implement the policy, and uses a personality object to retrieve the identified cloud data from one or more cloud services. The cloud data protection system performs one or more protection actions on the retrieved cloud data. The protection actions can include scanning the cloud data for malicious software, for compliance with a data loss prevention policy, or for data matching a discovery specification. The protection actions can also include archiving or backing up the cloud data.