Cloud Data Security Layer for Confidential Storage
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In Cloud computing environments, data migration between different instances or locations poses a risk of exposing confidential data to insecure environments, as existing technologies lack automatic security measures and often require client-side encryption management, which can be cumbersome and insecure.
Innovation Solution
A method is introduced that includes a security layer between Cloud storage and the access interface, physically separating the storage from a key vault system, which encrypts data and assigns a confidentiality rating, categorizing Cloud zones by trust levels, and stores data accordingly, ensuring secure storage without client-side encryption management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If client-side encryption is implemented to protect data before sending to Cloud storage, then data security is improved, but device complexity and ease of operation deteriorate due to different encryption capabilities and management requirements across client systems
Solution Approach 1:
The patent introduces a security layer as an intermediary component between the client and cloud storage. This security layer handles all encryption operations centrally, eliminating the need for clients to manage encryption keys and algorithms. The security layer receives data from clients, encrypts it using secure algorithms, and stores it in the cloud, thereby improving data security while reducing client-side complexity
Solution Approach 2:
The system provides self-service encryption where the cloud storage system automatically handles encryption without requiring client systems to implement or manage encryption capabilities. The security layer autonomously manages key generation, storage, and rotation, allowing clients to simply upload data without worrying about encryption management
2Reliability
If automatic security measures are implemented for data migration between Cloud instances, then data protection is improved, but device complexity worsens due to additional security layer requirements
Solution Approach 1:
The patent merges the security functions into a centralized security layer that is integrated with the cloud storage system. This security layer combines data encryption, key management, and migration security control into a single unified component, providing automatic protection during data migration while avoiding the complexity of multiple separate security systems
Solution Approach 2:
The security layer performs preliminary encryption actions before data is stored in the cloud or migrated between instances. By encrypting data upfront and managing keys centrally, the system ensures data is protected during migration without requiring complex real-time security measures during the actual data transfer
Data Source
AI summary
A shared networked storage may be separated from a key vault system. A storage request with data to be stored and the storage request with a confidentiality rating may be received. The confidentiality rating may indicate a level of confidentiality the data is associated with. The storage request with the data and the confidentiality rating may be received via a shared networked storage access interface by a security layer. The data to be stored by the key vault system and the confidentiality rating may be encrypted on request of the security layer and into a data container. The shared networked storage may be categorized into Cloud zones. Each Cloud zone may be assigned a trust level. The data container may be stored in one of the Cloud zones of the shared networked storage. The trust level of the one of the Cloud zones may correspond to the confidentiality rating.


