Cloud Gateway Secure Data Migration Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

System administrators face logistical challenges in managing data migrations and access control between enterprises and cloud service providers due to varying security needs, policies, and rules, requiring manual configuration and reconfiguration of proxy servers and connectors in a changing environment.

Innovation Solution

A cloud gateway with a mapping and access control system that maps users and groups to roles and permissions, using connectors to encrypt and decrypt data based on access control rules, and manages keys for secure data access and migration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual configuration and reconfiguration of proxy servers and connectors is performed to manage data migrations and access control, then security needs and policies can be addressed, but administrative burden and time consumption increase significantly

Engineering Contradiction:
Improvesecurity controlVSAvoidadministrative time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables self-service automation where the cloud gateway automatically performs user mapping, access control rule enforcement, and connector configuration based on predefined policies. The mapping between enterprise directories and cloud service directories is automatically maintained, and access controls are dynamically applied without requiring manual administrative intervention for each data migration or access request.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary configuration by pre-establishing mapping relationships between enterprise users/groups and cloud service directories, and pre-defining access control rules and policies. This preliminary setup allows the system to automatically handle subsequent data migrations and access requests without requiring manual reconfiguration, thereby reducing administrative time while maintaining security control.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If proxy servers and connectors are manually reconfigured in a changing environment, then access control can be maintained, but device complexity and operational difficulty increase

Engineering Contradiction:
Improveaccess controlVSAvoidoperational ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The cloud gateway automatically detects changes in the enterprise directory structure and cloud service directory structure, and self-adjusts the mapping relationships and access control configurations. This eliminates the need for manual reconfiguration operations, making the system easy to operate while maintaining reliable access control in dynamic environments.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system continuously monitors and detects changes in directory structures and access patterns, and automatically adjusts mapping and access control rules based on this feedback. This closed-loop approach maintains access control reliability while eliminating manual operational complexity.

Inventive Principle:
Principle #23Feedback

3Reliability

If connectors encrypt and decrypt data for each access request, then data security is improved, but processing time and system complexity increase

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The cloud gateway implements a universal encryption/decryption mechanism that applies to all data migrations and access requests through centralized connectors. Rather than implementing separate encryption logic in each application or connector, the system provides a unified encryption service that handles all data security requirements through standardized processes, reducing overall system complexity while maintaining data security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Measurement precision

If manual mapping and access control configuration is performed for each cloud service, then precise control is achieved, but productivity and efficiency decrease

Engineering Contradiction:
Improvecontrol precisionVSAvoiddata migration efficiency
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system implements universal mapping and access control mechanisms that work across multiple cloud services simultaneously. Rather than requiring separate manual configuration for each cloud service, the cloud gateway provides centralized mapping and access control that automatically applies to all connected cloud services, thereby maintaining precise control while significantly improving productivity and data migration efficiency.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system performs preliminary mapping between enterprise directories and cloud service directories once, and this mapping is automatically maintained and applied across all cloud services. This preliminary action eliminates the need for repeated manual configuration for each service, achieving both precise control and high productivity.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3269117B1Secure and control data migrating between enterprise and cloud services
Publication Date: 2020.04.29 THALES DIS CPL USA INC
  • EP3269117B1 patent drawingFigure 1
  • EP3269117B1 patent drawingFigure 2~3
  • EP3269117B1 patent drawingFigure 4

AI summary

A method for operating a cloud gateway is provided. The method includes generating a plurality of rules relating users and groups to data access at a plurality of cloud service providers. The method includes encrypting, at one of a plurality of connectors, outgoing data that is moving through a cloud gateway en route from a proxy server to one of the plurality of cloud service providers, responsive to a data write request associated with a first user, the encrypting in accordance to one of the plurality of rules as related to the first user. The method includes decrypting, at one of the plurality of connectors, incoming data that is moving through the cloud gateway en route from one of the plurality of cloud service providers to the server, responsive to a data read request associated with a second user, the decrypting in accordance to one of the plurality of rules as related to the second user.