Cloud Intermediary for Data Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud service providers do not account for individual client needs, leading to challenges in data retention, access, and compliance with varying data retention laws and security protocols across different cloud service providers.

Innovation Solution

A cloud intermediary system that intercepts and processes data communication between users and cloud service providers, applying user-defined policies to manage data retention, access, and security, allowing for independent storage and retrieval of data according to specific user requirements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If cloud service providers use a unified data management approach, then service delivery efficiency is improved, but individual client needs and compliance requirements cannot be met

Engineering Contradiction:
Improveservice delivery efficiencyVSAvoidindividual client needs
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The patent segments the cloud service architecture by introducing a cloud intermediary that separates data management functions into two layers: the service provider's unified infrastructure and the individual user's policy-controlled data. This allows the service provider to maintain efficient unified service delivery while users retain control over their specific data retention and access policies through the intermediary layer.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The cloud intermediary acts as a mediator between users and cloud service providers, enabling users to impose their own data policies without requiring changes to the service provider's infrastructure. The intermediary intercepts data communications, applies user-defined policies for retention and access control, and forwards data to the appropriate service provider, thus resolving the conflict between unified service efficiency and individualized compliance needs.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If cloud service providers implement individualized data policies for each client, then compliance with data retention laws is improved, but system complexity increases

Engineering Contradiction:
Improvecompliance with data retention lawsVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The cloud intermediary serves as a policy enforcement layer that handles individualized data policies without requiring the service provider's system to become complex. Users define their retention and access policies through the intermediary, which then automatically enforces these policies by intercepting and managing data communications. This keeps the service provider's system simple while ensuring compliance with various data retention laws.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Speed

If data is stored directly by cloud service providers, then data access speed is improved, but data security and user control are reduced

Engineering Contradiction:
Improvedata access speedVSAvoiddata security
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The cloud intermediary maintains user control and security by intercepting data communications between users and service providers. Users can define access control policies that determine who can access their data and under what conditions. The intermediary enforces these policies while allowing fast data access through the service provider's infrastructure, thus maintaining both speed and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10051073B1Cloud information services
Publication Date: 2018.08.14 EMC IP HLDG CO LLC
  • US10051073B1 patent drawing
  • US10051073B1 patent drawing
  • US10051073B1 patent drawing

AI summary

A method, article of manufacture, and apparatus for processing data. In some embodiments, this includes determining a policy, intercepting communication between a user and a cloud service provider, applying the determined policy to the intercepted communication, storing at least a portion of the intercepted communication in an intermediary. In some embodiments, information stored in the intermediary may be retrieved without the cloud service provider.