Cloud Application Deployment with Secure Data Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Enterprise customers are hesitant to move sensitive data to the cloud due to security concerns and regulatory compliance issues, which inhibits the adoption of cloud computing environments.
Innovation Solution
A method for securely deploying software applications in the cloud by identifying and isolating secure and non-secure data components, deploying secure data on private servers and non-secure data on public cloud servers, using secure connections, and employing a point-of-delivery terminal to manage secure data access, with an access policy to generate exceptions for secure data access events.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If secure data is deployed on public cloud servers, then cloud benefits (cost reduction, resource sharing) are achieved, but security and compliance requirements are violated
Solution Approach 1:
The patent segments the application deployment into two distinct parts: secure components deployed on private servers and non-secure components deployed on public cloud servers. This segmentation allows each part to be placed in the most appropriate environment, achieving both security compliance and cloud benefits without compromise.
Solution Approach 2:
The patent extracts secure data and components from the public cloud environment and places them on private servers. This extraction removes the security risk from the public cloud while retaining the ability to use public cloud resources for non-sensitive operations, thus resolving the contradiction between security and cloud utilization.
2Reliability
If all application components are deployed on private servers, then security requirements are met, but cloud benefits (cost reduction, resource sharing) are lost
Solution Approach 1:
The patent applies different deployment qualities to different parts of the system: secure components receive the high-security treatment of private server deployment, while non-secure components benefit from the cost-effectiveness and resource-sharing advantages of public cloud deployment. This local differentiation resolves the contradiction by optimizing each component's deployment location based on its security requirements.
3Ease of operation
If secure and non-secure data are mixed in the same deployment environment, then deployment simplicity is maintained, but security isolation cannot be achieved
Solution Approach 1:
The patent segments the application into secure and non-secure components and deploys them in separate environments. The system automatically identifies and separates these components, maintaining security isolation while managing the complexity of dual-environment deployment through automated processes and orchestration.
Data Source
AI summary
A method of securely deploying a software application in the Internet cloud including identifying those aspects of a software application that use secure data, and those aspects of the application that use non-secure data, deploying the secure data on one or more secure servers that are not publicly accessible over the Internet, and deploying non-secure data on one or more cloud servers that are publicly available over the Internet, where communication between the secure servers and the cloud servers is managed using secure connections with access only to computation results.


