Cloud Application Deployment with Secure Data Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprise customers are hesitant to move sensitive data to the cloud due to security concerns and regulatory compliance issues, which inhibits the adoption of cloud computing environments.

Innovation Solution

A method for securely deploying software applications in the cloud by identifying and isolating secure and non-secure data components, deploying secure data on private servers and non-secure data on public cloud servers, using secure connections, and employing a point-of-delivery terminal to manage secure data access, with an access policy to generate exceptions for secure data access events.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If secure data is deployed on public cloud servers, then cloud benefits (cost reduction, resource sharing) are achieved, but security and compliance requirements are violated

Engineering Contradiction:
Improvecloud deployment efficiencyVSAvoiddata security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the application deployment into two distinct parts: secure components deployed on private servers and non-secure components deployed on public cloud servers. This segmentation allows each part to be placed in the most appropriate environment, achieving both security compliance and cloud benefits without compromise.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts secure data and components from the public cloud environment and places them on private servers. This extraction removes the security risk from the public cloud while retaining the ability to use public cloud resources for non-sensitive operations, thus resolving the contradiction between security and cloud utilization.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If all application components are deployed on private servers, then security requirements are met, but cloud benefits (cost reduction, resource sharing) are lost

Engineering Contradiction:
Improvedata securityVSAvoidcloud deployment efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies different deployment qualities to different parts of the system: secure components receive the high-security treatment of private server deployment, while non-secure components benefit from the cost-effectiveness and resource-sharing advantages of public cloud deployment. This local differentiation resolves the contradiction by optimizing each component's deployment location based on its security requirements.

Inventive Principle:
Principle #3Local quality

3Ease of operation

If secure and non-secure data are mixed in the same deployment environment, then deployment simplicity is maintained, but security isolation cannot be achieved

Engineering Contradiction:
Improvedeployment simplicityVSAvoidsecurity isolation
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the application into secure and non-secure components and deploys them in separate environments. The system automatically identifies and separates these components, maintaining security isolation while managing the complexity of dual-environment deployment through automated processes and orchestration.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8984132B2System and method for supporting secure application deployment in a cloud
Publication Date: 2015.03.17 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US8984132B2 patent drawing
  • US8984132B2 patent drawing
  • US8984132B2 patent drawing

AI summary

A method of securely deploying a software application in the Internet cloud including identifying those aspects of a software application that use secure data, and those aspects of the application that use non-secure data, deploying the secure data on one or more secure servers that are not publicly accessible over the Internet, and deploying non-secure data on one or more cloud servers that are publicly available over the Internet, where communication between the secure servers and the cloud servers is managed using secure connections with access only to computation results.