Multi-Layer Compliance Boundaries for Cloud Data Segregation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for implementing permissions in cloud environments are cumbersome and inefficient, often resulting in unauthorized access to data due to the tedious administration of role-based access control techniques, especially in electronic discovery scenarios.

Innovation Solution

The system creates compliance boundaries using multiple layers to segregate data, allowing only authorized compliance administrators access to specific data sets within these boundaries, using a compliance tool that maps compliance boundary attributes to administrators and users, thereby ensuring secure and efficient access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If role-based access control techniques are used for regulating access to data, then access permissions can be defined for different user roles, but the administration becomes tedious and difficult, resulting in unauthorized access

Engineering Contradiction:
Improveaccess control reliabilityVSAvoidpermission administration ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments the cloud environment into multiple compliance boundaries, each representing a distinct regulatory or organizational domain. These boundaries divide the data space into isolated zones with specific access rules, transforming the monolithic permission management into manageable segments. Each boundary can be independently configured and administered, reducing the complexity of overall access control while maintaining reliability through structured organization.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces compliance boundaries as intermediary layers between users and data. These boundaries act as mediators that automatically enforce access policies without requiring manual permission administration for each data access request. The boundaries serve as the intermediary mechanism that resolves the contradiction by automating what would otherwise be tedious manual permission management, thereby improving both reliability and ease of operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If permissions are circumvented to allow unbound access for electronic discovery, then enterprises can access all data to respond to requests, but authorized users may access data they should not access

Engineering Contradiction:
Improveelectronic discovery efficiencyVSAvoiddata access authorization
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements dynamic compliance boundaries that can be flexibly configured to meet different electronic discovery requirements. The boundaries are not static restrictions but dynamic filters that adapt to specific discovery needs while maintaining authorization rules. This allows enterprises to efficiently access relevant data for electronic discovery while the system dynamically enforces which data each user is authorized to access, resolving the contradiction between discovery efficiency and access control reliability.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameters of access control by introducing compliance boundary attributes that can be modified without altering the fundamental authorization model. By changing parameters such as boundary scope, visibility, and access rules, the system enables efficient electronic discovery access while maintaining authorization integrity. The parameter-based approach allows flexible configuration for different discovery scenarios without compromising the reliability of access control.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If multiple compliance boundaries are created to segregate data, then access security is improved, but system complexity increases

Engineering Contradiction:
Improvedata access securityVSAvoidcompliance boundary system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent designs compliance boundaries with universal characteristics that allow them to serve multiple functions simultaneously. Each boundary not only provides security isolation but also enables efficient query routing, access policy enforcement, and audit tracking. This multi-functionality reduces the need for separate complex systems for each function, thereby improving security while managing overall system complexity through consolidated, versatile boundary structures.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3669296B1Compliance boundaries for multi-tenant cloud environment
Publication Date: 2022.05.04 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP3669296B1 patent drawingFigure 1
  • EP3669296B1 patent drawingFigure 2
  • EP3669296B1 patent drawingFigure 3

AI summary

Aspects of the present disclosure relate to systems and methods for creating compliance boundaries. In one example, compliance boundaries may be implemented via a compliance tool. Data associated with a tenant may be segregated using a plurality of layers defining one or more compliance boundaries. In response to an action initiated by a compliance administrator using the compliance tool for accessing the data, it may be determined which data is within the one or more compliance boundaries associated with the compliance administrator. Access to the data determined to be within the one or more compliance boundaries associated with the compliance administrator may be authorized.