Concealing Customer Data in Virtual Computing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In virtual computing environments, customer sensitive data remains exposed due to the disclosure of application and object names, hindering adoption and increasing administrative overhead, as existing security measures are inadequate to ensure compliance and data protection.
Innovation Solution
A computing platform receives an object name from a user device, hashes or encrypts it, and transmits the concealed name to a virtual computing platform, allowing secure presentation and later decoding for display, thereby protecting sensitive information from exposure.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If object names are disclosed in the virtual control plane, then virtual computing operations can be executed, but customer sensitive data is exposed to external third parties
Solution Approach 1:
The patent introduces a naming service as an intermediary component between the virtual computing platform and the control plane. This naming service receives object name requests, retrieves them from the directory service, and returns concealed names to the virtual computing platform. The intermediary prevents direct exposure of sensitive object names in the control plane while enabling virtual computing operations to proceed with concealed identifiers.
Solution Approach 2:
The patent creates concealed copies of object names that can be used in the virtual control plane without exposing the original sensitive names. The directory service stores both the original object names and concealed name mappings, allowing the virtual computing platform to operate with concealed name copies while the original sensitive names remain protected within the enterprise directory service.
2Reliability
If sensitive information is manually reviewed to ensure compliance, then data security can be maintained, but administrative overhead increases
Solution Approach 1:
The patent implements an automated self-service system where the naming service automatically retrieves object names from the directory service, conceals them according to defined policies, and provides them to the virtual computing platform without requiring manual administrative review. The system self-manages the concealment process, eliminating the need for administrators to manually review each object name for compliance.
Solution Approach 2:
The patent performs preliminary concealment of object names before they are exposed to the virtual control plane. The naming service pre-processes object names by retrieving them from the directory service and applying concealment algorithms in advance, so that only concealed names are ever presented to the external virtual computing platform, eliminating the need for subsequent manual compliance reviews.
3Object-affected harmful factors
If object names are concealed using encryption or hashing, then sensitive data protection is improved, but system complexity increases
Solution Approach 1:
The patent implements a universal naming service that handles multiple functions within a single system component. The naming service performs directory service communication, name concealment through encryption or hashing, policy enforcement, and response generation all within one service. This multi-functional approach consolidates what would otherwise be separate complex systems into a single manageable service that protects sensitive data while maintaining operational simplicity.
Data Source
AI summary
Aspects described herein are directed to the concealment of customer sensitive data in virtual computing arrangements. A local computing platform may receive an object including a customer sensitive object name from a user computing device operating on a same internal domain as the local computing platform. The local computing platform may conceal the customer sensitive object name from a virtual computing platform operating on a domain external from the internal domain. The local computing platform may provide the concealed object name to the virtual computing platform for facilitating object enumeration requests from the user computing device during virtual computing sessions. During a virtual computing session between the user computing device and virtual computing platform, the local computing platform may receive the concealed object name from the user computing device and may perform one or more operations to reveal the object name to the user computing device.


