Intermediary Data Bridge for Secure Cloud Analytics

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud analytics systems face security risks due to direct access to sensitive data and databases, leading to potential data breaches, and existing methods fail to provide real-time analytics for dynamic cloud services with diverse user access requirements.

Innovation Solution

A separate analytics database is maintained, where data is selectively pushed from the cloud service, filtering sensitive information and allowing restricted access to different user groups, with dynamic logs of service events and adapted database records that include statistical and linguistic analysis, ensuring secure and efficient data access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If direct access to main databases and file repositories is enabled for analytics, then real-time analytics capability is improved, but data security and breach risk worsen

Engineering Contradiction:
Improvereal-time analytics capabilityVSAvoiddata breach risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary component called the 'data bridge' that sits between the analytics system and the cloud service databases. This data bridge selectively transforms and pushes data to the analytics system, enabling real-time analytics while preventing direct access to sensitive data. The intermediary filters, transforms, and controls data flow, thus resolving the contradiction between analytics capability and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments the data architecture into distinct components: the original cloud service databases, the intermediary data bridge, and the separate analytics database. This segmentation isolates the analytics system from direct access to sensitive data while still providing necessary information through controlled data pushing, thereby maintaining both analytics functionality and security.

Inventive Principle:
Principle #1Segmentation

2Loss of information

If analytics system directly queries cloud service databases, then data access completeness is improved, but security perimeter lengthening worsens

Engineering Contradiction:
Improvedata access completenessVSAvoidsecurity perimeter
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The data bridge acts as an intermediary that consolidates the security perimeter. Instead of having to secure both the original databases and the analytics system separately, the security model only needs to protect the data bridge and the analytics database, reducing the overall security perimeter complexity while maintaining complete data access for analytics purposes.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If sensitive data is exposed to analytics system, then analytics accuracy is improved, but information security worsens

Engineering Contradiction:
Improveanalytics accuracyVSAvoidinformation security
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The data bridge transforms data parameters before pushing to the analytics system. It converts detailed sensitive data into aggregated, anonymized, or transformed metrics that maintain analytical value while removing sensitive identifiers. This parameter transformation enables accurate analytics on behavioral patterns and trends without exposing personally identifiable information or sensitive data.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system applies different data quality levels to different analytics needs. For analytics requiring high accuracy, transformed data with sufficient detail is provided. For analytics where complete sensitivity protection is paramount, more aggregated data is pushed. The data bridge dynamically adjusts the quality and detail of pushed data based on the specific analytics requirements and security constraints.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS9454671B2Selective data transformation and access for secure cloud analytics
Publication Date: 2016.09.27 BENDING SPOONS SPA
  • US9454671B2 patent drawing
  • US9454671B2 patent drawing
  • US9454671B2 patent drawing

AI summary

Providing analytics information from a cloud service includes maintaining an analytics database that is separate from data and servers accessed by users of the cloud service, selectively pushing information from the cloud service to the analytics database, where data and servers accessed by users of the cloud service are inaccessible for direct access by the analytics database, and allowing users limited access to the analytics database, where users of the analytics information that are accessing the analytics database are restricted from accessing data and servers of the cloud service. The analytics database may include a first database of adapted database records and a second database of dynamic logs of service related events. The adapted database records may be initially formed using the data and servers accessed by users of the cloud service prior to being pushed to the analytics database.