Intermediary Data Bridge for Secure Cloud Analytics
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cloud analytics systems face security risks due to direct access to sensitive data and databases, leading to potential data breaches, and existing methods fail to provide real-time analytics for dynamic cloud services with diverse user access requirements.
Innovation Solution
A separate analytics database is maintained, where data is selectively pushed from the cloud service, filtering sensitive information and allowing restricted access to different user groups, with dynamic logs of service events and adapted database records that include statistical and linguistic analysis, ensuring secure and efficient data access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If direct access to main databases and file repositories is enabled for analytics, then real-time analytics capability is improved, but data security and breach risk worsen
Solution Approach 1:
The patent introduces an intermediary component called the 'data bridge' that sits between the analytics system and the cloud service databases. This data bridge selectively transforms and pushes data to the analytics system, enabling real-time analytics while preventing direct access to sensitive data. The intermediary filters, transforms, and controls data flow, thus resolving the contradiction between analytics capability and security.
Solution Approach 2:
The system segments the data architecture into distinct components: the original cloud service databases, the intermediary data bridge, and the separate analytics database. This segmentation isolates the analytics system from direct access to sensitive data while still providing necessary information through controlled data pushing, thereby maintaining both analytics functionality and security.
2Loss of information
If analytics system directly queries cloud service databases, then data access completeness is improved, but security perimeter lengthening worsens
Solution Approach 1:
The data bridge acts as an intermediary that consolidates the security perimeter. Instead of having to secure both the original databases and the analytics system separately, the security model only needs to protect the data bridge and the analytics database, reducing the overall security perimeter complexity while maintaining complete data access for analytics purposes.
3Measurement precision
If sensitive data is exposed to analytics system, then analytics accuracy is improved, but information security worsens
Solution Approach 1:
The data bridge transforms data parameters before pushing to the analytics system. It converts detailed sensitive data into aggregated, anonymized, or transformed metrics that maintain analytical value while removing sensitive identifiers. This parameter transformation enables accurate analytics on behavioral patterns and trends without exposing personally identifiable information or sensitive data.
Solution Approach 2:
The system applies different data quality levels to different analytics needs. For analytics requiring high accuracy, transformed data with sufficient detail is provided. For analytics where complete sensitivity protection is paramount, more aggregated data is pushed. The data bridge dynamically adjusts the quality and detail of pushed data based on the specific analytics requirements and security constraints.
Data Source
AI summary
Providing analytics information from a cloud service includes maintaining an analytics database that is separate from data and servers accessed by users of the cloud service, selectively pushing information from the cloud service to the analytics database, where data and servers accessed by users of the cloud service are inaccessible for direct access by the analytics database, and allowing users limited access to the analytics database, where users of the analytics information that are accessing the analytics database are restricted from accessing data and servers of the cloud service. The analytics database may include a first database of adapted database records and a second database of dynamic logs of service related events. The adapted database records may be initially formed using the data and servers accessed by users of the cloud service prior to being pushed to the analytics database.


