Data-Centric Property Enforcement for Mobile Cloud Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In mobile and cloud computing systems, ensuring the security, integrity, and consistency of data accessed by various applications is a manual, burdensome, and error-prone process, as traditional program-centric approaches are insufficient for enforcing properties over data, particularly in dynamic ecosystems where data is a valuable and persistent asset.
Innovation Solution
A data-centric approach is adopted, where properties such as consistency, integrity, and security are specified directly over data structures, using a formal declarative language for aggregation and abstraction, allowing for modular verification of data integrity and automatic enforcement of security policies, shifting focus from code to data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a traditional program-centric approach is used to manage data, then the system can operate with simple data structures, but it becomes difficult to enforce security and integrity policies over data
Solution Approach 1:
The patent inverts the traditional program-centric approach by adopting a data-centric approach where data structures are annotated with security and integrity properties directly. Instead of enforcing policies through program logic, the properties are attached to data structures themselves, allowing automated verification of data access and transformation operations.
Solution Approach 2:
The patent introduces an intermediary layer of data structure annotations that act as a mediator between raw data and policy enforcement. These annotations serve as a formal interface that enables automated tools to verify security and integrity properties without requiring complex program analysis.
2Reliability
If data properties are enforced through program analysis, then security policies can be monitored, but the approach becomes manual and error-prone
Solution Approach 1:
The patent enables data structures to self-describe their security and integrity properties through annotations. This self-service mechanism allows automated tools to verify policy compliance without manual intervention, eliminating the error-prone nature of manual program analysis while maintaining high reliability.
Solution Approach 2:
The patent applies preliminary action by annotating data structures with security and integrity properties before data operations occur. This advance preparation enables automated verification tools to check policy compliance proactively, rather than requiring manual post-hoc analysis, thereby improving both reliability and productivity.
3Adaptability or versatility
If raw data is treated as unstructured information, then data can be easily accessed by applications, but it is difficult to specify and enforce properties over the data
Solution Approach 1:
The patent applies local quality by allowing different parts of data structures to have different properties and annotations. Specific fields or elements within a data structure can be marked with security classifications, integrity requirements, or access controls, enabling fine-grained property enforcement while maintaining overall data accessibility.
Solution Approach 2:
The patent creates a composite data structure that combines raw data with metadata annotations. This composite structure integrates the accessibility of raw data with the enforceability of structured properties, allowing applications to access data while automated tools can verify compliance with security and integrity policies.
Data Source
AI summary
A method, system and computer readable program are disclosed for managing data in a computing network. In an embodiment, the invention provides a method comprising obtaining specified data from a database in the computing network, aggregating the specified data in a defined data structure stored in the computing network, and specifying in the data structure properties over the data aggregated in the data structure. In an embodiment, a plurality of services in the computing network use the data in the data structure in accordance with the properties specified in the data structure. In an embodiment, one or more of the services modifies one or more of the properties specified in the data structure based on a transformation by the one or more of the services of the data aggregated in the data structure.


