Data Compliance Manifest for Multi-Cloud Workloads

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The enforcement of data compliance in distributed applications across multi-cloud and edge infrastructures is complex and prone to violations due to non-specific and programmatic blind-spots, leading to potential regulatory breaches and associated fines and penalties.

Innovation Solution

A device creates a mapping between the type of data handled by an application and a category of protected data, generating a data compliance manifest that constrains data usage through an ontology-derived approach, enabling automated inference and enforcement of data compliance constraints by workload engines during execution or deployment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data compliance enforcement is performed in distributed applications across multi-cloud and edge infrastructures, then data sovereignty compliance is improved, but system complexity and operational overhead increase

Engineering Contradiction:
Improvedata sovereignty complianceVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a data compliance manifest as an intermediary artifact that bridges application metadata and data sovereignty requirements. The manifest contains structured declarations about data types, locations, and compliance constraints, serving as a mediator between the application layer and compliance enforcement mechanisms, thereby reducing direct complexity while maintaining reliability

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent performs compliance constraint generation and mapping in advance during application deployment or data ingestion phases. By pre-computing compliance constraints and storing them in the manifest before execution, the system avoids real-time compliance analysis complexity while ensuring data sovereignty compliance during runtime

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If automated mapping of application metadata to protected data categories is implemented, then compliance enforcement precision is improved, but processing time and computational resources increase

Engineering Contradiction:
Improvecompliance enforcement precisionVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent performs metadata extraction, ontology mapping, and constraint generation in advance during application deployment or data cataloging phases. By pre-computing the mapping between application metadata and protected data categories and storing results in the compliance manifest, the system achieves high precision without real-time processing overhead

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates a simplified copy or representation of compliance constraints in the manifest that mirrors the complex regulatory requirements in a machine-readable format. This copied representation enables fast, precise matching during execution without requiring repeated analysis of the original complex regulations

Inventive Principle:
Principle #26Copying

3Reliability

If data compliance constraints are generated and enforced programmatically, then violation detection capability is improved, but implementation complexity and development effort increase

Engineering Contradiction:
Improveviolation detection capabilityVSAvoidimplementation complexity
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent introduces the data compliance manifest as an intermediary that translates complex compliance requirements into structured, machine-readable constraints. This manifest serves as a mediator between regulatory requirements and programmatic enforcement, providing a standardized interface that simplifies implementation while maintaining strong violation detection capabilities

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent transforms compliance constraints into parameterized rules that can be systematically applied to different data types and locations. By representing compliance requirements as configurable parameters and constraints in the manifest, the system enables programmatic enforcement through standard software mechanisms rather than custom compliance logic

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20240037132A1Mapping of application data
Publication Date: 2024.02.01 CISCO TECHNOLOGY INC
  • US20240037132A1 patent drawing
  • US20240037132A1 patent drawing
  • US20240037132A1 patent drawing

AI summary

In one embodiment, a device obtains an ontology derived from a data usage restriction document and indicative of a category of protected data. The device obtains metadata indicative of a type of data handled by an application. The device creates a mapping between the type of data handled by the application and the category of protected indicated by the ontology. The device generates, based on the mapping, a data compliance manifest used by a workload engine to constrain use of the type of data during execution of the application or used to constrain use of the type of data during deployment of the application.