Data Custodian Region for Public Cloud Sovereignty

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprises face challenges in managing governance, risk, and compliance (GRC) for their services hosted in public clouds, particularly in ensuring data sovereignty, transparency, and control over data access and processing, as existing solutions either compromise on global presence and availability or require building scaled-back private clouds.

Innovation Solution

A data custodian model and platform are implemented within public cloud infrastructures, providing a data custodian region with union definitions for controlling data access, transfer, and storage, along with logging and monitoring of data events to ensure compliance with customer-defined policies, and offering independent visibility and control over data custodian functions like key management and private computing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If enterprises use public cloud infrastructures to host services and store data globally, then service availability and global presence are improved, but data sovereignty and compliance control are worsened

Engineering Contradiction:
Improveservice availabilityVSAvoiddata sovereignty compliance
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the public cloud infrastructure by introducing a data custodian region that is logically separated from the general public cloud environment. This segmentation allows customer data to be isolated in a dedicated region where specific compliance rules can be enforced, while still utilizing the public cloud's global infrastructure for service delivery. The data custodian region acts as a segregated zone that maintains both the benefits of public cloud availability and the control needed for data sovereignty.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a data custodian as an intermediary entity that mediates between the public cloud provider and the customer. This data custodian region serves as a trusted intermediary that enforces compliance policies, monitors data access, and ensures data sovereignty requirements are met. The custodian acts as a bridge that allows enterprises to use public cloud services while maintaining independent visibility and control over their data through policy enforcement mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If enterprises implement strict data access controls and monitoring to ensure compliance, then data security and compliance are improved, but system complexity and operational overhead are worsened

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service mechanisms where the data custodian region automatically enforces compliance policies through union definitions and automated monitoring. Instead of requiring manual intervention for each data access decision, the system uses pre-defined policies that automatically evaluate and control data access requests. This automation reduces operational overhead while maintaining strict security controls, as the system serves itself by making compliance decisions based on established rules.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent changes the parameter of policy enforcement from manual configuration to automated policy-based control. By introducing union definitions that specify compliance requirements as configurable parameters, the system transforms complex security policies into manageable rule sets. This allows enterprises to define their compliance requirements once and have them automatically applied across the data custodian region, reducing the complexity of ongoing security management.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If enterprises use isolated private clouds to ensure data protection and compliance, then data security and compliance control are improved, but scalability and global presence are worsened

Engineering Contradiction:
Improvedata protectionVSAvoidscalability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent merges the benefits of private cloud data protection with public cloud scalability by combining these previously separate approaches into a unified data custodian region. This merged solution allows enterprises to maintain the security and compliance control characteristics of private clouds while leveraging the infrastructure and scalability of public clouds. The data custodian region integrates both models, enabling data to be protected with private cloud-level security while benefiting from public cloud global presence and elastic resources.

Inventive Principle:
Principle #5Merging (Combining)

4Loss of information

If enterprises require transparent monitoring of data access and processing, then compliance visibility is improved, but processing speed and operational efficiency are worsened

Engineering Contradiction:
Improvecompliance visibilityVSAvoidprocessing speed
Core Design Contradiction:
Loss of informationVSSpeed

Solution Approach 1:

The patent applies preliminary action by establishing compliance policies and union definitions before data access operations occur. These pre-configured policies are ready to automatically evaluate data access requests without requiring real-time analysis or manual intervention. By preparing the compliance framework in advance, the system can quickly enforce rules during data operations, maintaining both high visibility into compliance events and fast processing speeds, as the evaluation logic is already in place and optimized.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10726146B2Data custodian model and platform for public clouds
Publication Date: 2020.07.28 SAP SE
  • US10726146B2 patent drawing
  • US10726146B2 patent drawing
  • US10726146B2 patent drawing

AI summary

Implementations are directed to providing a data custodian region within a public cloud, the data custodian region being specific to a customer of an enterprise having services hosted on the public cloud, the public cloud including regional data centers, through which customer data passes and/or is stored, each data center being at a location within a region, storing at least one union definition that is used to control access, transfer, and storage of customer data within respective regional data centers, the at least one union definition being provided by a data custodian associated with the customer, monitoring a plurality of actions of respective workflows executed using the one or more computer-implemented services hosted on the public cloud, for each action, logging a data event within a repository of the data custodian region, and determining whether the data event complies with the at least one union definition.