Data Custodian Region for Public Cloud Sovereignty
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Enterprises face challenges in managing governance, risk, and compliance (GRC) for their services hosted in public clouds, particularly in ensuring data sovereignty, transparency, and control over data access and processing, as existing solutions either compromise on global presence and availability or require building scaled-back private clouds.
Innovation Solution
A data custodian model and platform are implemented within public cloud infrastructures, providing a data custodian region with union definitions for controlling data access, transfer, and storage, along with logging and monitoring of data events to ensure compliance with customer-defined policies, and offering independent visibility and control over data custodian functions like key management and private computing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If enterprises use public cloud infrastructures to host services and store data globally, then service availability and global presence are improved, but data sovereignty and compliance control are worsened
Solution Approach 1:
The patent segments the public cloud infrastructure by introducing a data custodian region that is logically separated from the general public cloud environment. This segmentation allows customer data to be isolated in a dedicated region where specific compliance rules can be enforced, while still utilizing the public cloud's global infrastructure for service delivery. The data custodian region acts as a segregated zone that maintains both the benefits of public cloud availability and the control needed for data sovereignty.
Solution Approach 2:
The patent introduces a data custodian as an intermediary entity that mediates between the public cloud provider and the customer. This data custodian region serves as a trusted intermediary that enforces compliance policies, monitors data access, and ensures data sovereignty requirements are met. The custodian acts as a bridge that allows enterprises to use public cloud services while maintaining independent visibility and control over their data through policy enforcement mechanisms.
2Reliability
If enterprises implement strict data access controls and monitoring to ensure compliance, then data security and compliance are improved, but system complexity and operational overhead are worsened
Solution Approach 1:
The patent implements self-service mechanisms where the data custodian region automatically enforces compliance policies through union definitions and automated monitoring. Instead of requiring manual intervention for each data access decision, the system uses pre-defined policies that automatically evaluate and control data access requests. This automation reduces operational overhead while maintaining strict security controls, as the system serves itself by making compliance decisions based on established rules.
Solution Approach 2:
The patent changes the parameter of policy enforcement from manual configuration to automated policy-based control. By introducing union definitions that specify compliance requirements as configurable parameters, the system transforms complex security policies into manageable rule sets. This allows enterprises to define their compliance requirements once and have them automatically applied across the data custodian region, reducing the complexity of ongoing security management.
3Reliability
If enterprises use isolated private clouds to ensure data protection and compliance, then data security and compliance control are improved, but scalability and global presence are worsened
Solution Approach 1:
The patent merges the benefits of private cloud data protection with public cloud scalability by combining these previously separate approaches into a unified data custodian region. This merged solution allows enterprises to maintain the security and compliance control characteristics of private clouds while leveraging the infrastructure and scalability of public clouds. The data custodian region integrates both models, enabling data to be protected with private cloud-level security while benefiting from public cloud global presence and elastic resources.
4Loss of information
If enterprises require transparent monitoring of data access and processing, then compliance visibility is improved, but processing speed and operational efficiency are worsened
Solution Approach 1:
The patent applies preliminary action by establishing compliance policies and union definitions before data access operations occur. These pre-configured policies are ready to automatically evaluate data access requests without requiring real-time analysis or manual intervention. By preparing the compliance framework in advance, the system can quickly enforce rules during data operations, maintaining both high visibility into compliance events and fast processing speeds, as the evaluation logic is already in place and optimized.
Data Source
AI summary
Implementations are directed to providing a data custodian region within a public cloud, the data custodian region being specific to a customer of an enterprise having services hosted on the public cloud, the public cloud including regional data centers, through which customer data passes and/or is stored, each data center being at a location within a region, storing at least one union definition that is used to control access, transfer, and storage of customer data within respective regional data centers, the at least one union definition being provided by a data custodian associated with the customer, monitoring a plurality of actions of respective workflows executed using the one or more computer-implemented services hosted on the public cloud, for each action, logging a data event within a repository of the data custodian region, and determining whether the data event complies with the at least one union definition.


