Embedding Policy Tags in Data Objects for Cross-Boundary Enforcement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cloud computing technologies face challenges in enforcing data policies and tags across trust boundaries, leading to hesitation from customers to transmit data due to the loss or disregard of policies and tags when data crosses these boundaries.
Innovation Solution
Embedding tags and policy identifiers in data objects, encoding them in headers or opaque tokens, and ensuring that entities accessing the data agree to enforce policies, allowing for seamless transmission and storage across trust boundaries while transforming policies as necessary for different environments.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If data is transmitted across trust boundaries in cloud environments, then data accessibility and cloud service utilization are improved, but data policies and tags are lost or disregarded
Solution Approach 1:
The patent embeds policy identifiers and tags within the data object structure itself, nesting the metadata inside the data container. This ensures that when data is transmitted across trust boundaries, the embedded policy information travels with the data and can be enforced by resources in different account environments without being lost or discarded.
Solution Approach 2:
The patent introduces policy identifiers as intermediary elements that mediate between the data object and the enforcement mechanisms in different trust boundaries. These identifiers act as references that allow resources in one account environment to access and enforce policies defined in another account environment, enabling cross-boundary policy enforcement without direct policy replication.
2Reliability
If policies are enforced within a trust boundary, then data security and compliance are improved, but customer hesitation to transmit data across boundaries increases
Solution Approach 1:
The patent creates a universal policy enforcement mechanism that works across multiple trust boundaries and account environments. By using standardized policy identifiers and embedded tags that can be recognized and enforced by resources in different environments, the system maintains policy reliability universally rather than being confined to single trust boundaries, thereby reducing customer hesitation.
Solution Approach 2:
The patent performs preliminary embedding of policy identifiers and tags into data objects before transmission occurs. This advance preparation ensures that when data crosses trust boundaries, the policy information is already in place and ready for enforcement, eliminating the need for complex post-transmission policy reconstruction and giving customers confidence that policies will be maintained.
3Reliability
If tags and policy identifiers are embedded in data objects, then policy enforcement across trust boundaries is improved, but data object complexity increases
Solution Approach 1:
The patent applies local quality by embedding only essential policy identifiers and tags directly within data objects, while allowing full policy definitions to remain in their original locations. This selective embedding approach adds minimal complexity to data objects while maintaining the ability to enforce policies across trust boundaries, as only critical identification information needs to travel with the data.
Solution Approach 2:
The patent uses copying by embedding lightweight references (policy identifiers) rather than duplicating entire policy definitions within data objects. This approach maintains policy enforcement capability while minimizing the increase in data object complexity, as the embedded identifiers are compact and can be resolved to full policy definitions when needed by enforcement mechanisms.
Data Source
AI summary
Information for a data object can be prevented from loss for import and export operations across a trust boundary, such as may exist between environments under control of different legal entities. A set of dependencies, including information such as data tags and identifiers for applicable policies, can be embedded in a data object, such as directly in a header or in a digest or token of the data object. When the data object is transmitted across a trust boundary, such as to a destination bucket, the destination bucket can ensure that all dependencies are available and able to be enforced in the destination environment. If not, the request can be denied or the destination environment can contact the source environment to attempt to obtain and enforce the missing dependencies. At least some of the dependencies may also need to be transformed in the second environment.


