Data Trust Level Tagging for Secure Cloud Domain Processing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cloud computing environments, sensitive data is often processed and stored without adequate control over its movement and processing locations, posing legal and practical challenges for entities handling sensitive information, such as hospitals and governmental institutions, as existing technologies lack mechanisms to ensure data trust levels and secure data flow between domains.

Innovation Solution

A method and apparatus for tagging data with trust levels based on semantic knowledge and content, allowing data to be mapped to specific trust levels, and an apparatus to manage data flow by inspecting and adjusting trust levels to ensure secure processing within or outside a trusted domain, using techniques like service duplication, migration, or data transformation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If data is processed in cloud data centers without control of data flow, then computing resources are unlimited and service efficiency is improved, but data trust level cannot be ensured and sensitive data may be moved to untrusted domains

Engineering Contradiction:
Improveservice efficiencyVSAvoiddata trust level
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies preliminary action by tagging data with trust level metadata before data processing operations. This pre-tagging mechanism ensures that trust level information is available upfront, allowing the system to make informed decisions about data flow and processing locations without compromising security while enabling efficient cloud computing operations

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a trust level metadata tag as an intermediary element between data and processing systems. This intermediary carries trust level information through the data flow, enabling gateways and processing units to verify trust levels without direct inspection of data content, thus maintaining both security and processing efficiency

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If data trust levels are strictly controlled within domains, then data security is improved, but data flow control complexity increases

Engineering Contradiction:
Improvedata securityVSAvoiddata flow control complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies parameter changes by representing trust levels as simple numerical metadata tags rather than complex security policies. This parameterization allows trust level comparison and verification to be performed through simple numerical operations, significantly reducing the complexity of data flow control while maintaining strict security boundaries

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent segments the data flow control mechanism into distinct components: data tagging (adding trust level metadata), gateway inspection (verifying trust levels), and processing unit validation (ensuring trust level requirements are met). This segmentation allows each component to perform its function independently, reducing overall system complexity

Inventive Principle:
Principle #1Segmentation

3Productivity

If processing services are moved outside the domain for efficiency, then service performance is improved, but control over sensitive data processing is reduced

Engineering Contradiction:
Improveservice performanceVSAvoidcontrol over sensitive data
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements feedback by requiring processing units to report their trust levels back to the gateway or data source. This feedback mechanism allows the system to verify that external processing services meet the required trust level criteria, enabling performance optimization through external processing while maintaining control over sensitive data through continuous trust level verification

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10594654B2Data protection control
Publication Date: 2020.03.17 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US10594654B2 patent drawing
  • US10594654B2 patent drawing
  • US10594654B2 patent drawing

AI summary

The invention relates to the field of data processing in a distributed environment, and more particularly control of movement of data and processes so as to achieve a protection that ensures that sensitive data and processes is not moved to untrusted domains. This is achieved by a method and apparatus for tagging of data with a trust level, comprising configuring a data analysis policy for mapping data elements to one of a number of trust levels; receiving a data flow; inspecting the data flow and identifying data elements to be tagged; for a data element to be tagged, analyzing the data element and mapping it to a trust level according to the data analysis policy; and adding the mapped trust level to the data element. This is further achieved by a method and apparatus for data protection, comprising: within a domain as defined by a boundary (10) within which controlled trust levels prevail, starting a service request with associated data to be processed; inspecting a trust level of the data; locating a processing unit (PU) having an associated trust level. Depending on the location of the processing unit within or without the domain, and on the trust level of the located processing unit relative to the trust level of the data, the data is sent out from the domain to the processing unit for processing; or sent to the processing unit configured inside the domain for processing; or the trust level of the data is downgraded to be equal or less than the trust level of the processing unit, and the downgraded data is sent out from the domain to the processing unit for processing.