Secure Domain Data Transfer via Intermediary Mediation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data transfer processes across domains lacking a trust relationship are inefficient, costly, and time-consuming, requiring numerous manual steps, data replication, and lacking security, making them unsuitable for large hosting environments.

Innovation Solution

A communication framework that establishes a secure communication session between domains using a public/private key pair, allowing direct and orchestrated data transfer without replication, backup, or manual intervention, enabling real-time notification of transfer steps and secure encryption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual data transfer process with backup and shared database is used, then data security between tenants is maintained, but transfer time and operational complexity increase significantly

Engineering Contradiction:
Improvedata securityVSAvoidtransfer time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent introduces a trusted intermediary domain that mediates data transfer between source and target domains. The intermediary receives encrypted data from the source domain, stores it temporarily in an isolated manner, and then transfers it to the target domain. This mediator approach maintains security through encryption and isolation while enabling direct transfer that eliminates manual backup and restore operations, significantly reducing transfer time.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent uses encryption to create a secure copy of the data that can be transferred independently. The source domain encrypts data with a key pair, creating an encrypted copy that can be safely transmitted through the intermediary without exposing the original data. This copying mechanism enables parallel processing and eliminates the sequential manual backup-restore process.

Inventive Principle:
Principle #26Copying

2Reliability

If numerous signaling steps are implemented between source and target server farms, then data isolation between tenants is ensured, but process complexity and difficulty of orchestration increase

Engineering Contradiction:
Improvedata isolationVSAvoidprocess complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The intermediary domain consolidates multiple signaling steps into a single coordinated process. Instead of direct complex signaling between source and target domains, all communication flows through the intermediary which manages the transfer workflow. This reduces orchestration complexity while maintaining data isolation through the intermediary's controlled access and encryption mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent merges multiple separate signaling and coordination steps into a unified transfer process managed by the intermediary. The encryption key pair generation, data encryption, temporary storage, and transfer confirmation are combined into a single orchestrated workflow, reducing the number of separate signaling interactions while maintaining security and isolation.

Inventive Principle:
Principle #5Merging (Combining)

3Productivity

If direct data transfer between domains without trust relationship is implemented, then transfer efficiency improves, but security risks increase

Engineering Contradiction:
Improvetransfer efficiencyVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The intermediary domain provides a secure bridge between domains without pre-existing trust relationships. It implements mutual authentication using key pairs, ensuring that both source and target domains are verified before transfer. This enables direct efficient transfer while maintaining security through the intermediary's authentication and encrypted communication channels.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the security parameters by implementing dynamic key pair authentication and encryption. Instead of relying on pre-established trust relationships, the system generates ephemeral key pairs for each transfer session, changing the authentication mechanism to enable secure direct transfer between previously untrusted domains while maintaining high transfer efficiency.

Inventive Principle:
Principle #35Parameter changes

4Reliability

If manual copying and restore operations are performed, then data integrity is verified, but operational cost and time consumption increase

Engineering Contradiction:
Improvedata integrityVSAvoidoperational efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system implements automated self-service mechanisms where the intermediary domain automatically performs data verification, integrity checking, and transfer confirmation without manual intervention. Encryption and decryption operations are automated, and the system self-manages the transfer workflow including error handling and retry logic, eliminating manual operational steps while maintaining data integrity verification.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent implements automated feedback mechanisms where the intermediary receives confirmation from the target domain about successful data restoration and integrity verification. This feedback loop automatically validates data integrity through cryptographic verification and confirms successful transfer, eliminating manual verification steps while ensuring data integrity through automated checking and reporting.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10715494B2Orchestrating work across domains and work streams
Publication Date: 2020.07.14 MICROSOFT TECHNOLOGY LICENSING LLC
  • US10715494B2 patent drawing
  • US10715494B2 patent drawing
  • US10715494B2 patent drawing

AI summary

Aspects of the present disclosure provide systems and methods for directly transferring tenant data hosted on a source domain to a target domain, wherein the source and target domains are associated with different server farms. Additionally, where the source domain is managed by a source management layer and the target domain is managed by target management layer, which source and target management layers are not in a trust relationship. Aspects describe establishing a secure, direct communication bus between the source and target management layers in order to accomplish a plurality of steps involved in transferring the tenant, wherein tenant data transferred thereon is encrypted. In example aspects, the direct communication bus terminates upon completion of the tenant data transfer.