Automated Provisioning Platform for Encrypted Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The provisioning of data resources across an enterprise is a time-consuming process due to the multitude of steps required, especially when large amounts of data are involved, and is further complicated by remote data storage and security concerns, lacking a convenient mechanism for enabling access while ensuring network security and data encryption.

Innovation Solution

An automated provisioning platform that generates digital certificates, manages encryption keys, defines business units, specifies datasets, and facilitates data sharing, automating the provisioning process to reduce time and effort, using a system that interacts with data services and key management systems to manage access and security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual provisioning steps are performed for data access, then security and authentication can be ensured, but the provisioning process becomes time-consuming and complex

Engineering Contradiction:
Improvesecurity and authenticationVSAvoidprovisioning time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-configuring security certificates, encryption keys, and access policies before data provisioning is needed. The provisioning platform automatically retrieves pre-approved data containers and applies pre-defined security measures, eliminating the need for manual security configuration steps during provisioning.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The provisioning platform enables self-service by automatically handling security operations without manual intervention. The system autonomously manages certificate validation, key retrieval, encryption application, and access policy enforcement, allowing rapid provisioning while maintaining security through automated processes.

Inventive Principle:
Principle #25Self-service

2Adaptability or versatility

If multiple manual steps are performed for data provisioning, then access control can be precise, but the process complexity increases significantly

Engineering Contradiction:
Improveaccess control precisionVSAvoidprovisioning process complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system merges multiple separate provisioning operations into a single integrated process. The provisioning platform combines data container retrieval, security certificate validation, encryption key application, and access policy configuration into one automated workflow, reducing process complexity while maintaining precise access control through unified management.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The provisioning platform provides universal functionality by handling multiple provisioning tasks through a single system. It serves as a multi-functional platform that manages data access, security authentication, encryption operations, and policy enforcement simultaneously, eliminating the need for separate manual processes for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If remote data storage is used for security, then data protection is improved, but access and authentication mechanisms become more complex

Engineering Contradiction:
Improvedata protectionVSAvoidauthentication mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system introduces an intermediary provisioning platform that mediates between data storage and access operations. This platform handles the complexity of remote data access by automatically managing authentication certificates, encryption keys, and access policies, simplifying the authentication mechanism while maintaining secure remote data storage.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Productivity

If automated provisioning is implemented, then provisioning speed increases, but security management becomes more challenging

Engineering Contradiction:
Improveprovisioning speedVSAvoidsecurity management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The automated provisioning platform performs self-service by autonomously managing security operations. It automatically validates certificates, retrieves and applies encryption keys, enforces access policies, and monitors security compliance without human intervention, maintaining robust security management while achieving rapid provisioning through automation.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9729541B2Method and apparatus for migrating encrypted data
Publication Date: 2017.08.08 HERE GLOBAL BV
  • US9729541B2 patent drawing
  • US9729541B2 patent drawing
  • US9729541B2 patent drawing

AI summary

An approach is provided for managing the provisioning and sharing of data among common users of a data service. A provisioning platform associates a security certificate with a business unit based on the submission of a provisioning request. The provisioning platform also associating one or more keys for accessing the data from the data service with a data container of the data service, the business unit, a key manager associated with the business unit, or a combination thereof based on the generation of a policy for establishing the identity of the business unit, for controlling access to data associated with the business unit as maintained by a data service, or a combination thereof based on the security certificate.