Field-Level Metadata Encryption for Multi-Tenant Cloud Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data encryption techniques are resource-intensive and time-consuming, making them impractical for real-time access and multi-tenant cloud environments, where efficient and flexible encryption is necessary to ensure data security and compliance with varying tenant requirements.

Innovation Solution

The system employs field-level metadata to determine encryption requirements for application objects, allowing for transparent, per-tenant encryption capabilities by examining object metadata structures and enabling encryption during data transfer between the application and storage layers, with customizable configurations for efficient resource use.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional bulk encryption methods are used to ensure data security, then data privacy and integrity are improved, but computational resource consumption and processing time increase significantly

Engineering Contradiction:
Improvedata securityVSAvoidcomputational resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent segments the data into individual fields within application objects and applies encryption selectively at the field level rather than encrypting entire data sets. The metadata structure divides encryption configuration into object-level and field-level components, allowing granular control over which data elements require encryption, thereby reducing overall computational overhead while maintaining security for sensitive fields.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by applying different encryption properties to different fields based on their sensitivity and security requirements. The metadata structure allows each field to have its own encryption configuration, enabling encryption to be applied only where necessary rather than uniformly across all data, thus optimizing resource usage while preserving data security for critical information.

Inventive Principle:
Principle #3Local quality

2Reliability

If traditional encryption methods are used to protect data, then data privacy is improved, but real-time access and processing speed deteriorate

Engineering Contradiction:
Improvedata privacyVSAvoidreal-time access speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent performs preliminary action by pre-configuring encryption metadata and determining encryption requirements before actual data processing occurs. The metadata structure is established in advance with field-level encryption flags, allowing the system to quickly identify and encrypt only the necessary fields during data operations without performing comprehensive encryption analysis in real-time, thus maintaining fast access speeds while ensuring privacy protection.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If comprehensive data encryption is implemented to ensure security, then data integrity is improved, but system complexity and implementation difficulty increase

Engineering Contradiction:
Improvedata integrityVSAvoidencryption system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary metadata structure that mediates between the application layer and encryption mechanisms. This metadata layer acts as a configuration interface, allowing encryption rules to be defined and managed separately from the core application logic. The metadata structure serves as a bridge that translates high-level security requirements into specific encryption operations, simplifying system implementation while ensuring data integrity through structured field-level encryption control.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Adaptability or versatility

If field-level encryption is implemented to provide flexible security control, then adaptability to different security requirements is improved, but metadata management complexity increases

Engineering Contradiction:
Improveper-tenant encryption flexibilityVSAvoidmetadata structure complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements universality by designing a metadata structure that serves multiple functions: it stores encryption configuration, identifies sensitive fields, manages per-tenant security requirements, and interfaces with encryption operations. This multi-functional metadata approach consolidates what could be separate complex systems into a unified structure, enabling flexible field-level and per-tenant encryption control while managing complexity through a single coherent metadata framework rather than multiple separate mechanisms.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11354419B2Encryption of application data using field-level metadata
Publication Date: 2022.06.07 SAP SE
  • US11354419B2 patent drawing
  • US11354419B2 patent drawing
  • US11354419B2 patent drawing

AI summary

Techniques are provided for identifying and encrypting fields of an application object at an application layer in a multi-tenant cloud architecture, using an object metadata structure of the application object. Accordingly, transparent, per-tenant encryption capabilities are provided, while enabling transfer of encrypted object data between the application layer and a storage layer.