Location-Based Data Confinement via Encryption Keys

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods do not effectively confine data to specific geographic locations within cloud computing environments, failing to meet the requirements of entities that need to geographically isolate data.

Innovation Solution

An apparatus and method that utilize a processor to identify location restrictions, encrypt data, and confine it to specific data servers based on these restrictions, using encryption keys and data transfer policies to ensure data remains within designated geographic areas.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If data is stored in cloud computing environment with flexible data transfer, then data accessibility and cloud benefits are improved, but data geographic isolation and location control are lost

Engineering Contradiction:
Improvedata accessibilityVSAvoiddata geographic isolation
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies local quality by encrypting data with location-specific encryption keys that are tied to particular geographic regions or data centers. Each location receives a unique encryption key, ensuring that data can only be decrypted and accessed at authorized locations. This resolves the contradiction by maintaining cloud flexibility for authorized access while enforcing geographic isolation through location-dependent decryption capabilities.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements preliminary action by pre-establishing location restrictions and encryption key associations before data transfer occurs. The system预先 identifies the authorized geographic location for data storage and configures the appropriate encryption key in advance. This prevents data from being accessed at unauthorized locations while still allowing flexible transfer within the authorized geographic boundary, thus maintaining both accessibility and geographic isolation.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If data transfer policies are enforced to restrict data movement, then data location control is improved, but data transfer flexibility and cloud computing benefits are reduced

Engineering Contradiction:
Improvedata location controlVSAvoiddata transfer flexibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies parameter changes by dynamically adjusting the encryption state of data based on location parameters. When data is transferred to an authorized location, the system changes the decryption parameter (providing the appropriate encryption key) to enable access. When data is transferred to unauthorized locations, the encryption parameter remains active, preventing decryption. This resolves the contradiction by maintaining transfer flexibility for authorized movements while enforcing location control through conditional decryption.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If encryption is applied to confine data to specific locations, then data security and location restriction are improved, but system complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary component (data migration module or policy enforcement point) that manages encryption key distribution and location restriction enforcement. This intermediary handles the complex tasks of identifying authorized locations, selecting appropriate encryption keys, and controlling data transfer permissions. By centralizing these functions in a dedicated intermediary component, the system achieves strong location-based security without distributing complexity throughout the entire data storage and transfer infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10735388B2Confining data based on location
Publication Date: 2020.08.04 LENOVO SWITZERLAND INTERNATIONAL GMBH
  • US10735388B2 patent drawing
  • US10735388B2 patent drawing
  • US10735388B2 patent drawing

AI summary

For confining data to particular set of data servers based on a location restriction of the data, systems, apparatus, methods, and program products are disclosed. The apparatus may include a storage device for storing data, a processor, and a memory that stores code executable by the processor. In one embodiment, the processor identifies a location restriction of the data, encrypt. In another embodiment, the processor encrypts the data. In a further embodiment, the processor confines the data to particular set of data servers based on the location restriction.