Logical Data Containers with Policy-Based Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Ensuring the security and integrity of computing resources and data across distributed networks is challenging, particularly as network complexity grows, due to the need for secure data storage and access management across multiple geographic locations.

Innovation Solution

The implementation of logical data containers with associated policies that enforce data transformations, such as encryption, based on request features and data characteristics, using cryptographic keys managed by a computing resource service provider to secure data storage and access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If data is stored across distributed networks with multiple geographic locations, then data accessibility and service robustness are improved, but data security and integrity become harder to ensure

Engineering Contradiction:
Improvedata accessibilityVSAvoiddata security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments data into multiple parts and stores them in different logical data containers across distributed networks. Each segment is encrypted separately, and metadata is created to track the segments. This segmentation allows data to be accessed from multiple locations while maintaining security through distributed storage and encryption.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces cryptographic keys and metadata as intermediaries between the data and the access points. The computing resource service provider manages cryptographic keys that encrypt data segments, and metadata serves as an intermediary layer that tracks segments without containing the actual data. This intermediary mechanism enables secure access control across distributed locations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If data is encrypted using cryptographic keys, then data security is improved, but processing and access operations become more complex

Engineering Contradiction:
Improvedata securityVSAvoidprocessing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service mechanisms where the system automatically performs encryption, segmentation, and metadata generation without requiring manual intervention. The computing resource service provider automatically manages cryptographic keys and encrypts data segments when they are stored, reducing the complexity burden on users while maintaining strong security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent creates a universal encryption framework that handles multiple operations through a single cryptographic key management system. The same key management infrastructure supports encryption, decryption, segmentation, and access control across different data types and storage locations, reducing overall system complexity through consolidation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If data segments are distributed across multiple locations, then data availability is improved, but tracking and managing segments becomes more difficult

Engineering Contradiction:
Improvedata availabilityVSAvoidsegment management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent creates metadata copies that track the location and status of each data segment without requiring direct management of the segments themselves. The metadata serves as a simplified representation or copy of the segment information, allowing the system to track and manage segments across distributed locations through this intermediary layer rather than directly handling the complex segment distribution.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS9519696B1Data transformation policies
Publication Date: 2016.12.13 AMAZON TECH INC
  • US9519696B1 patent drawing
  • US9519696B1 patent drawing
  • US9519696B1 patent drawing

AI summary

Data transformation policies specify conditions based at least in part on request features. When a request is received, features of the received request are used to determine any data transformation policies applicable to the request. When a data transformation policy applies to the request, a corresponding data transformation is applied to data responsive to the request. A response to the request comprising transformed data is provided.