Secure Multi-Cloud Data Integration via Intermediary Platform

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cloud computing architectures face challenges in securely integrating data across multiple clouds, as transferring confidential data between databases hosted on different clouds can expose sensitive information to insecure environments.

Innovation Solution

A secure multi-cloud integration system is implemented, featuring a data integration platform on a network independent of the clouds, with multiple layers of firewalls and cryptographic protocols, including a key vault module and load balancer, to control and secure data flow between databases hosted on different clouds.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If data is transferred directly between databases on different clouds, then data integration is achieved, but confidential data is exposed to insecure environments

Engineering Contradiction:
Improvedata integration capabilityVSAvoiddata exposure to insecure environments
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a data integration platform as an intermediary component that mediates data transfers between cloud databases. This platform includes service gateways, integration packages, and reverse proxy modules that act as secure intermediaries, preventing direct exposure of confidential data between clouds while enabling necessary data integration through controlled intermediate processing layers.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The data integration platform is segmented into multiple independent components including service gateways, integration packages, reverse proxy modules, and firewall layers. Each segment performs a specific security function, creating a distributed security architecture that prevents single-point failures and reduces the attack surface for potential security breaches.

Inventive Principle:
Principle #1Segmentation

2Reliability

If multiple layers of firewalls and security protocols are implemented, then data security is improved, but system complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The data integration platform is designed as a universal multi-functional system that combines service gateway functions, integration package management, reverse proxy capabilities, and firewall protection into a single integrated platform. This multi-functionality reduces the need for separate independent security components, managing complexity through consolidation while maintaining comprehensive security coverage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system implements feedback mechanisms through logging and monitoring capabilities that track data transfers, authentication events, and security incidents. This feedback enables dynamic security adjustments, automated threat response, and continuous security improvement, reducing the need for overly complex static security configurations.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11546296B2Cloud computing architecture with secure multi-cloud integration
Publication Date: 2023.01.03 BANK OF AMERICA CORP
  • US11546296B2 patent drawing
  • US11546296B2 patent drawing
  • US11546296B2 patent drawing

AI summary

Aspects of the disclosure relate to cloud computing architectures. A system may include a plurality of clouds. One or more of the clouds may transfer data to another one or more of the clouds. A data integration platform may control the data transfer. The transfer may be securely routed through the data integration platform. The transfer may be logged, and the log may be transmitted to an administrative network.