On-Premise Tokenization for Secure Cloud Messaging
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Enterprises face challenges in maintaining data security and cost efficiency, as they insist on keeping data on-premise while software vendors prefer cloud-based messaging servers, leading to security concerns and high maintenance costs with on-premise solutions.
Innovation Solution
A system that tokenizes user data on an on-premise data server before sending it to a cloud-based messaging server for routing, then de-tokenizes it for delivery to the intended user device, allowing secure communication while maintaining data on-premise and utilizing cloud-based routing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If enterprises host data on on-premise data servers to ensure data security, then data security is improved, but maintenance costs and setup time increase significantly
Solution Approach 1:
The system segments the messaging infrastructure into two parts: sensitive user data remains on on-premise data servers while the messaging application and routing logic are hosted on cloud-based messaging servers. This segmentation allows enterprises to maintain data security locally while leveraging cloud services for messaging functionality, thereby reducing maintenance costs and setup time.
Solution Approach 2:
The system introduces an intermediary mechanism where cloud-based messaging servers act as mediators between users. These servers handle message routing, delivery, and application logic without direct access to sensitive user data stored on-premise. This intermediary approach enables secure data localization while providing cloud-based messaging capabilities with lower maintenance overhead.
2Reliability
If enterprises use on-premise data servers to keep data secure, then data security is improved, but setup time increases much higher than cloud-based servers
Solution Approach 1:
By segmenting the system architecture to separate data storage (on-premise) from messaging services (cloud), enterprises can leverage the rapid deployment capabilities of cloud-based messaging servers while maintaining secure on-premise data infrastructure. This eliminates the need to set up entire messaging systems on-premise, significantly reducing setup time.
Solution Approach 2:
The cloud-based messaging servers are pre-configured with messaging application logic, routing rules, and security protocols before deployment. This preliminary configuration on cloud infrastructure allows for rapid setup while on-premise data servers can be connected to existing secure storage systems, reducing overall deployment time compared to building everything from scratch on-premise.
3Reliability
If enterprises maintain on-premise messaging applications to keep data secure, then data security is improved, but feature updates take longer to implement
Solution Approach 1:
The system separates messaging application features (hosted on cloud-based servers) from user data (stored on on-premise servers). This allows feature updates to be deployed independently on cloud infrastructure without requiring changes to on-premise data storage systems, enabling rapid feature updates while maintaining data security.
Solution Approach 2:
Cloud-based messaging servers serve as intermediaries that can be updated and upgraded independently. These servers communicate with on-premise data servers through standardized interfaces, allowing feature updates to propagate quickly through the cloud layer without requiring modifications to the secure on-premise data infrastructure.
4Ease of manufacture
If enterprises host messaging applications on cloud-based servers, then maintenance costs are reduced, but data security concerns arise
Solution Approach 1:
The architecture segments sensitive user data from messaging services, storing data on secure on-premise servers while hosting messaging applications on cloud-based servers. This segmentation allows enterprises to enjoy the cost benefits of cloud-based messaging infrastructure while maintaining data security through local data storage.
Solution Approach 2:
The system uses cloud-based messaging servers as intermediaries that process messages without directly accessing or storing sensitive user data. These intermediary servers handle routing and delivery while on-premise servers securely store data, combining the cost efficiency of cloud services with the security of on-premise data storage.
Data Source
AI summary
The present disclosure relates to system(s) and method(s) for enabling secure and efficient communication between user devices within an organization. Cloud-based messaging services are popular, but organizations hesitate to use them due to the risk of private data residing on public cloud servers. Organizations prefer to host the servers within the organization (on-premise). However, this approach is neither efficient nor cost-effective. The disclosure describes a system and method for secure and efficient communication within an organization that uses an on-premise server to tokenize user messages, i.e. replacing user data in messages with token to generate a tokenized message and sending the tokenized message to the cloud server. In response, the cloud server returns a processed tokenized message, which is then de-tokenized by the on-premise server before forwarding the message to the user. The proposed system is both secure and efficient.


