Policy-Based Data Aggregation for Secure Cloud Network Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Configuring network services to operate efficiently in a cloud computing environment, especially when access to sensitive data files is required, is a challenging task due to the complexity of large and distributed network architectures.

Innovation Solution

A policy-based data aggregation service is implemented within a restricted network environment to filter confidential data into a declassified form by applying anonymization and tokenization rules, allowing non-confidential data to be accessible outside the restricted area while maintaining sensitive information secure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If sensitive data files are accessed for network services configuration, then network service efficiency is improved, but data security and compliance are compromised

Engineering Contradiction:
Improvenetwork service efficiencyVSAvoiddata security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments data into confidential and non-confidential portions, allowing selective access. The data aggregation service divides data files into segments based on sensitivity, enabling network services to access only non-confidential segments while confidential segments remain protected, thus resolving the contradiction between service efficiency and data security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The data aggregation service acts as an intermediary between network services and sensitive data files. It automatically filters and aggregates data, presenting only non-confidential information to network services while maintaining the integrity and security of the original confidential data files, thereby enabling efficient service operation without direct access to sensitive data.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If data is filtered and declassified for external access, then data sharing efficiency is improved, but processing time and complexity increase

Engineering Contradiction:
Improvedata sharing efficiencyVSAvoidprocessing time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The data aggregation service performs preliminary filtering and declassification of data files before they are accessed by network services. By pre-processing data to identify and remove confidential portions, the system eliminates the need for repeated filtering operations, thus reducing processing time for subsequent data access operations while maintaining high data sharing efficiency.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10333901B1Policy based data aggregation
Publication Date: 2019.06.25 AMAZON TECH INC
  • US10333901B1 patent drawing
  • US10333901B1 patent drawing
  • US10333901B1 patent drawing

AI summary

A method for data aggregation of declassified sensitive data may include obtaining a policy associated with an isolated region of a service provider. The policy may identify a plurality of rules for declassifying sensitive data accessible within the isolated region. At least a portion of the plurality of rules identified by the policy may be obtained. A file with the sensitive data may be identified, the file being generated within the isolated region. An output file may be generated based on applying the obtained rules to the file. At least a portion of the sensitive data may be filtered out using the obtained rules. The generated output file may be provided for access outside of the isolated region. The sensitive data may be inaccessible by at least another region of the service provider.