Policy-Based Data Aggregation for Secure Cloud Network Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Configuring network services to operate efficiently in a cloud computing environment, especially when access to sensitive data files is required, is a challenging task due to the complexity of large and distributed network architectures.
Innovation Solution
A policy-based data aggregation service is implemented within a restricted network environment to filter confidential data into a declassified form by applying anonymization and tokenization rules, allowing non-confidential data to be accessible outside the restricted area while maintaining sensitive information secure.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If sensitive data files are accessed for network services configuration, then network service efficiency is improved, but data security and compliance are compromised
Solution Approach 1:
The patent segments data into confidential and non-confidential portions, allowing selective access. The data aggregation service divides data files into segments based on sensitivity, enabling network services to access only non-confidential segments while confidential segments remain protected, thus resolving the contradiction between service efficiency and data security.
Solution Approach 2:
The data aggregation service acts as an intermediary between network services and sensitive data files. It automatically filters and aggregates data, presenting only non-confidential information to network services while maintaining the integrity and security of the original confidential data files, thereby enabling efficient service operation without direct access to sensitive data.
2Productivity
If data is filtered and declassified for external access, then data sharing efficiency is improved, but processing time and complexity increase
Solution Approach 1:
The data aggregation service performs preliminary filtering and declassification of data files before they are accessed by network services. By pre-processing data to identify and remove confidential portions, the system eliminates the need for repeated filtering operations, thus reducing processing time for subsequent data access operations while maintaining high data sharing efficiency.
Data Source
AI summary
A method for data aggregation of declassified sensitive data may include obtaining a policy associated with an isolated region of a service provider. The policy may identify a plurality of rules for declassifying sensitive data accessible within the isolated region. At least a portion of the plurality of rules identified by the policy may be obtained. A file with the sensitive data may be identified, the file being generated within the isolated region. An output file may be generated based on applying the obtained rules to the file. At least a portion of the sensitive data may be filtered out using the obtained rules. The generated output file may be provided for access outside of the isolated region. The sensitive data may be inaccessible by at least another region of the service provider.


