Policy Migration Service for Cloud Data Compliance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional approaches fail to migrate and enforce user policies when data is transferred from on-premises storage to cloud storage environments, as cloud storage systems lack mechanisms to map or translate user policies, leading to compliance, security, and governance issues.

Innovation Solution

Implementing a policy migration service that applies and enforces user-defined tags and policies across data objects, ensuring compliance and security by using policy import/export engines to manage data access and usage, even across trust boundaries, and maintaining a chain of custody through detailed audit logs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If data is migrated from on-premises storage to cloud storage, then storage flexibility and scalability are improved, but policy enforcement capability deteriorates

Engineering Contradiction:
Improvestorage flexibilityVSAvoidpolicy enforcement capability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a cloud storage system that acts as an intermediary between the user environment and the data repository. This cloud storage system receives data objects with embedded policies from the user environment, stores them in the cloud data repository, and enforces the policies during data access operations. This intermediary approach allows data to be stored flexibly in the cloud while maintaining policy enforcement capability that would otherwise be lost in the migration process.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Quantity of substance

If conventional cloud storage systems are used, then storage capacity and accessibility are improved, but policy mapping and translation capability deteriorates

Engineering Contradiction:
Improvestorage capacityVSAvoidpolicy mapping capability
Core Design Contradiction:
Quantity of substanceVSAdaptability or versatility

Solution Approach 1:

The patent implements preliminary action by embedding the policy information directly into the data object before it is migrated to the cloud storage system. The policy is attached to the data object in the user environment prior to upload, ensuring that the policy information is preserved and available for enforcement during subsequent cloud storage operations. This preliminary attachment of policies eliminates the need for complex policy mapping and translation mechanisms in the cloud storage system.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3757844A1Policy management for data migration
Publication Date: 2020.12.30 AMAZON TECH INC
  • EP3757844A1 patent drawingFigure 1
  • EP3757844A1 patent drawingFigure 2
  • EP3757844A1 patent drawingFigure 3

AI summary

A customer of a resource provider environment can apply policies at the data object level that will live with a data object during its lifecycle, even as the object moves across trusted boundaries. A customer can classify data, causing tags and/or predicates to be applied to the corresponding data object. Each tag corresponds to a policy, with predicates relating to various actions that can be performed on the data. A chain of custody is maintained for each data object, such that any changes to the object, tags, or policies for the data can be determined, as may be required for various audit processes. The support of such policies also enables the resource provider environment to function as an intermediary, whereby a third party can receive the data along with the tags, policies, and chain of custody as long as the environment trusts the third party to receive the data object.