Policy Migration Service for Cloud Data Compliance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional approaches fail to migrate and enforce user policies when data is transferred from on-premises storage to cloud storage environments, as cloud storage systems lack mechanisms to map or translate user policies, leading to compliance, security, and governance issues.
Innovation Solution
Implementing a policy migration service that applies and enforces user-defined tags and policies across data objects, ensuring compliance and security by using policy import/export engines to manage data access and usage, even across trust boundaries, and maintaining a chain of custody through detailed audit logs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If data is migrated from on-premises storage to cloud storage, then storage flexibility and scalability are improved, but policy enforcement capability deteriorates
Solution Approach 1:
The patent introduces a cloud storage system that acts as an intermediary between the user environment and the data repository. This cloud storage system receives data objects with embedded policies from the user environment, stores them in the cloud data repository, and enforces the policies during data access operations. This intermediary approach allows data to be stored flexibly in the cloud while maintaining policy enforcement capability that would otherwise be lost in the migration process.
2Quantity of substance
If conventional cloud storage systems are used, then storage capacity and accessibility are improved, but policy mapping and translation capability deteriorates
Solution Approach 1:
The patent implements preliminary action by embedding the policy information directly into the data object before it is migrated to the cloud storage system. The policy is attached to the data object in the user environment prior to upload, ensuring that the policy information is preserved and available for enforcement during subsequent cloud storage operations. This preliminary attachment of policies eliminates the need for complex policy mapping and translation mechanisms in the cloud storage system.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A customer of a resource provider environment can apply policies at the data object level that will live with a data object during its lifecycle, even as the object moves across trusted boundaries. A customer can classify data, causing tags and/or predicates to be applied to the corresponding data object. Each tag corresponds to a policy, with predicates relating to various actions that can be performed on the data. A chain of custody is maintained for each data object, such that any changes to the object, tags, or policies for the data can be determined, as may be required for various audit processes. The support of such policies also enables the resource provider environment to function as an intermediary, whereby a third party can receive the data along with the tags, policies, and chain of custody as long as the environment trusts the third party to receive the data object.