Policy-Proof Data Storage With Region-Based Access Validation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Sovereign cloud service providers face high costs and security vulnerabilities when storing resources protected by region-based security policies in data centers located outside the region due to physical risks and unauthorized access, necessitating a more secure and cost-effective solution.
Innovation Solution
Implementing region-based security policies with cryptographic enforcement using a zero-trust model, where entities provide proof of region attributes to access encrypted resources, ensuring only authorized entities can decrypt data, thereby preventing unauthorized access and conserving computing resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If resources protected by region-based security policies are stored in data centers located outside the region, then storage flexibility and cost-effectiveness are improved, but security vulnerabilities and physical risks increase
Solution Approach 1:
The patent segments the storage system into region-specific data centers for resources requiring region-based security policies, while allowing other resources to be stored in centralized locations. This segmentation enables the system to maintain both security compliance and storage flexibility by placing sensitive data in appropriate regional facilities while using centralized data centers for less sensitive workloads.
Solution Approach 2:
The patent introduces a policy verification system as an intermediary between data access requests and the actual data storage locations. This intermediary validates security policies and manages access control, allowing resources to be stored in optimized locations while maintaining security through centralized policy enforcement rather than physical data proximity.
2Reliability
If cryptographic enforcement with zero-trust model is implemented, then data security and unauthorized access prevention are improved, but system complexity increases
Solution Approach 1:
The patent implements preliminary action by pre-establishing and verifying security policies before data access is granted. The policy verification system proactively checks access criteria and cryptographic proofs in advance, ensuring that only authorized entities can access data. This preliminary verification simplifies the overall system by preventing unauthorized access attempts before they occur, rather than requiring complex real-time monitoring and response mechanisms.
3Reliability
If region-based security policies are strictly enforced, then compliance with regional privacy laws is improved, but access restrictions and operational limitations increase
Solution Approach 1:
The patent implements dynamic access control where security policies are not static barriers but flexible frameworks that can adapt to different access scenarios. The policy verification system dynamically evaluates access requests based on the specific data, the requesting entity, and the current context, allowing compliant access when conditions are met while blocking access only when necessary. This dynamic approach maintains compliance while maximizing operational flexibility.
Data Source
AI summary
An entity is enabled to access encrypted resources in response to verifying access criteria of a region-based security policy is met. For example, a resource request to access an encrypted resource is received from an entity. A determination that the encrypted resource is assigned to a first region and is protected by a region-based security policy is made. A proof of a region attribute indicating that the entity possesses the region attribute is received from the entity, the region attribute indicates the entity is associated with the first region. An encrypted version of the region attribute is obtained from a ledger database. The resource request is validated based at least on the encrypted attribute and the proof of the region attribute. A verification is made that an access criteria of the region-based security policy is met. The entity is provided access to the encrypted resource.


