Policy-Proof Data Storage With Region-Based Access Validation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Sovereign cloud service providers face high costs and security vulnerabilities when storing resources protected by region-based security policies in data centers located outside the region due to physical risks and unauthorized access, necessitating a more secure and cost-effective solution.

Innovation Solution

Implementing region-based security policies with cryptographic enforcement using a zero-trust model, where entities provide proof of region attributes to access encrypted resources, ensuring only authorized entities can decrypt data, thereby preventing unauthorized access and conserving computing resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If resources protected by region-based security policies are stored in data centers located outside the region, then storage flexibility and cost-effectiveness are improved, but security vulnerabilities and physical risks increase

Engineering Contradiction:
Improvestorage flexibilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the storage system into region-specific data centers for resources requiring region-based security policies, while allowing other resources to be stored in centralized locations. This segmentation enables the system to maintain both security compliance and storage flexibility by placing sensitive data in appropriate regional facilities while using centralized data centers for less sensitive workloads.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a policy verification system as an intermediary between data access requests and the actual data storage locations. This intermediary validates security policies and manages access control, allowing resources to be stored in optimized locations while maintaining security through centralized policy enforcement rather than physical data proximity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If cryptographic enforcement with zero-trust model is implemented, then data security and unauthorized access prevention are improved, but system complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by pre-establishing and verifying security policies before data access is granted. The policy verification system proactively checks access criteria and cryptographic proofs in advance, ensuring that only authorized entities can access data. This preliminary verification simplifies the overall system by preventing unauthorized access attempts before they occur, rather than requiring complex real-time monitoring and response mechanisms.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If region-based security policies are strictly enforced, then compliance with regional privacy laws is improved, but access restrictions and operational limitations increase

Engineering Contradiction:
ImprovecomplianceVSAvoidaccess flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic access control where security policies are not static barriers but flexible frameworks that can adapt to different access scenarios. The policy verification system dynamically evaluates access requests based on the specific data, the requesting entity, and the current context, allowing compliant access when conditions are met while blocking access only when necessary. This dynamic approach maintains compliance while maximizing operational flexibility.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS20250300992A1Policy proof-based data storage and storage request validation
Publication Date: 2025.09.25 MICROSOFT TECHNOLOGY LICENSING LLC
  • US20250300992A1 patent drawing
  • US20250300992A1 patent drawing
  • US20250300992A1 patent drawing

AI summary

An entity is enabled to access encrypted resources in response to verifying access criteria of a region-based security policy is met. For example, a resource request to access an encrypted resource is received from an entity. A determination that the encrypted resource is assigned to a first region and is protected by a region-based security policy is made. A proof of a region attribute indicating that the entity possesses the region attribute is received from the entity, the region attribute indicates the entity is associated with the first region. An encrypted version of the region attribute is obtained from a ledger database. The resource request is validated based at least on the encrypted attribute and the proof of the region attribute. A verification is made that an access criteria of the region-based security policy is met. The entity is provided access to the encrypted resource.