Protected Field Detection in Cloud Data Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Organizations face challenges in using public cloud services due to data privacy and security regulations, such as HIPAA and PCI DSS, which restrict the movement of personally identifiable information across borders, and the risk of government access to cloud data, discouraging the use of cost-effective cloud solutions.
Innovation Solution
Implementing data obfuscation methods like encryption and tokenization to protect sensitive data, where sensitive information is transformed into unreadable formats or tokens, allowing secure storage and use in the cloud without revealing real data, and using a PRS server to intercept and encrypt or tokenize data transmissions between client devices and cloud applications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If organizations store and process data in public cloud, then cost-effective cloud-based solutions are achieved, but data privacy and security compliance becomes difficult due to regulations like HIPAA and PCI DSS
Solution Approach 1:
The system segments data into protected and non-protected fields, applying different security measures to each. The data model configuration allows selective identification of sensitive attributes that require protection, enabling organizations to maintain cloud storage while complying with data privacy regulations by only protecting necessary fields.
Solution Approach 2:
The patent introduces an intermediary mechanism (data security provider) that monitors communications between cloud applications and client devices. This intermediary automatically detects operations on protected fields and enforces security policies, allowing organizations to use public cloud services while maintaining compliance without manual intervention.
2Reliability
If data is protected through encryption and tokenization, then data security and privacy are improved, but data accessibility and operational capability deteriorate
Solution Approach 1:
The system performs preliminary actions by configuring the data model in advance to identify protected fields and their supported operations. This configuration is done before data operations occur, allowing the system to automatically handle security requirements without impacting real-time data accessibility or operational capability.
Solution Approach 2:
The cloud-based application performs self-service by automatically detecting operations on protected fields and determining whether they are supported based on the configured data model. The application can autonomously handle security compliance without requiring manual intervention, maintaining both security and operational efficiency.
3Reliability
If comprehensive monitoring of cloud application communications is implemented, then data security compliance is improved, but system complexity increases
Solution Approach 1:
The data model configuration serves multiple functions: it identifies protected fields, defines supported operations, and provides the basis for automatic security enforcement. This universal configuration approach consolidates multiple security management tasks into a single mechanism, reducing overall system complexity while maintaining comprehensive monitoring capability.
Data Source
Figure 1
Figure 2
Figure 3A
AI summary
Systems and methods are provided for automatic operation detection on protected fields. A data model configuration can be used to specify which attributes of a data model used by a cloud-based application are protected by a data security provider monitoring communications between the application and a client device. A determination can be made automatically which operations of the cloud-based application are supported for protected fields. The cloud-based application can be configured to enable/disable certain features, such as validators, auto complete, search operators, etc. according to whether the attributes are protected fields.