Protected Field Detection in Cloud Data Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizations face challenges in using public cloud services due to data privacy and security regulations, such as HIPAA and PCI DSS, which restrict the movement of personally identifiable information across borders, and the risk of government access to cloud data, discouraging the use of cost-effective cloud solutions.

Innovation Solution

Implementing data obfuscation methods like encryption and tokenization to protect sensitive data, where sensitive information is transformed into unreadable formats or tokens, allowing secure storage and use in the cloud without revealing real data, and using a PRS server to intercept and encrypt or tokenize data transmissions between client devices and cloud applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If organizations store and process data in public cloud, then cost-effective cloud-based solutions are achieved, but data privacy and security compliance becomes difficult due to regulations like HIPAA and PCI DSS

Engineering Contradiction:
Improvecost-effectiveness of cloud solutionsVSAvoiddata privacy and security compliance
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The system segments data into protected and non-protected fields, applying different security measures to each. The data model configuration allows selective identification of sensitive attributes that require protection, enabling organizations to maintain cloud storage while complying with data privacy regulations by only protecting necessary fields.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary mechanism (data security provider) that monitors communications between cloud applications and client devices. This intermediary automatically detects operations on protected fields and enforces security policies, allowing organizations to use public cloud services while maintaining compliance without manual intervention.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If data is protected through encryption and tokenization, then data security and privacy are improved, but data accessibility and operational capability deteriorate

Engineering Contradiction:
Improvedata security and privacyVSAvoiddata accessibility and operational capability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary actions by configuring the data model in advance to identify protected fields and their supported operations. This configuration is done before data operations occur, allowing the system to automatically handle security requirements without impacting real-time data accessibility or operational capability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The cloud-based application performs self-service by automatically detecting operations on protected fields and determining whether they are supported based on the configured data model. The application can autonomously handle security compliance without requiring manual intervention, maintaining both security and operational efficiency.

Inventive Principle:
Principle #25Self-service

3Reliability

If comprehensive monitoring of cloud application communications is implemented, then data security compliance is improved, but system complexity increases

Engineering Contradiction:
Improvedata security complianceVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The data model configuration serves multiple functions: it identifies protected fields, defines supported operations, and provides the basis for automatic security enforcement. This universal configuration approach consolidates multiple security management tasks into a single mechanism, reducing overall system complexity while maintaining comprehensive monitoring capability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3716126B1Automatic operation detection on protected field with support for federated search
Publication Date: 2022.08.24 ORACLE INT CORP
  • EP3716126B1 patent drawingFigure 1
  • EP3716126B1 patent drawingFigure 2
  • EP3716126B1 patent drawingFigure 3A

AI summary

Systems and methods are provided for automatic operation detection on protected fields. A data model configuration can be used to specify which attributes of a data model used by a cloud-based application are protected by a data security provider monitoring communications between the application and a client device. A determination can be made automatically which operations of the cloud-based application are supported for protected fields. The cloud-based application can be configured to enable/disable certain features, such as validators, auto complete, search operators, etc. according to whether the attributes are protected fields.