Protected Field Detection in Cloud Applications
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Organizations face challenges in using public cloud-based solutions due to complex data privacy and security regulations, such as HIPAA and European data protection laws, which restrict the movement of personally identifiable information across borders, and the risk of law enforcement access to cloud data, discouraging the use of cost-effective cloud services.
Innovation Solution
A method involving data model configuration to identify protected fields and determine actions that can be performed on them, enabling or disabling features in cloud-based applications to ensure data privacy and security, using encryption or tokenization to protect sensitive data, and utilizing a PRS server to intercept and encrypt or tokenize data transmissions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If organizations store and process sensitive data in public cloud infrastructure, then cost-effective cloud-based solutions and processing efficiency are improved, but data security, privacy compliance, and control over data access are worsened
Solution Approach 1:
The patent introduces a private cloud infrastructure as an intermediary layer between organizations and public cloud providers. This intermediary infrastructure hosts encrypted data and implements security controls, allowing organizations to leverage public cloud processing capabilities while maintaining data security and compliance through the private cloud's protective functions.
2Reliability
If organizations use encryption to protect sensitive data in the cloud, then data security is improved, but data accessibility and usability are worsened
Solution Approach 1:
The patent implements different encryption and access control mechanisms for different data elements based on their sensitivity levels. Critical personal information is heavily encrypted with strict access controls, while less sensitive data remains more accessible. This local differentiation of security measures allows organizations to maintain security for sensitive data while preserving usability for non-sensitive data.
3Reliability
If organizations implement strict data privacy controls and encryption, then compliance with regulations is improved, but cloud-based application functionality and flexibility are worsened
Solution Approach 1:
The patent implements dynamic access controls and encryption key management that adapt based on user roles, data sensitivity, and operational context. The system can dynamically adjust security measures and data accessibility, allowing cloud applications to maintain full functionality for authorized users while ensuring compliance through context-aware security enforcement.
Data Source
AI summary
Systems and methods are provided for automatic operation detection on protected fields. A data model configuration can be used to specify which attributes of a data model used by a cloud-based application are protected by a data security provider monitoring communications between the application and a client device. A determination can be made automatically which operations of the cloud-based application are supported for protected fields. The cloud-based application can be configured to enable/disable certain features, such as validators, auto complete, search operators, etc. according to whether the attributes are protected fields.


