Protected Field Detection in Cloud Applications

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizations face challenges in using public cloud-based solutions due to complex data privacy and security regulations, such as HIPAA and European data protection laws, which restrict the movement of personally identifiable information across borders, and the risk of law enforcement access to cloud data, discouraging the use of cost-effective cloud services.

Innovation Solution

A method involving data model configuration to identify protected fields and determine actions that can be performed on them, enabling or disabling features in cloud-based applications to ensure data privacy and security, using encryption or tokenization to protect sensitive data, and utilizing a PRS server to intercept and encrypt or tokenize data transmissions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If organizations store and process sensitive data in public cloud infrastructure, then cost-effective cloud-based solutions and processing efficiency are improved, but data security, privacy compliance, and control over data access are worsened

Engineering Contradiction:
Improvedata processing efficiencyVSAvoiddata security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces a private cloud infrastructure as an intermediary layer between organizations and public cloud providers. This intermediary infrastructure hosts encrypted data and implements security controls, allowing organizations to leverage public cloud processing capabilities while maintaining data security and compliance through the private cloud's protective functions.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If organizations use encryption to protect sensitive data in the cloud, then data security is improved, but data accessibility and usability are worsened

Engineering Contradiction:
Improvedata securityVSAvoiddata accessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements different encryption and access control mechanisms for different data elements based on their sensitivity levels. Critical personal information is heavily encrypted with strict access controls, while less sensitive data remains more accessible. This local differentiation of security measures allows organizations to maintain security for sensitive data while preserving usability for non-sensitive data.

Inventive Principle:
Principle #3Local quality

3Reliability

If organizations implement strict data privacy controls and encryption, then compliance with regulations is improved, but cloud-based application functionality and flexibility are worsened

Engineering Contradiction:
Improveregulatory complianceVSAvoidapplication functionality
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic access controls and encryption key management that adapt based on user roles, data sensitivity, and operational context. The system can dynamically adjust security measures and data accessibility, allowing cloud applications to maintain full functionality for authorized users while ensuring compliance through context-aware security enforcement.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10592684B2Automatic operation detection on protected field
Publication Date: 2020.03.17 ORACLE INT CORP
  • US10592684B2 patent drawing
  • US10592684B2 patent drawing
  • US10592684B2 patent drawing

AI summary

Systems and methods are provided for automatic operation detection on protected fields. A data model configuration can be used to specify which attributes of a data model used by a cloud-based application are protected by a data security provider monitoring communications between the application and a client device. A determination can be made automatically which operations of the cloud-based application are supported for protected fields. The cloud-based application can be configured to enable/disable certain features, such as validators, auto complete, search operators, etc. according to whether the attributes are protected fields.