Reverse Firewall Gateway for Data Center Privacy Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data center security methods, including encryption and firewalls, are inadequate in preventing unauthorized access and protecting sensitive data from privacy attacks, as they fail to effectively authenticate authorized parties and deny access to determined hackers.

Innovation Solution

A computer network data center equipped with a reverse firewall and encryption-enabled gateway over a multiplexed communication channel, utilizing a persistent storing device and a multi-core parallel modeling system to process and anonymize data, ensuring that only processed and anonymized information is accessible, while keeping raw data secure and inaccessible via the internet.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional firewall and encryption methods are used, then data protection is provided, but determined hackers can still access sensitive data

Engineering Contradiction:
Improvedata protection effectivenessVSAvoidunauthorized access to raw data
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent inverts the traditional firewall architecture by placing the firewall inside the data center rather than outside. This reverse firewall configuration blocks unauthorized access at the source before hackers can reach the data, rather than attempting to block them after penetration. The firewall is positioned between the data storage system and the network, creating a protective barrier that prevents direct access to sensitive data while allowing authorized operations to proceed normally.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The patent introduces an intermediary processing system that sits between the data storage and network access points. This intermediary anonymizes data before it leaves the data center, transforming sensitive information into unusable form for hackers while maintaining utility for authorized users. The anonymization process acts as a mediator that protects the original data while enabling controlled information sharing.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If raw data is made accessible for processing, then information can be provided to users, but security against privacy attacks is compromised

Engineering Contradiction:
Improveinformation delivery capabilityVSAvoidprivacy attack vulnerability
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by anonymizing data before it is exposed to potential hackers. The system pre-processes the data through anonymization routines that remove personally identifiable information and sensitive details while preserving the analytical value. This preliminary transformation ensures that even if hackers access the data, they cannot use it for privacy attacks because the sensitive information has already been stripped away.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent segments the data processing function from the data storage function. The raw data remains securely stored in isolated storage systems, while separate processing systems create anonymized versions for external distribution. This segmentation ensures that the original sensitive data never leaves the secure environment, while still enabling information delivery through the anonymized copies.

Inventive Principle:
Principle #1Segmentation

3Object-affected harmful factors

If data is anonymized before access, then privacy protection is improved, but access to useful information may be restricted

Engineering Contradiction:
Improveprivacy attack riskVSAvoidutility of shared information
Core Design Contradiction:
Object-affected harmful factorsVSLoss of information

Solution Approach 1:

The patent changes the parameters of the data through controlled anonymization processes that selectively remove or transform specific data elements while preserving others. The system adjusts the degree and type of anonymization based on the intended use case, maintaining the analytical utility of the data while eliminating privacy risks. This parameter transformation allows the data to retain its value for research and analysis purposes while becoming unusable for identity theft or privacy attacks.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11316832B1Computer network data center with reverse firewall and encryption enabled gateway for security against privacy attacks over a multiplexed communication channel
Publication Date: 2022.04.26 ANALYTICAL WIZARDS INC
  • US11316832B1 patent drawing
  • US11316832B1 patent drawing
  • US11316832B1 patent drawing

AI summary

A computer network data center includes a persistent storing device storing raw data from an external data source, a multi-core parallel modelling system coupled to the persistent storing device, and a gateway server coupled to the persistent storing device as a reverse firewall. In operation, the raw data in the persistent storing device is not erased, altered or destroyed. The multi-core parallel modelling system processes the raw data to provide anonymized information for an external user device. The gateway server has a communication channel for secure communication with external devices but prevents access to the raw data stored in the persistent storing device by the external devices.