Secure Data Proxy for Cloud Computing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Enterprises face security concerns and resource inefficiencies when transferring private data to persistent storage in public clouds for application execution, as it requires excessive bandwidth and resources, and may compromise data security.
Innovation Solution
Implementing a secure data proxy with non-persistent storage in the public cloud, which retrieves and processes data from an external enterprise storage system using cryptographic operations and deduplication, ensuring data is never persistently stored in the public cloud, thereby reducing resource consumption and maintaining data security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If private data is copied into persistent storage of the public cloud for application execution, then application execution in the public cloud is enabled, but data security is compromised and excessive system bandwidth and resources are expended
Solution Approach 1:
The system separates data storage and computation into distinct components. Data remains in enterprise-controlled storage while computation occurs in the public cloud, allowing application execution without compromising data security or requiring data copying to persistent cloud storage.
Solution Approach 2:
A secure data proxy acts as an intermediary between the public cloud applications and enterprise storage systems. The proxy enables data transfer and processing in the cloud while maintaining security controls, preventing direct persistent storage of private data in the public cloud.
2Adaptability or versatility
If private data is transferred into persistent storage of the public cloud, then application execution is enabled, but excessive system bandwidth and resources are consumed
Solution Approach 1:
The system transfers only the specific data subsets needed for each application execution rather than copying entire datasets. This partial action approach reduces bandwidth consumption while enabling application execution with the required data.
Solution Approach 2:
Data is pre-processed and prepared in the enterprise storage system before transfer to the cloud. The secure data proxy identifies and retrieves only the necessary data portions in advance, reducing the bandwidth and resources required during actual application execution.
Data Source
AI summary
An apparatus in one embodiment comprises a plurality of host devices configured to support execution of applications on behalf of one or more tenants of cloud infrastructure. The apparatus further comprises a secure data proxy implemented utilizing at least one of the host devices. The secure data proxy comprises non-persistent storage configured to store data required for execution of at least one of the applications. The data is obtained by the secure data proxy from persistent storage in a storage system external to the cloud infrastructure. The secure data proxy is configured to perform cryptographic operations in conjunction with transfer of the data between the persistent storage of the external storage system and the non-persistent storage of the secure data proxy. The secure data proxy may be further configured to perform deduplication operations in conjunction with transfer of the data between the persistent storage and the non-persistent storage.


