Secure Resource Provisioning Gateway for Test Environments

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Resources from lower-level environments often contain sensitive information that is not consistently sanitized or obfuscated before entering test environments, posing a risk to data integrity and security.

Innovation Solution

A holistic and secure resource provisioning gateway system that identifies sensitive resources, sanitizes them by scrambling, replacing, or adjusting their values, and stores them in a sanitized database for secure provision to testing environments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If resources are directly provisioned from production/staging environments to test environments, then resource availability and realism are improved, but data security and sensitivity protection deteriorate

Engineering Contradiction:
Improveresource availabilityVSAvoiddata security risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a resource provisioning gateway as an intermediary system between production/staging environments and test environments. This gateway includes multiple servers that receive resources, identify sensitive information, sanitize the data, and then provision the cleaned resources to test environments. The gateway acts as a mediator that enables resource sharing while protecting sensitive data through automated identification and sanitization processes.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If resources are sanitized to protect sensitive information, then data security is improved, but resource format integrity and usability deteriorate

Engineering Contradiction:
Improvedata securityVSAvoidresource format integrity
Core Design Contradiction:
Object-affected harmful factorsVSManufacturing precision

Solution Approach 1:

The patent applies sanitization selectively to specific sensitive portions of resources rather than uniformly processing entire resource sets. The system identifies sensitive information locations within resources and applies sanitization only to those specific areas, leaving non-sensitive portions unchanged. This localized approach maintains resource format integrity and usability while protecting sensitive data.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The sanitization process modifies specific parameters of sensitive data (such as masking, tokenization, or transformation of sensitive values) while preserving the overall resource structure and non-sensitive parameters. This allows the resource to maintain its format and usability for testing purposes while the sensitive parameters are transformed to protect confidentiality.

Inventive Principle:
Principle #35Parameter changes

3Object-affected harmful factors

If comprehensive sanitization is applied to all resources, then data privacy protection is improved, but processing time and system complexity deteriorate

Engineering Contradiction:
Improvedata privacy protectionVSAvoidsystem complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The resource provisioning gateway is divided into multiple independent servers, each capable of handling resource processing tasks. The system segments the sanitization process into distinct stages: resource reception, sensitive information identification, sanitization execution, and provisioning. This segmentation allows parallel processing of multiple resources and distributes system complexity across multiple components rather than concentrating it in a single system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system employs automated identification of sensitive information using predefined patterns, schemas, and data classification rules. The sanitization process is self-executing based on automated detection, reducing the need for manual review and intervention. This self-service approach streamlines the processing workflow while maintaining comprehensive privacy protection.

Inventive Principle:
Principle #25Self-service

4Productivity

If multiple servers process resource blocks in parallel, then processing efficiency is improved, but system coordination and management complexity deteriorate

Engineering Contradiction:
Improveprocessing efficiencyVSAvoidsystem coordination complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

Multiple servers in the resource provisioning gateway are merged into a coordinated system that processes resource blocks in parallel. The servers work together as a unified system, with each server handling specific resource blocks simultaneously. This merging enables efficient parallel processing while the gateway's architecture provides coordinated management of the distributed servers, balancing productivity gains with manageable system complexity.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS10776508B2Holistic and secure resource provisioning gateway system
Publication Date: 2020.09.15 BANK OF AMERICA CORP
  • US10776508B2 patent drawing
  • US10776508B2 patent drawing
  • US10776508B2 patent drawing

AI summary

Embodiments of the present invention provide a holistic and secure resource provisioning gateway system. In particular, a managing system receives resources from disparate sources like production environments. The resources are divided into multiple resource blocks and each resource block is transmitted to individual servers of a resource gateway network along with packaged code that is configured to cause the individual servers to identify sensitive resource elements and sanitize the sensitive resource elements. A request for a provisioned set of sanitized resources meeting certain application testing requirements is then received, and the set of sanitized resources are generated based on the requirements and transmitted to a testing environment.