Security Tokens for Tenant Data Protection in Cloud Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cloud-mediated computing networks lack sufficient security measures to prevent malicious internal threats, as tenants have limited control over data access and operations, and existing encryption methods are inefficient for large data sets or data-intensive operations.
Innovation Solution
A system that generates and manages secure tokens to validate and control computing operations on tenant data, allowing only pre-negotiated operations within defined time windows, using a combination of hash generation, two-party signature, and dynamic token activation, integrated into the virtual machine monitoring layer and Dom0 kernel.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If encryption is applied to data, then data confidentiality is improved, but data searchability and operational efficiency deteriorate
Solution Approach 1:
The patent segments data access control into multiple components: encryption keys are separated from data, access policies are divided into hierarchical levels, and token-based authentication splits verification across multiple parties. This allows encrypted data to remain secure while enabling efficient search and operations through segmented access control mechanisms.
Solution Approach 2:
The patent introduces token-based intermediaries that mediate between encrypted data and access requests. These tokens act as intermediaries that enable efficient verification of access rights without requiring decryption of the actual data, thus maintaining both confidentiality and operational efficiency.
2Ease of operation
If cloud tenants trust service providers with data management, then operational simplicity is improved, but security control and trust verification deteriorate
Solution Approach 1:
The patent implements feedback mechanisms where access decisions are verified through multi-party token validation. Service providers receive feedback from tenants regarding access policies, and the system continuously verifies access rights through token-based authentication, providing ongoing security assurance while maintaining operational simplicity.
Solution Approach 2:
The patent introduces token-based intermediaries that enable tenants to maintain security control without directly managing data operations. These tokens serve as mediators that tenants can issue and revoke, providing simple operational control while ensuring robust security verification through the token validation process.
3Object-affected harmful factors
If traditional security measures like firewalls and encryption are implemented, then external security threats are reduced, but internal malicious threats are not prevented
Solution Approach 1:
The patent implements preliminary action by requiring pre-authorized tokens for all data access operations. Before any internal operation can occur, the system verifies that appropriate tokens exist and are valid, preventing malicious internal threats from executing unauthorized operations. This preliminary verification occurs before data access, not after.
Solution Approach 2:
The patent enables self-service security where the system automatically verifies token validity and access rights without requiring manual intervention. The token-based mechanism allows the system to self-validate access requests, preventing internal threats through automated verification rather than relying on manual security monitoring.
4Reliability
If token generation and validation processes are implemented, then data access security is improved, but computational overhead and processing time increase
Solution Approach 1:
The patent applies preliminary action by generating and validating tokens in advance of actual data operations. Tokens are created with embedded access policies and validity periods before data access is needed, allowing rapid verification during actual operations without time-consuming computation at the moment of access.
Solution Approach 2:
The patent uses copying by creating token representations of access rights that can be rapidly validated without accessing the actual encrypted data. These token copies contain all necessary verification information, allowing fast validation through simple comparison operations rather than complex cryptographic verification at access time.
Data Source
AI summary
A system for protecting data managed in a cloud-computing network from malicious data operations includes an Internet-connected server and software executing on the server from a non-transitory physical medium, the software providing a first function for generating one or more security tokens that validate one or more computing operations to be performed on the data, a second function for generating a hash for each token generated, the hash detailing, in a secure fashion, the operation type or types permitted by the one or more tokens, a third function for brokering two-party signature of the one or more tokens, and a fourth function for dynamically activating the one or more signed tokens for a specific time window required to perform the operations permitted by the token.


