Selective Encryption Service Interface for Third-Party Cloud Data
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The shift towards cloud, SaaS, and web applications exposes security issues due to the storage of confidential information outside the corporate firewall, necessitating mechanisms for independent security of these systems.
Innovation Solution
A computer system that selectively encrypts and decrypts data based on historical analysis of client computers, using a server system to perform cryptographic operations and provide encryption as a service, with a service interface conforming to SOAP or REST, to manage encryption and decryption of data elements communicated between client computers and third-party network services.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If data is stored in cloud services outside corporate firewall, then accessibility and convenience are improved, but security and control over confidential information deteriorate
Solution Approach 1:
The patent segments data into encrypted and unencrypted portions, allowing selective encryption of sensitive data elements while leaving other data accessible. This enables cloud storage to maintain accessibility while enhancing security for confidential information through granular encryption control
Solution Approach 2:
The patent introduces an encryption service as an intermediary between client computers and third-party network services. This service performs cryptographic operations on data elements, acting as a mediator that enables secure cloud storage while maintaining controlled access to confidential information
2Reliability
If selective encryption is implemented based on historical analysis, then security is improved, but system complexity and processing overhead increase
Solution Approach 1:
The patent performs historical analysis of client computers in advance to identify security risks and determine which data elements should be encrypted. By conducting this analysis beforehand, the system establishes encryption requirements before data is stored in the cloud, reducing real-time complexity while maintaining security
Solution Approach 2:
The patent enables the system to automatically perform historical analysis and determine encryption needs without requiring manual intervention. The system self-manages the identification of sensitive data elements and applies appropriate encryption, reducing operational complexity while enhancing security
Data Source
AI summary
A network computer system implements a service interface to provide encryption as a service, performs cryptographic operations on a plurality of data elements communicated between client computers of an enterprise and a third-party network service, and stores decryption logic in association with the plurality of data elements. The network computer system receives a decryption request via the service interface from a programmatic entity implemented by the third-party network service, the decryption request specifying an encrypted form of a data element. The network computer system decrypts the encrypted form of the data element to generate a decrypted form of the data element using a decryption key, of the one or more decryption keys that is associated with the data element. The network computer system provides a response to the decryption request to the programmatic entity, the response including the decrypted form of the data element.


