Selective Message Filtering for Secure Database Deployment Exchange
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional messaging techniques between different database deployments either allow or disallow all communication, exposing sensitive data to unauthorized access and failing to provide secure and controlled data exchange between private and public deployments.
Innovation Solution
Implementing a selective filtering scheme with configurable rule sets to filter outgoing and incoming messages across deployments, allowing selective communication based on message types, characteristics, and content, ensuring secure data replication between private and public deployments.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If conventional messaging techniques allow all communication between deployments, then data exchange functionality is improved, but security is worsened due to unauthorized access
Solution Approach 1:
The patent segments the communication control into multiple rule sets that can independently evaluate different aspects of message traffic. Instead of a single all-or-nothing approach, the system divides communication control into granular rules that can allow or block specific message types, characteristics, or content patterns, thereby enabling selective data exchange while maintaining security.
Solution Approach 2:
The patent applies different security rules to different parts of the communication stream based on local characteristics. Each message can be evaluated against relevant rule sets that match its specific properties (type, characteristics, content), allowing the system to apply appropriate security measures locally rather than uniformly across all communication.
2Object-affected harmful factors
If conventional messaging techniques disallow all communication between deployments, then security is improved, but data exchange functionality is worsened
Solution Approach 1:
The patent implements dynamic rule evaluation where the security policy is not static but adapts based on message properties. The system dynamically determines whether to allow or block communication by evaluating messages against applicable rule sets in real-time, enabling flexible security control that can permit legitimate data exchange while blocking threats.
Solution Approach 2:
The patent changes the parameter of security control from a binary state (all-or-nothing) to a multi-dimensional state based on message type, characteristics, and content. By introducing configurable parameters and rule sets that evaluate different message attributes, the system achieves fine-grained security control that enables both security and functionality.
3Object-affected harmful factors
If selective filtering with configurable rule sets is implemented, then security control is improved, but system complexity is worsened
Solution Approach 1:
The patent creates a universal filtering framework that handles multiple security evaluation dimensions (message type, characteristics, content) through a single configurable rule set system. This multi-functional approach allows the same infrastructure to evaluate different message properties using the same rule evaluation mechanism, reducing overall system complexity despite the enhanced security control capabilities.
Solution Approach 2:
The system enables self-service configuration of security rules, allowing users to define and manage their own rule sets based on their specific security requirements. This self-service capability reduces the need for complex pre-configured security policies and allows the system to adapt to different security needs without requiring complex system changes.
Data Source
AI summary
Different database deployments, or other data system deployments, may want to communicate with each other without sacrificing security or control. To this end, embodiments of the present disclosure may provide secure message exchange techniques for a source and/or target deployment. Configurable rule sets may be stored in the deployments; the rule sets may define what messages may be communicated between deployments. The deployments may implement a selective filtering scheme in one or more stages based on the rule sets to filter outgoing and/or incoming messages.


