Selective Message Filtering for Secure Database Deployment Exchange

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional messaging techniques between different database deployments either allow or disallow all communication, exposing sensitive data to unauthorized access and failing to provide secure and controlled data exchange between private and public deployments.

Innovation Solution

Implementing a selective filtering scheme with configurable rule sets to filter outgoing and incoming messages across deployments, allowing selective communication based on message types, characteristics, and content, ensuring secure data replication between private and public deployments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If conventional messaging techniques allow all communication between deployments, then data exchange functionality is improved, but security is worsened due to unauthorized access

Engineering Contradiction:
Improvedata exchange functionalityVSAvoidunauthorized access
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the communication control into multiple rule sets that can independently evaluate different aspects of message traffic. Instead of a single all-or-nothing approach, the system divides communication control into granular rules that can allow or block specific message types, characteristics, or content patterns, thereby enabling selective data exchange while maintaining security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different security rules to different parts of the communication stream based on local characteristics. Each message can be evaluated against relevant rule sets that match its specific properties (type, characteristics, content), allowing the system to apply appropriate security measures locally rather than uniformly across all communication.

Inventive Principle:
Principle #3Local quality

2Object-affected harmful factors

If conventional messaging techniques disallow all communication between deployments, then security is improved, but data exchange functionality is worsened

Engineering Contradiction:
ImprovesecurityVSAvoiddata exchange functionality
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic rule evaluation where the security policy is not static but adapts based on message properties. The system dynamically determines whether to allow or block communication by evaluating messages against applicable rule sets in real-time, enabling flexible security control that can permit legitimate data exchange while blocking threats.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameter of security control from a binary state (all-or-nothing) to a multi-dimensional state based on message type, characteristics, and content. By introducing configurable parameters and rule sets that evaluate different message attributes, the system achieves fine-grained security control that enables both security and functionality.

Inventive Principle:
Principle #35Parameter changes

3Object-affected harmful factors

If selective filtering with configurable rule sets is implemented, then security control is improved, but system complexity is worsened

Engineering Contradiction:
Improvesecurity controlVSAvoidsystem complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent creates a universal filtering framework that handles multiple security evaluation dimensions (message type, characteristics, content) through a single configurable rule set system. This multi-functional approach allows the same infrastructure to evaluate different message properties using the same rule evaluation mechanism, reducing overall system complexity despite the enhanced security control capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system enables self-service configuration of security rules, allowing users to define and manage their own rule sets based on their specific security requirements. This self-service capability reduces the need for complex pre-configured security policies and allows the system to adapt to different security needs without requiring complex system changes.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20240422127A1Secure message exchange between deployments
Publication Date: 2024.12.19 SNOWFLAKE INC
  • US20240422127A1 patent drawing
  • US20240422127A1 patent drawing
  • US20240422127A1 patent drawing

AI summary

Different database deployments, or other data system deployments, may want to communicate with each other without sacrificing security or control. To this end, embodiments of the present disclosure may provide secure message exchange techniques for a source and/or target deployment. Configurable rule sets may be stored in the deployments; the rule sets may define what messages may be communicated between deployments. The deployments may implement a selective filtering scheme in one or more stages based on the rule sets to filter outgoing and/or incoming messages.