Multi-Cloud Sensitive Data Tracking via Blockchain

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing and tracking sensitive data across multiple cloud environments from different vendors is complex due to varying technologies and regulations, such as GDPR, which hinders effective data handling and compliance.

Innovation Solution

A system that identifies key interfaces carrying sensitive data, generates series of service nodes based on these interfaces, and monitors data traffic using a neural network and blockchain for immutable record-keeping, ensuring compliance and integrity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple cloud environments from different vendors are used to address specific business requirements and avoid vendor limitations, then flexibility and technology adoption capability are improved, but data tracking complexity and compliance management difficulty increase

Engineering Contradiction:
ImproveflexibilityVSAvoiddata tracking complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the monitoring task by deploying specific monitoring agents at each cloud service node rather than attempting to monitor the entire multi-cloud environment as a single system. Each agent independently tracks sensitive data within its local cloud environment, dividing the complex tracking problem into manageable segments that can be handled individually.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces blockchain technology as an intermediary layer that receives data from multiple cloud providers and standardizes the tracking information. This intermediary blockchain network translates diverse data formats from different vendors into a unified structure, making cross-cloud tracking manageable despite vendor differences.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If traditional monitoring methods are used across multi-cloud environments, then implementation simplicity is maintained, but monitoring effectiveness and data integrity are reduced due to varying technologies and regulations

Engineering Contradiction:
Improveimplementation simplicityVSAvoidmonitoring effectiveness
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent creates a universal monitoring solution that functions across multiple cloud vendors simultaneously. The system is designed to work with different cloud providers' technologies while maintaining consistent monitoring effectiveness, allowing the same approach to be applied universally across AWS, Azure, Google Cloud, and other platforms despite their technical differences.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent changes the monitoring parameters by transitioning from vendor-specific monitoring approaches to a standardized set of parameters enforced through blockchain. This includes using consistent data classification schemes, tracking protocols, and compliance criteria across all cloud environments, thereby improving monitoring effectiveness without sacrificing ease of operation.

Inventive Principle:
Principle #35Parameter changes

3Loss of information

If sensitive data is tracked across multiple cloud providers with varying regulations, then comprehensive data visibility is achieved, but compliance management complexity and time consumption increase

Engineering Contradiction:
Improvedata visibilityVSAvoidcompliance management time
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The patent implements preliminary action by establishing blockchain-based tracking protocols and data classification schemes before data is transferred across cloud boundaries. Monitoring agents are pre-configured with compliance rules and tracking templates, so that data is tracked and classified from the moment it enters the multi-cloud environment, eliminating the need for retroactive compliance checks and reducing time consumption.

Inventive Principle:
Principle #10Preliminary action

4Measurement precision

If detailed monitoring of data traffic is implemented to ensure GDPR compliance, then compliance accuracy is improved, but system resource consumption and processing overhead increase

Engineering Contradiction:
Improvecompliance accuracyVSAvoidsystem resource consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent applies partial monitoring by focusing tracking resources only on sensitive data flows rather than monitoring all data traffic equally. Monitoring agents identify and track only data classified as sensitive based on pre-defined criteria, applying detailed monitoring where needed while reducing or eliminating monitoring of non-sensitive data, thereby maintaining compliance accuracy while reducing overall system resource consumption.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11838304B2Tracking of sensitive data
Publication Date: 2023.12.05 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11838304B2 patent drawing
  • US11838304B2 patent drawing
  • US11838304B2 patent drawing

AI summary

Methods, apparatus, computer program products for tracking sensitive data are provided. A method for tracking sensitive data comprises identifying, by one or more processing units, for a type of sensitive data, at least one key interface that carries the type of sensitive data and recording the at least one key interface. The method further comprises generating, by one or more processing units, for the type of sensitive data, for each type of sensitive data, a series of service nodes based on the at least one key interface, and monitoring, by one or more processing units, for the type of sensitive data, corresponding data traffic flowing through corresponding series of service nodes, based on the identified at least one key interface.