Sensitivity-Based Cloud Data Encryption for Hybrid Ingestion

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing technologies fail to address the challenges of securely migrating and securing data across different cloud environments, specifically in the context of data sensitivity and confidentiality, leading to potential cyber threats, adversarial attacks, data breaches, and redundant data storage.

Innovation Solution

A system and method for encrypting and ingesting private cloud data into a hybrid cloud based on data sensitivity, utilizing a data orchestration engine, a dynamic data encryption engine, and a data ingestion and decryption engine to identify and secure data based on sensitivity levels, employing algorithms like AES, RSA, and ECC for encryption and decryption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If data is migrated to public cloud for improved accessibility and scalability, then productivity and ease of operation are improved, but security and reliability deteriorate due to exposure to cyber threats and data breaches

Engineering Contradiction:
Improvedata accessibilityVSAvoiddata security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments data into different sensitivity categories (public, internal, confidential, restricted) and applies different security policies and encryption levels to each category. This allows highly sensitive data to be protected while less sensitive data remains easily accessible, resolving the contradiction between security and accessibility.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements location-aware security where data security measures are tailored to specific cloud environments and data locations. Different encryption keys, access controls, and security protocols are applied based on where the data is stored and accessed, allowing high security for critical data while maintaining ease of access for non-critical data.

Inventive Principle:
Principle #3Local quality

2Reliability

If encryption is applied to all data to improve security, then reliability is improved, but device complexity and processing overhead increase

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies encryption selectively rather than universally - only data classified as confidential or restricted receives strong encryption, while public and internal data uses lighter protection mechanisms. This partial application of encryption maintains security for critical data while avoiding the complexity and overhead of encrypting all data.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent dynamically adjusts encryption parameters such as key length, algorithm type, and encryption intensity based on data sensitivity classification. This allows the system to optimize security measures for each data type, avoiding unnecessary complexity while maintaining appropriate security levels.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If data sensitivity classification is implemented to improve security, then reliability is improved, but measurement precision and detection difficulty increase

Engineering Contradiction:
Improvesecurity levelVSAvoidsensitivity detection accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent performs automatic data classification and sensitivity assessment during the data ingestion phase before migration occurs. By pre-classifying data and assigning appropriate security labels upfront, the system avoids the need for complex real-time detection during data access and transfer, reducing measurement precision requirements while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20260005857A1System and Method for Dynamically Encrypting and Ingesting Private Cloud Data into a Hybrid Cloud Based on Data Sensitivity
Publication Date: 2026.01.01 BANK OF AMERICA CORP
  • US20260005857A1 patent drawing
  • US20260005857A1 patent drawing
  • US20260005857A1 patent drawing

AI summary

A system includes a memory configured to store a set of private valid source data. The system includes processors operably coupled to the memory and configured to access the set of private valid source data, and to execute a dynamic data encryption engine configured to identify a sensitivity level of the set of private valid source data and to encrypt the set of private valid source data in accordance with a data encryption algorithm. The data encryption algorithm is selected based on the identified sensitivity level. The processors further execute a data ingestion and dynamic decryption engine configured to ingest the encrypted set of private valid source data into the hybrid cloud computing and storage system, and in response to receiving a request to retrieve the encrypted set of private valid source data from the hybrid cloud computing and storage system, decrypt the encrypted set of private valid source data.