Sensitivity-Based Cloud Data Encryption for Hybrid Ingestion
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing technologies fail to address the challenges of securely migrating and securing data across different cloud environments, specifically in the context of data sensitivity and confidentiality, leading to potential cyber threats, adversarial attacks, data breaches, and redundant data storage.
Innovation Solution
A system and method for encrypting and ingesting private cloud data into a hybrid cloud based on data sensitivity, utilizing a data orchestration engine, a dynamic data encryption engine, and a data ingestion and decryption engine to identify and secure data based on sensitivity levels, employing algorithms like AES, RSA, and ECC for encryption and decryption.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If data is migrated to public cloud for improved accessibility and scalability, then productivity and ease of operation are improved, but security and reliability deteriorate due to exposure to cyber threats and data breaches
Solution Approach 1:
The patent segments data into different sensitivity categories (public, internal, confidential, restricted) and applies different security policies and encryption levels to each category. This allows highly sensitive data to be protected while less sensitive data remains easily accessible, resolving the contradiction between security and accessibility.
Solution Approach 2:
The patent implements location-aware security where data security measures are tailored to specific cloud environments and data locations. Different encryption keys, access controls, and security protocols are applied based on where the data is stored and accessed, allowing high security for critical data while maintaining ease of access for non-critical data.
2Reliability
If encryption is applied to all data to improve security, then reliability is improved, but device complexity and processing overhead increase
Solution Approach 1:
The patent applies encryption selectively rather than universally - only data classified as confidential or restricted receives strong encryption, while public and internal data uses lighter protection mechanisms. This partial application of encryption maintains security for critical data while avoiding the complexity and overhead of encrypting all data.
Solution Approach 2:
The patent dynamically adjusts encryption parameters such as key length, algorithm type, and encryption intensity based on data sensitivity classification. This allows the system to optimize security measures for each data type, avoiding unnecessary complexity while maintaining appropriate security levels.
3Reliability
If data sensitivity classification is implemented to improve security, then reliability is improved, but measurement precision and detection difficulty increase
Solution Approach 1:
The patent performs automatic data classification and sensitivity assessment during the data ingestion phase before migration occurs. By pre-classifying data and assigning appropriate security labels upfront, the system avoids the need for complex real-time detection during data access and transfer, reducing measurement precision requirements while maintaining security.
Data Source
AI summary
A system includes a memory configured to store a set of private valid source data. The system includes processors operably coupled to the memory and configured to access the set of private valid source data, and to execute a dynamic data encryption engine configured to identify a sensitivity level of the set of private valid source data and to encrypt the set of private valid source data in accordance with a data encryption algorithm. The data encryption algorithm is selected based on the identified sensitivity level. The processors further execute a data ingestion and dynamic decryption engine configured to ingest the encrypted set of private valid source data into the hybrid cloud computing and storage system, and in response to receiving a request to retrieve the encrypted set of private valid source data from the hybrid cloud computing and storage system, decrypt the encrypted set of private valid source data.


