Server Access Log Storage with WORM Compliance and Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cloud-based storage platforms fail to provide a complete, fully-compliant mechanism for storing access log data, as they often lack Write Once Read Many (WORM) compliance and robust encryption, which are essential for regulatory requirements in financial and healthcare organizations.
Innovation Solution
A system and method for securely storing server access logs by generating logs from a compliant storage container, copying them to a non-compliant container, and then transferring them to a second compliant container with WORM compliance and key management service encryption enabled, ensuring regulatory compliance and security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If cloud-based storage platforms provide server-side access logging, then access log storage is enabled, but WORM compliance and robust encryption are not provided
Solution Approach 1:
The patent implements a copying mechanism that replicates access log data from a non-compliant storage container to a compliant storage container. The system periodically copies access logs generated in the default container to a dedicated compliant container that enables WORM storage and key management service encryption, thereby achieving regulatory compliance without sacrificing storage flexibility.
Solution Approach 2:
The patent introduces an intermediary process that acts as a bridge between the non-compliant default storage container and the compliant storage container. This intermediary mechanism automatically transfers access log data, enabling the system to leverage existing cloud storage flexibility while ensuring regulatory compliance through the compliant container's WORM and encryption features.
2Adaptability or versatility
If access logs are stored in a non-compliant container, then storage flexibility is maintained, but regulatory compliance is not achieved
Solution Approach 1:
The patent segments the storage system into two distinct containers: a non-compliant default container for initial access log storage and a compliant container for regulated storage. This segmentation allows the system to maintain storage flexibility in the default container while ensuring regulatory compliance in the dedicated container, resolving the contradiction between flexibility and compliance.
Solution Approach 2:
The system uses a copying mechanism to transfer access logs from the non-compliant container to the compliant container. This copying process enables the system to leverage the flexibility of the default container during operation while ensuring that a compliant copy is maintained for regulatory requirements, thus resolving the compliance-flexibility contradiction.
3Reliability
If WORM compliance is enabled, then data preservation is ensured, but storage flexibility is reduced
Solution Approach 1:
The patent segments the storage functionality by creating a dedicated compliant container for access logs that enforces WORM compliance, while the default container maintains full flexibility. This segmentation allows data preservation to be ensured in the compliant container without restricting the flexibility of the default container, resolving the contradiction between preservation and flexibility.
Solution Approach 2:
The system creates a copy of access logs in the compliant container that enforces WORM compliance, while the original data remains accessible in the flexible default container. This copying approach ensures data preservation for compliance purposes while maintaining storage flexibility for operational needs.
4Ease of manufacture
If encryption is limited to AES256, then storage simplicity is maintained, but security robustness is insufficient
Solution Approach 1:
The patent changes the encryption parameter by enabling key management service encryption in addition to or instead of AES256. This parameter change enhances security robustness by providing more flexible and robust encryption capabilities while maintaining storage simplicity through automated encryption management, resolving the contradiction between simplicity and security.
Data Source
AI summary
Methods and apparatuses are described for secure compliant storage of server access data. A server computing device generates one or more access logs based upon data access requests executed on a first compliant data storage container comprising a plurality of files. The server computing device stores the one or more access logs in a non-compliant data storage container and establishes a second compliant data storage container. The server computing device retrieves, from the non-compliant data storage container, the access logs stored therein and stores the access logs in the second compliant data storage container.


