Software Defined Data Security Layer for Differential IO Request Classification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cloud computing environments, existing data security measures lack the ability to differentiate between varying levels of sensitivity in input/output requests, leading to inefficient resource allocation and security treatment of data.

Innovation Solution

A software-defined data security layer intercepts and analyzes input/output requests based on a service level agreement (SLA), assigning a security level to each request, allowing for differential security treatment of sensitive and non-sensitive data by translating SLA requirements into appropriate encryption techniques and network security parameters.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If uniform high-level security measures are applied to all input/output requests, then security reliability is improved, but system performance and resource efficiency deteriorate due to unnecessary security processing on non-sensitive data

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidsystem performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements differential security treatment by classifying IO requests into different security levels based on data sensitivity. High-security measures are applied only to sensitive data requests, while low-security measures are applied to non-sensitive requests, optimizing resource allocation and system performance without compromising security where needed

Inventive Principle:
Principle #3Local quality

2Measurement precision

If comprehensive security analysis is performed on every input/output request, then security detection capability is improved, but processing time and system overhead increase

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent performs security analysis selectively rather than uniformly on all IO requests. The classification layer analyzes requests to determine security levels, applying comprehensive analysis only when necessary to identify sensitive data, while using faster classification methods for routine requests, thereby reducing overall processing time while maintaining security detection capability

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If encryption and security protocols are applied to all data transmissions, then data protection is improved, but network bandwidth and computational resources are wasted on non-sensitive data

Engineering Contradiction:
Improvedata protectionVSAvoidnetwork and computational resources
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent applies encryption and security protocols selectively based on the security level of each IO request. Sensitive data transmissions receive full encryption and security treatment, while non-sensitive data uses lighter security measures or none at all, optimizing network bandwidth and computational resource utilization while maintaining adequate data protection

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11693977B2Software defined data security layer
Publication Date: 2023.07.04 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11693977B2 patent drawing
  • US11693977B2 patent drawing
  • US11693977B2 patent drawing

AI summary

A software defined data security level method, computer program product, and data processing system. One embodiment may comprise intercepting, by a processor at a data security layer, an input/output (IO) request from a local software application, wherein the IO request includes a header and a data payload, analyzing, by the processor at the data security layer, the data payload of the IO request relative to a service level agreement (SLA), assigning, by the processor at the data security layer, a security level to the IO request based on the analysis.