Taints and Assertions for Network Data Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cloud computing environments face challenges in protecting data due to the complexity of managing rules and policies across multiple layers of the network stack, leading to potential misconfigurations that expose sensitive data.

Innovation Solution

The use of taints and assertions to protect data within networks, where taints are applied to data based on its sensitivity and assertions define how tainted data can flow through the network, enforced at various points throughout the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If perimeter-based security rules and policies are created to protect data, then data protection is improved, but system complexity and difficulty of maintenance increase

Engineering Contradiction:
Improvedata protectionVSAvoidsecurity rules complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Instead of controlling what resources can access data (traditional perimeter security), the patent inverts the approach by controlling what can be done with the data itself. Taints are attached to data objects to track and restrict their flow, rather than managing complex access policies for each resource. This inversion simplifies security management while maintaining or improving protection effectiveness.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The patent introduces taints as intermediary markers attached to data objects. These taints act as mediators that automatically enforce policy restrictions on data flow without requiring complex rule configurations. The taints propagate with the data through the system, automatically preventing unauthorized access or movement without human intervention in policy management.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple layers of network security rules are implemented, then data protection coverage is improved, but configuration errors and misconfigurations increase

Engineering Contradiction:
Improvedata protection coverageVSAvoidmisconfiguration exposure
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The taint-based system is self-enforcing and automatically tracks data flow through the network. Once taints are applied to sensitive data, they automatically propagate and enforce restrictions without requiring manual configuration at each network layer. This self-service mechanism eliminates misconfiguration risks associated with manual multi-layer security rule management while maintaining comprehensive data protection coverage.

Inventive Principle:
Principle #25Self-service

3Reliability

If traditional access control policies are used, then resource security is improved, but adaptability to new network equipment and configurations decreases

Engineering Contradiction:
Improveresource securityVSAvoidadaptability to new equipment
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The taint-based security system is dynamic and automatically adapts to new network equipment, configurations, and data flows. Unlike static access control lists that require manual updates, taints automatically propagate with data objects regardless of the path taken or equipment encountered. This dynamic approach maintains resource security while providing seamless adaptability to changing network environments.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS20250088544A1Taints and fading taints
Publication Date: 2025.03.13 ORACLE INT CORP
  • US20250088544A1 patent drawing
  • US20250088544A1 patent drawing
  • US20250088544A1 patent drawing

AI summary

Techniques are described for using taints and assertions to protect data within one or more networks. Instead of being restricted to perimeter-based security and defining and creating rules that are difficult to maintain, techniques described herein allow users to protect data using assertions that are enforced at different enforcement points within one or more networks. According to some configurations, the assertions/policy statements defined by a user specify where data is allowed to travel throughout one or more networks. Assertions/policy statements can be as simple as “Red data never leaves my tenancy”, “Blue data never reaches the internet”, “Blue data is not stored with Red data”, “Green data never leaves Data Zone 2”, and the like. In some examples, a policy statement can protect the flow of data based on a number of hops the resource is from where the data is stored.