Token Vault for Secure Cloud Data Storage
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for protecting sensitive documents and data in cloud computing applications are inadequate, as they leave data exposed to decryption breaches, disrupt application functions, and violate international data export laws, while local tokenization systems are vulnerable to hacking.
Innovation Solution
A system that encrypts sensitive data, generates a token, tokenizes the encrypted data, and stores it in a token vault, allowing secure storage and retrieval in a cloud environment, ensuring data security and compliance with international regulations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If sensitive data is encrypted and uploaded to cloud computing application, then data security is improved, but data is exposed to unwanted decryption if encryption keys are breached
Solution Approach 1:
The patent introduces a token as an intermediary between the sensitive data and the cloud storage system. Instead of storing or transmitting actual sensitive data, the system stores tokens that reference the data. This token intermediary prevents direct access to the data even if cloud systems are compromised, as tokens alone cannot decrypt or reveal the underlying sensitive information without additional authorization layers.
Solution Approach 2:
The patent extracts the sensitive data from the cloud storage environment entirely. The actual sensitive data remains stored locally or in secure enterprise-controlled storage, while only non-sensitive tokens are uploaded to the cloud application. This extraction eliminates the risk of cloud-based decryption breaches affecting the actual sensitive data.
2Reliability
If encryption is applied to sensitive data, then data security is improved, but application/user functions such as Search, Sort etc. are broken
Solution Approach 1:
The patent creates a functional copy in the form of tokens that represent the sensitive data. These tokens can be stored, searched, and sorted in the cloud application without affecting the security of the original data. The token copy maintains the structural and searchable properties needed for application functions while the actual sensitive data remains encrypted and secure.
3Adaptability or versatility
If unencrypted documents and data are stored to local data storage system through tokenization, then cloud application access is enabled, but token vault or file system is vulnerable to hacking
Solution Approach 1:
The token serves as an intermediary that enables cloud application access while protecting the local storage system. The token vault stores tokens rather than actual sensitive data, creating a security buffer. Even if the token vault is hacked, the tokens alone cannot access or reveal the underlying sensitive data without additional authorization, thus mitigating the vulnerability while maintaining cloud compatibility.
4Adaptability or versatility
If sensitive data is exported to cloud application, then data distribution within enterprise is enabled, but company policies and international data export laws are violated
Solution Approach 1:
The patent extracts only the token (a non-sensitive reference) from the enterprise environment and stores it in the cloud application, while the actual sensitive data remains within the enterprise boundaries. This extraction enables cloud-based data distribution and access capabilities while ensuring that sensitive data never leaves the enterprise, thus maintaining regulatory compliance with company policies and international data export laws.
Data Source
AI summary
The present disclosure includes a method comprising encrypting sensitive data, generating a token comprising a data identifier, tokenizing the encrypted sensitive data, and/or storing the encrypted sensitive data in association with the token to a token vault. Tokenizing may comprise mapping the encrypted sensitive data to the token. The method may further comprise storing the token to a cloud application, wherein the cloud application comprises a software application that functions within a cloud computing environment.


