Transparent Proxy Selective Encryption Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional systems face challenges in securely and transparently transmitting data between source and target hosts within a cloud platform, often resulting in unreliable data transmissions due to single point failures and redundant encryption, which degrades system performance.

Innovation Solution

Implementing transparent proxies that modify source host identifiers and enforce encryption policies dynamically, ensuring data is only encrypted if necessary, thereby avoiding redundant encryption and maintaining system integrity without modifying existing infrastructure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data is encrypted multiple times according to different data transmission schemes, then data security is improved, but processing time increases and system performance degrades

Engineering Contradiction:
Improvedata securityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies selective encryption where only portions of data streams that fail compliance checks are encrypted, rather than encrypting all data. The system determines whether encryption is necessary by evaluating data against policies before transmission, applying encryption only when required by the destination host's requirements or security policies.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system performs preliminary compliance checks and encryption determinations before data transmission begins. By evaluating data policies and determining encryption requirements in advance, the system avoids redundant encryption operations and reduces processing time during actual data transmission.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If middle man servers are used to decrypt and re-transmit data, then data transmission flexibility is improved, but system reliability deteriorates due to single point failure

Engineering Contradiction:
Improvedata transmission flexibilityVSAvoidsystem reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent extracts the encryption/decryption functionality from centralized middle-man servers and distributes it to endpoint hosts. Each host independently performs encryption and decryption operations, eliminating the single point of failure represented by centralized intermediary servers while maintaining transmission flexibility.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system enables hosts to perform encryption and decryption operations independently without requiring centralized intermediary servers. Each host self-manages its data encryption according to policies and directly transmits encrypted data to destination hosts, which independently handle decryption, eliminating dependency on middle-man infrastructure.

Inventive Principle:
Principle #25Self-service

3Reliability

If transparent proxies modify source host identifiers and enforce encryption dynamically, then data transmission security is improved, but device complexity increases

Engineering Contradiction:
Improvedata transmission securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements multi-functional endpoint hosts that can independently perform data encryption, policy evaluation, compliance checking, and transmission operations. This universal capability at each host reduces the need for specialized intermediary infrastructure, managing complexity through consolidation of functions at standardized endpoint devices.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11228615B2Transparent enforcement of data policies
Publication Date: 2022.01.18 SALESFORCE INC
  • US11228615B2 patent drawing
  • US11228615B2 patent drawing
  • US11228615B2 patent drawing

AI summary

Methods, systems, and devices for transparent data encryption are described. A transparent proxy may enforce a specific encryption policy for a data transmission from a source host to a target host, where the transparent proxy determines if the data transmission is encrypted according to a specific encryption policy prior to forwarding the data transmission to the target host. As such, if the data transmission is not encrypted according to the specific encryption policy, the transparent proxy may encrypt the data transmission and then forward it to the target host. Alternatively, if the transparent proxy determines that the data transmission is encrypted according to the specific encryption policy, then the transparent proxy may refrain from further encrypting the data transmission and forward the data transmission to the target host without the additional encryption.