Trusted Storage Orchestrator for SaaS Data Compliance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Centrally hosted Software as a Service (SaaS) providers face challenges in complying with data protection legislation upon termination of services, as customer data remains in multiple cloud locations outside customer control, leading to non-compliance and potential fines or sanctions.

Innovation Solution

A method and system for moving customer data from SaaS providers to customer-controlled, secure storage upon account deletion, involving a client/service-to-service message exchange to establish a trust relationship, storing data in persistent storage, and copying it to customer-owned secure storage before deletion.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If customer data is stored in multiple individual SaaS services in the cloud, then the service provider can offer comprehensive collaborative services, but the customer data cannot be properly deleted or controlled upon termination of service

Engineering Contradiction:
Improveservice comprehensivenessVSAvoiddata control reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces an intermediary mechanism (the orchestrator and trusted storage system) that mediates between multiple SaaS services and the customer. This intermediary collects data from various services, stores it in a centralized trusted location under customer control, and manages deletion requests, thereby resolving the contradiction between service comprehensiveness and data control reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the data management function from the service delivery function. While multiple SaaS services continue to deliver their respective services, the data management (storage, retrieval, and deletion) is segmented into a separate trusted storage system that operates independently under customer control, allowing each service to focus on its core function while data compliance is handled separately.

Inventive Principle:
Principle #1Segmentation

2Reliability

If the service provider deletes customer accounts upon termination, then data protection legislation compliance is improved, but customer data is lost permanently and cannot be recovered by the customer

Engineering Contradiction:
Improvedata protection complianceVSAvoidcustomer data availability
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

Instead of the traditional approach where the service provider deletes data upon termination, the patent inverts the control: the customer's trusted storage system actively requests and receives data from services, and the service provider deletes data only after confirmation that the customer has received it. This inversion ensures both compliance (provider deletes data) and data availability (customer has copies).

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The patent implements preliminary action by having the trusted storage system request and receive customer data from services before the service provider performs deletion. This ensures data is safely transferred to customer control prior to deletion, preventing accidental loss and enabling compliance verification.

Inventive Principle:
Principle #10Preliminary action

3Ease of manufacture

If the service provider maintains policies for deletion of customer accounts, then operational procedures are standardized, but the service provider remains unable to comply with data protection legislation due to data existing in multiple cloud locations

Engineering Contradiction:
Improvepolicy standardizationVSAvoidlegislation compliance
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent merges the data deletion function across multiple distributed SaaS services into a single centralized operation managed by the orchestrator. Instead of each service independently handling deletion (which is complex and error-prone), the trusted storage system consolidates data retrieval, and the orchestrator manages a single deletion command that ensures all services delete their copies, simplifying policy implementation while ensuring compliance.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP3547640B1Method and system for moving customer data to trusted storage
Publication Date: 2021.07.14 MITEL CLOUD SERVICES INC
  • EP3547640B1 patent drawingFigure 1~2
  • EP3547640B1 patent drawingFigure 3A~3B
  • EP3547640B1 patent drawingFigure 4

AI summary

Methods and systems are provided for moving customer data relating to a service from the service to a customer-controlled secure storage upon deletion of a customer account from the service. Exemplary methods and systems are provided for moving the customer data to a location which is under the control or under ownership of the customer in a secure and automated fashion. Additionally, methods and systems are provided for establishing a client/service to service relationship.