Trusted Storage Orchestrator for SaaS Data Compliance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Centrally hosted Software as a Service (SaaS) providers face challenges in complying with data protection legislation upon termination of services, as customer data remains in multiple cloud locations outside customer control, leading to non-compliance and potential fines or sanctions.
Innovation Solution
A method and system for moving customer data from SaaS providers to customer-controlled, secure storage upon account deletion, involving a client/service-to-service message exchange to establish a trust relationship, storing data in persistent storage, and copying it to customer-owned secure storage before deletion.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If customer data is stored in multiple individual SaaS services in the cloud, then the service provider can offer comprehensive collaborative services, but the customer data cannot be properly deleted or controlled upon termination of service
Solution Approach 1:
The patent introduces an intermediary mechanism (the orchestrator and trusted storage system) that mediates between multiple SaaS services and the customer. This intermediary collects data from various services, stores it in a centralized trusted location under customer control, and manages deletion requests, thereby resolving the contradiction between service comprehensiveness and data control reliability.
Solution Approach 2:
The patent segments the data management function from the service delivery function. While multiple SaaS services continue to deliver their respective services, the data management (storage, retrieval, and deletion) is segmented into a separate trusted storage system that operates independently under customer control, allowing each service to focus on its core function while data compliance is handled separately.
2Reliability
If the service provider deletes customer accounts upon termination, then data protection legislation compliance is improved, but customer data is lost permanently and cannot be recovered by the customer
Solution Approach 1:
Instead of the traditional approach where the service provider deletes data upon termination, the patent inverts the control: the customer's trusted storage system actively requests and receives data from services, and the service provider deletes data only after confirmation that the customer has received it. This inversion ensures both compliance (provider deletes data) and data availability (customer has copies).
Solution Approach 2:
The patent implements preliminary action by having the trusted storage system request and receive customer data from services before the service provider performs deletion. This ensures data is safely transferred to customer control prior to deletion, preventing accidental loss and enabling compliance verification.
3Ease of manufacture
If the service provider maintains policies for deletion of customer accounts, then operational procedures are standardized, but the service provider remains unable to comply with data protection legislation due to data existing in multiple cloud locations
Solution Approach 1:
The patent merges the data deletion function across multiple distributed SaaS services into a single centralized operation managed by the orchestrator. Instead of each service independently handling deletion (which is complex and error-prone), the trusted storage system consolidates data retrieval, and the orchestrator manages a single deletion command that ensures all services delete their copies, simplifying policy implementation while ensuring compliance.
Data Source
Figure 1~2
Figure 3A~3B
Figure 4
AI summary
Methods and systems are provided for moving customer data relating to a service from the service to a customer-controlled secure storage upon deletion of a customer account from the service. Exemplary methods and systems are provided for moving the customer data to a location which is under the control or under ownership of the customer in a secure and automated fashion. Additionally, methods and systems are provided for establishing a client/service to service relationship.