Virtual Private Container for Secure Third-Party Analytics

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current techniques for accessing data stored in offsite repositories are insecure, leading to data leaks and vulnerabilities due to improper sanitization and authorization issues, especially when third-party analytics are involved, resulting in significant labor costs and potential data corruption.

Innovation Solution

The development of a virtual private container (VPC) that provides a self-contained software environment with isolated analytic components, an interface for user authentication, and a gateway for secure data access from external sources, with strict rules for data ingress and egress to prevent unauthorized data movement and ensure secure analytics.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If third-party analytics tools are integrated to access customer data, then analytic capabilities are enhanced, but security risks and data leakage vulnerabilities increase

Engineering Contradiction:
Improveanalytic capabilitiesVSAvoiddata security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system segments the analytics environment into isolated virtual containers, each dedicated to a specific customer. This segmentation allows multiple third-party analytics tools to operate simultaneously with enhanced capabilities while preventing cross-contamination and data leakage between customers, thus resolving the security risk associated with integrated analytics.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a virtual container as an intermediary layer between customer data and third-party analytics tools. This intermediary provides controlled access through defined interfaces, enabling analytics capabilities while preventing direct access to raw data, thereby maintaining data security while enhancing analytic versatility.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If custom data environments are manually tailored to client needs, then customer-specific security and access requirements are met, but labor costs and deployment time increase significantly

Engineering Contradiction:
Improvecustomized securityVSAvoiddeployment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-configuring virtual container templates with standard security policies, authentication mechanisms, and access controls. When a new customer requires customized access, the system instantiates a pre-prepared template rather than building from scratch, dramatically reducing deployment time while maintaining customized security requirements through template-specific configurations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent utilizes parameter changes by allowing virtual container templates to be instantiated with different configuration parameters for each customer (e.g., authentication methods, data access permissions, encryption settings). This enables customized security for each client without manual reconfiguration, reducing both labor costs and deployment time while maintaining reliability.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If virtual containers are instantiated with strict data access controls, then data leakage is prevented, but data processing flexibility and analyst access are restricted

Engineering Contradiction:
Improvedata protectionVSAvoiddata access flexibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system implements dynamic data access controls within virtual containers, where access permissions can be adjusted based on the specific analytic task, user role, and data sensitivity. This dynamic approach maintains strict data protection by default while allowing flexible access when needed, resolving the contradiction between data protection and operational flexibility.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The virtual container architecture provides universal access control mechanisms that serve multiple functions: authentication, authorization, auditing, and data masking. This multi-functionality allows a single set of controls to both protect data and enable flexible access for legitimate analytic operations, eliminating the need to choose between protection and flexibility.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3360302B1Techniques for generating a virtual private container
Publication Date: 2021.08.11 CA TECH INC
  • EP3360302B1 patent drawingFigure 1
  • EP3360302B1 patent drawingFigure 2
  • EP3360302B1 patent drawingFigure 3

AI summary

Techniques for generating a virtual private container (VPC) are disclosed. In one embodiment, the techniques may be realized as a virtual container defining a self-contained software environment, comprising one or more analytic components configured to carry out specified analytic functions on data within the container, wherein the one or more analytic components are isolated to run within the self-contained software environment of the container; an interface configured to identify and authenticate a particular user and provide analysis results generated by the one or more analytic components; and a gateway configured to receive data from one or more secure data sources external to the virtual container and associated with the particular user for use by the one or more analytic components.