×

Automated management of confidential data in cloud environments

  • US 9,996,698 B2
  • Filed: 11/23/2015
  • Issued: 06/12/2018
  • Est. Priority Date: 12/09/2014
  • Status: Active Grant
First Claim
Patent Images

1. A method for storing data in a shared networked environment, the shared networked environment comprising a security layer between a shared networked storage and a shared networked storage access interface, the method comprising:

  • physically separating the shared networked storage from a key vault system;

    receiving a storage request together with data to be stored in the shared networked storage and receiving the storage request together with a confidentiality rating, the confidentiality rating indicating a level of confidentiality the data is associated with, wherein the storage request together with the data and the confidentiality rating is received via the shared networked storage access interface by the security layer;

    encrypting, on request of the security layer and into a data container, the data to be stored by the key vault system, and encrypting, into the data container, the confidentiality rating;

    categorizing the shared networked storage into Cloud zones, wherein each Cloud zone is assigned a trust level;

    storing the data container in one of the Cloud zones of the shared networked storage, wherein the trust level of the one of the Cloud zones corresponds to the confidentiality rating;

    validating that the security layer is trusted for communication and validating that a transmission channel between the security layer and the key vault system is secured by a certificate-based encryption;

    creating a transfer ticket, the transfer ticket comprising;

    authorization information about the requester of the storage request, metadata about the data to be stored, a first signature made by the security layer, an expiry time for the storage request, and a second signature made by the key vault system; and

    sending the transfer ticket to the security layer.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×