globally heterogeneous data mirror

CN115244536BActive Publication Date: 2026-09-04SDIP CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202080088076.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2019-12-16
Filing Date
2020-12-08
Publication Date
2026-09-04
Estimated Expiration
2040-12-08

AI Technical Summary

Technical Problem

然而,如果正在用于存储这种本地交易数据的云端供应商在某个地区内不可用,将会产生一定问题

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115244536B_ABST
    Figure CN115244536B_ABST
Patent Text Reader

Abstract

A method and apparatus for data mirroring. In one embodiment, a method of implementing country-specific data localization for storing data related to local transactions within the country where the transaction occurs, comprising: gathering transaction data sets related to payment processing transactions into a first public cloud storage resource; and performing data mirroring across a group of heterogeneous cloud vendors using a pipeline having a plurality of pipeline stages run by one or more processors.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Cross-references to related applications

[0002] This application claims priority to U.S. nonprovisional application No. 16 / 715,862, filed December 16, 2019, which is incorporated herein by reference in its entirety.

[0003] Copyright Notice and Authorization

[0004] The layout of the documents in this patent document contains copyrighted material. The copyright holder has no objection to any faxed copy of any patent document or patent disclosure appearing in the Patent and Trademark Office documents or records, but otherwise reserves all copyrights. Technical Field

[0005] Embodiments of the present invention relate to the field of systems for processing commercial transactions, and more particularly to mirroring transaction data to one or more locations arranged using cloud-based storage devices. Background Technology

[0006] Today, many merchants utilize third parties to handle all their payment processing needs for commercial transactions. In some cases, merchants outsource their customers' payment information to a third party responsible for collecting payment information and processing transactions, or merchants themselves collect their customers' payment information and send it to a third-party payment gateway for real-time transaction authorization and subsequent settlement of funds.

[0007] Transaction tracking software is commonly used to track transactions and store transaction-related data. Data associated with business transactions is typically stored so that one or more parties can access it for tracking and / or auditing. Storage devices are usually cloud-based and accessible via a network, such as the Internet. In this way, data associated with a merchant's business transactions is stored and can be accessed by the merchant or other licensees via the Internet. Multiple different cloud-based storage providers may be used to store transaction data, such as, but not limited to, Amazon Web Services (AWS), Google Compute, and Alibaba Cloud (AliCloud).

[0008] In order to participate in the Asia-Pacific region (APAC), and especially the Southeast Asia region (SEA), many local governments have enacted data locality legislation, which stipulates that, among other things, a portion of locally traded data must be stored within the country's borders. However, problems arise if the cloud provider used to store this locally traded data is unavailable in a particular region. In such cases, transaction tracking software must support other cloud providers (e.g., if AWS is not supported, Google Compute, Alibaba Cloud, etc. must be supported). Summary of the Invention

[0009] A method and apparatus for data mirroring are described. In one embodiment, a method for localizing country-specific data is provided for storing data related to local transactions within the country where the transactions occur. This includes: collecting a group of transaction data related to payment processing transactions into a first public cloud storage resource; and performing data mirroring across a heterogeneous cloud provider group using a pipeline with multiple pipeline stages run by one or more processors. The multiple pipeline stages include: a first stage filtering the group of transaction data stored in the first public cloud storage resource according to a configuration file of the first public cloud storage resource with specified filtering criteria to create a reduced data group from the transaction data group, the reduced data group containing data associated with each transaction, each transaction being associated with a location specified in the filtering criteria, and writing the reduced data group to a target public cloud storage resource located at that location, specified as the output destination in the configuration file; and a replication stage monitoring the target public cloud storage resource and performing a replication task to mirror the reduced data group to a remote cloud-based storage location defined in the configuration file for the target public cloud storage resource, the remote cloud-based storage location being located in a first country, which is different from a second country where the first public cloud storage resource is located. Attached Figure Description

[0010] To provide a fuller understanding of the present invention, a detailed description is provided below with reference to the accompanying drawings of various embodiments of the invention. This description and the accompanying drawings of the various embodiments are for the purpose of explaining and understanding the present invention only, and should not be construed as limiting the present invention to these specific embodiments.

[0011] Figure 1 A flowchart outlining the steps and entities involved in payment processing.

[0012] Figure 2 A block diagram of a network layout for cloud-based storage devices and transaction data mirroring.

[0013] Figure 3A This is a block diagram of a data mirroring pipeline for one embodiment.

[0014] Figure 3B A block diagram of a data mirroring pipeline for another embodiment.

[0015] Figure 4A This is a diagram illustrating a configuration file for a public cloud storage resource (e.g., a bucket) as an example.

[0016] Figure 4B This is a diagram illustrating a configuration file for a public cloud storage resource (e.g., a bucket), as shown in another embodiment.

[0017] Figure 5 An example of a server accessing a group of transaction data from a specific location.

[0018] Figure 6 This is a flowchart illustrating the process of mirroring data in a global environment, as shown in one embodiment.

[0019] Figure 7 This is a block diagram of a computer system according to one embodiment. Detailed Implementation

[0020] Numerous details are set forth in the following description in order to provide a more thorough explanation of the invention. However, it will be apparent to those skilled in the art that the invention may be practiced without these specific details. In other instances, well-known structures and devices are shown in block diagram form rather than in detail to avoid obscuring the invention.

[0021] Certain terms are used herein for convenience only and should not be construed as limiting the invention.

[0022] Embodiments of the invention are described in the context of a commercial online payment acceptance service known as Stripe in San Francisco, California.

[0023] The following definitions are provided to facilitate understanding of the invention.

[0024] Card networks (or card associations) – refer to financial payment networks such as Visa®, Mastercard®, American Express®, Diners Club®, JCB®, and China UnionPay®.

[0025] Processor – A processor is a company (usually a third party) designated to process credit card transactions. Third parties connect to various card networks and provide authorization and settlement services to merchants or payment service providers. Third parties can also transfer funds from the issuing bank to the merchant or acquiring bank.

[0026] Acquiring Bank – An acquiring bank (or acquiring party) is a bank or financial institution that can accept credit and debit card payments from an affiliated card network for products or services on behalf of a merchant or payment service provider.

[0027] Issuing Bank – An issuing bank is a bank that directly provides consumers with payment cards from a card network or association brand. The issuing bank bears primary responsibility for the consumer's ability to repay debts incurred using their card.

[0028] Payment information—In one embodiment of payment via credit or debit card, payment information includes the primary account number (PAN) or credit card number, card verification code, and expiry date. In another embodiment of payment via Automated Clearing House (ACH) transaction, payment information includes the bank routing number and in-bank account. Payment information includes at least some sensitive, non-public information.

[0029] Merchants – As stated above, a merchant is an entity that deals with the sale or licensing of products and / or services through electronic systems such as the Internet and other computer networks. A merchant can be a direct seller / licensor or an agent of a direct seller / licensor. For example, entities such as Amazon® sometimes act as direct sellers / licensors and sometimes as agents of direct sellers / licensors.

[0030] A merchant site is a merchant's e-commerce site (e.g., a website). The merchant (100) and merchant server (120) in the attached diagram are associated with the merchant site. The merchant site is associated with client-side (client) applications and server-side applications. In one embodiment, the merchant site includes a merchant server (120), and the server-side applications run on the merchant server (120).

[0031] A customer's electronic device—this is the device a customer uses to interact with the merchant. Examples of such devices include desktop computers, laptops, mobile devices (e.g., smartphones, tablets), and game consoles. A customer's electronic device can interact with the merchant through a browser application running on the device, or through a native application (app) installed on the customer's device. The client application runs on the customer's electronic device.

[0032] Payment Processor – As used herein, a payment processor is one or more entities used for transactions between a merchant site and a customer’s electronic device. A payment processor includes selected functions of a stylus (300) and a processor (400) / card network (500). For example, in one embodiment, the stylus (300) creates tokens and maintains and verifies publishable (non-secret) keys and secret keys in a manner well known in the art. See, for example, U.S. patents US10,134,036, US9,830,596, and US9,824,354. The processor (400) / card network (500) participates in authorizing or verifying payment information. In one embodiment, the stylus (300) and the processor (400) / card network (500) work together to authorize and verify payment information, issue tokens, and settle any charges incurred. Thus, in one embodiment, a payment processor refers to the functions of the stylus (300) and the processor (400) and card network (500). In another preferred embodiment, step 3A in the high-level description is not performed, and as described in step 7A in the high-level description, Stella (300) performs its own verification before issuing the token, while processor 400 and card network 500 are still used to settle any charges. Therefore, in this embodiment, the payment processor may refer only to the function of Stella (300) in issuing tokens.

[0033] Native applications are a type of application commonly used on mobile devices such as smartphones or tablets. When using a mobile device, native applications are installed directly on the device. Mobile device users typically obtain these applications through online stores or marketplaces such as app stores (e.g., Apple App Store, Google Play Store). More generally, native applications are designed to run within a running computer environment (machine language and operating system). They can be referred to as locally installed applications. Native applications differ from interpreted applications, such as Java applets, which require interpreter software. Native applications also differ from emulated applications written for different platforms and converted in real-time, and from web applications that run within a browser.

[0034] Overview

[0035] This document discloses techniques for processing payment flows involving tracking and mirroring transaction data to other locations. In one embodiment, the techniques disclosed herein enable a payment processing infrastructure to store transaction data in cloud storage and automatically mirror it to one or more different locations (e.g., one or more different countries), regardless of the cloud-based storage device used at the location where the mirrored data is stored.

[0036] Figure 1 This is a flowchart of the steps and entities implementing the payment processing flow in an embodiment of the present invention.

[0037] At a high level, the payment processing framework described in this paper operates as follows: Figure 1 ):

[0038] 1. A merchant’s customer (200) accesses the merchant’s website using an internet browser (customer browser (210)). In one embodiment, Stripe.js is provided to the customer (200) using standard web technology, which can activate a payment form (110). Stripe.js is a technology well known in the art. For more information about Stripe.js, see U.S. Patent Applications Nos. US10,134,036,9, US830,596, and US9,824,354. The customer (200) enters the necessary information, including their payment information (220), and submits the payment form (110). The bill information portion of the payment form (110) refers to payments made via credit or debit card. If the payment is made via an Automated Clearing House (ACH) transaction, the bill information portion of the payment form (110) will require the bank’s routing number and the bank’s internal account number, as well as possible additional information such as the bank name and whether the account is a checking account or a savings account.

[0039] 2. The customer's payment information (220) is sent from the customer's browser (210) to Stellar (300) without going through the merchant's server (120). In this way, the client application electronically sends the payment information retrieved from the customer's electronic device to the payment processor. The client application does not send the payment information (220) to the server application.

[0040] 3. In one embodiment, Stella (300) submits the relevant transaction to the processor (400) or directly to the card network (500) to authorize or verify payment information. The card network (500) sends a request to the issuing bank (600) that authorized the transaction. In this embodiment, Stella (300) and the processor (400) / card network (500) work together as a payment processor. In another embodiment, this step is performed without any communication with the processor (400) / card network (500). Instead, Stella (300) uses exploratory methods such as checking the Bank Identification Number (BIN), also known as the Issuer Identification Number (IIN), against a database of known valid bank identification numbers in Stella's (300) file to authorize or verify its own payment information. (The BIN is part of the bank card number, i.e., the first six digits.) In another embodiment, this step is not performed at all because success of the next step 4 does not require authorization or verification. That is, it is feasible to create a single-use token in step 4A representing payment information that has not been verified in any way.

[0041] 4. If authorized, Stella (300) generates a secure single-use token (350) and returns it to the client browser (210). The single-use token (350) represents the client's payment information (220) without disclosing any sensitive information. In embodiments where step A3 is not performed, Stella (300) performs this step without waiting for authorization from the processor (400) or the card network (500). In this way, the payment processor (here, Stella (300)) creates the token (350) from the payment information sent by the client application, whereby the token (350) acts as a proxy for the payment information (220).

[0042] 5. A payment form (110) is submitted to the merchant server (120), including a single-use token (350). More specifically, the payment processor sends the token (350) to the client application, which then sends the token (350) to the server application for use in the transaction.

[0043] 6. The merchant (100) submits a charge request to Stry (300) using a single-use token (350) (or creates a target customer for later use). In this step, Stry (300) submits a request to authorize the charge to the processor (400) or directly to the card network (500). This authorization specifies the actual charge amount for the credit card. This authorization request can be skipped if the correct amount has already been authorized in step 3A. This could be a one-time payment for a merchant project, or it could involve registering the payment information with the merchant's website for later use in paying for merchant goods (i.e., the "card on file" case). Using the process described in steps 1-6, the server-side application can use the payment information via the token (350) without exposing the server-side application to the payment information.

[0044] 7. Stella (300) settles charges on behalf of the merchant (100) with the processor (400) or directly with the card network (500).

[0045] 8. The card network (500) enables the issuing bank (600) to pay funds to Sterley (300) or Sterley's acquiring bank (700).

[0046] 9. Stry (300) sends the settlement funds to the service provider (or to the merchant bank (800)) without incurring any fees.

[0047] 10A. The issuing bank 600 collects the funds paid from the customer (200).

[0048] Data mirroring

[0049] In one embodiment, the platform stores data related to transactions processed or disposed of by a payment processor (e.g., Stellar) for customers (e.g., merchants, service providers, etc.), and a portion of the stored transaction data is also mirrored (and stored) to another location (e.g., a country different from the country where the full set of transaction data is located). That is, a copy of the transaction data is extracted from the storage device and stored in another location. In one embodiment, the extracted transaction data pertains to transactions by merchants in a specific country, and the extracted data is stored in a location within that specific country. This is done to comply with the regulatory requirements of a regulatory body and its supervisory bodies in a particular country, enabling the auditing and review of the transaction data. Therefore, data corresponding to transactions that occur at least partially in one country is copied to a data storage device within that country or is accessible from within that country. In one embodiment, the storage device used to store the transaction data is a database in a cloud-based storage device maintained by a cloud-based storage provider (e.g., AWS, Amazon Web Services), Google Compute, Ali Cloud, etc.

[0050] Figure 2 This is a block diagram of a network layout based on cloud-based storage devices and transaction data mirroring. (Refer to...) Figure 2 Payment processor 201 transmits, at least in part, transaction data related to the processed transaction to a cloud-based storage device, referred to herein as the cloud-based transaction data storage device at location 1. In one embodiment, location 1 is located in a first country. In one embodiment, the transaction data is transmitted via network 203 (e.g., the Internet, etc.) to be stored in the cloud-based transaction data storage device at location 1. The transaction data stored in the cloud-based transaction data storage device at location 1 may be accessed by merchants and customers, such as customer / merchant 1 to customer / merchant N, via network 203.

[0051] In one embodiment, part or all of the data is mirrored or copied to one or more other locations, such as cloud-based transaction data storage devices at locations 2 to N. Each of these other locations is located in a different country than the cloud-based transaction data storage device at location 1. In one embodiment, the mirrored data relates to at least a portion of the transactions that occurred in the country where the cloud-based transaction data storage device is located. This enables regulators from regulatory bodies such as regulators 1 through N to obtain the data to fulfill their regulatory obligations.

[0052] In one embodiment, the pipeline is used to support global data mirroring across a heterogeneous group of cloud providers. In another embodiment, the stages of the pipeline are discrete and used to mirror transaction data from transactions processed by the payment processor to different countries. In this way, the pipeline functions as a data extraction pipeline, allowing data from merchants in a specified country to be extracted from the entire group of transaction data in the database and mirrored to the specified country where the merchant is located.

[0053] Demonstration production line

[0054] In one embodiment, a pipeline with multiple pipeline stages is used to perform data mirroring across a heterogeneous cloud vendor group. In another embodiment, these stages are run by one or more processors in a data processing system.

[0055] In one embodiment, the pipeline stage includes at least a stage for acquiring data to be mirrored and a stage for mirroring that data to another location. In one embodiment, the stage for acquiring data to be mirrored is referred to herein as the pipeline reduction stage, while the stage for mirroring the data to another location is referred to herein as the replication stage.

[0056] In one embodiment, a reduction phase in the pipeline filters a set of transaction data stored in a public cloud storage resource (e.g., an S3 bucket). In one embodiment, the set of transaction data is filtered according to a profile of a first public cloud storage resource that specifies filtering criteria to create a reduced data set to obtain data associated with each transaction, each transaction being associated with a location specified in the filtering criteria. In one embodiment, the reduction phase writes the reduced data set to a target public cloud storage resource (e.g., a target S3 bucket) located at that location, specified as the output destination in the profile.

[0057] Figure 3A This is a block diagram of one embodiment of a data mirroring pipeline, including a scaling-down phase and a replication phase. (See reference...) Figure 3A A set of transaction data 301 located at a location in a first country (i.e., country 1) is fed into a reduction stage 310 of a data mirroring pipeline, which filters the data based on the location (e.g., country) where the transaction occurred to produce a (reduced) set of transaction data 302 for a specific location. In one embodiment, this set of data is stored at a location in the first country (country 1).

[0058] The replication phase 311 of the data mirroring pipeline receives, or otherwise accesses, a (reduced) set of transaction data 302 at a specific location, along with one or more profiles 320, and mirrors the data to another location as a (reduced) set of transaction data 303 at the specific location, according to the profiles 320. In one embodiment, the other location is in a different country than the country where the set of transaction data 301 is stored. Figure 4A An example configuration file 400 is shown, which includes a filter criterion 401 specifying the country (or location) of the transaction to be mirrored and the output destination of the data to be mirrored. In one embodiment, the output destination is a public cloud storage resource (e.g., an S3 bucket or similar storage). Therefore, in one embodiment, the input to the replication phase 311 is a set of configuration files and a reduced data group bucket defined within the configuration files, and the output of the replication phase 311 is the mirrored data group copied to a remote mirror bucket defined in the configuration file. In one embodiment, the remote cloud storage device is located in a country different from the country where the first public cloud storage resource is located.

[0059] In one embodiment, referring to the more detailed description below, the replication phase 311 encrypts a (reduced) set of transaction data 302 at a specific location using cryptographic processing logic including hardware (e.g., one or more processors, circuitry, dedicated logic, etc.) and / or software. In this case, in one embodiment, configuration file 320 specifies the encryption strategy (e.g., the type and / or key used to encrypt the data) to be mirrored to another location. An example of such a configuration file is... Figure 4A As shown.

[0060] In one embodiment, when new data is added to the target public cloud storage resource, replication phase 311 monitors the target public cloud storage resource that receives data from shrinking phase 310 and performs a replication task to mirror the shrunken data set to a remote cloud-based storage location (e.g., a target S3 bucket) defined in a configuration file for the target public cloud storage resource. For example, if the shrunken data set is in a first bucket configured for replication (where the configuration file describes the replication mode) and the public cloud storage resource is registered as a mirror containing a subset of a set of transaction data, the subset mirroring is performed in response to an update to the first bucket after filtering during the shrinking phase.

[0061] In one embodiment, the pipeline stages further include an inspection stage that has access to the mirrored data at the remote, cloud-based storage location. This access can be provided in various ways. Preferably, it is via a network-based server system, such as using a File Transfer Protocol (FTP) server.

[0062] Figure 3BA block diagram of a data mirroring pipeline according to another embodiment includes a reduction stage, a copy stage, and an inspection stage. (See also...) Figure 3B A set of transaction data 301 located in a first country (i.e., country 1) is fed into a reduction stage 310 of a data mirroring pipeline, which filters the data based on the location (e.g., country) where the transaction occurred to produce a (reduced) set of transaction data 302 for a specific location. In one embodiment, this set of data is stored in a location within the first country (country 1).

[0063] The replication phase 311 of the data mirroring pipeline receives, or otherwise accesses, a (reduced) set of transaction data 302 at a specific location and one or more configuration files 320, and mirrors the data to another location as a (reduced) set of transaction data 303 at the specific location, according to the configuration files 320. In one embodiment, the other location is located in a different country than the country where the set of transaction data 301 is stored. In one embodiment, the replication phase 311 encrypts the (reduced) set of transaction data 302 at the specific location using cryptographic processing logic including hardware (e.g., one or more processors, circuitry, dedicated logic, etc.) and / or software.

[0064] The pipeline includes an inspection phase 312 from another party, such as, but not limited to, a regulator from a regulatory body. In one embodiment, inspection phase 312 encrypts a (reduced) set of transaction data 302 at a specific location using hardware (e.g., one or more processors, circuitry, dedicated logic, etc.) and / or software cryptographic processing logic. In one embodiment, decryption occurs at a storage location. In another embodiment, decryption occurs at a download location (e.g., a regulatory body).

[0065] Additional reduction phase examples

[0066] In one embodiment, the reduction phase is implemented by extending the configuration file to define a common set of filtering criteria and an output destination for the reduced data set. In one embodiment, the input to the reduction phase is a set of configuration files and a main data set containing all data (e.g., transaction data for all transactions globally), and the output of the reduction phase is the reduced data set written to the configuration file defining the s3 bucket.

[0067] In one embodiment, the pipeline reduction phase 310 is performed as a task that runs all data sets of transaction data (e.g., transaction data for all countries, transaction data for all jurisdictions, etc.) and filters out target data sets (e.g., each country) based on each criterion stored in public cloud storage resources. In one embodiment, the public cloud storage resource is an S3 bucket; of course, other public cloud storage resources can also be used.

[0068] In one embodiment, the reduction phase 310 is executed as a periodically occurring batch task. In one embodiment, the periodically occurring batch task is a weekly batch task. Alternatively, the batch task may occur at other periodically occurring time intervals (e.g., hourly, scheduled hours, daily, scheduled days, monthly, etc.). Alternatively, the reduction phase 310 uses a more frequent batch task that runs only for the last N days / hours of the complete data set and then writes the incrementally reduced data set file.

[0069] In one embodiment, reduction phase 310 uses batch-driven temporal reduction. In one embodiment, this batch-driven temporal reduction reads / reduces / issues the data groups reduced each day. Therefore, there may be many separate data groups constituting all transaction data for a country (e.g., 10_4_2018_india_data.json), rather than a single file containing all transaction data for a country (e.g., all_india_data.json).

[0070] As an alternative to batch processing tasks, in one embodiment, the reduction phase 310 uses a lambda-driven incremental reduction phase. In one embodiment, this implementation monitors the transaction log and performs a reduction function on a per-transaction basis. In one embodiment, this lambda-driven solution appends records to a file (e.g., a journal), and upon reaching a threshold, finalizes the file (e.g., the journal) and writes it to a file to trigger a replication transaction.

[0071] In one embodiment, reduction phase 310 performs filtering on multiple distinct locations. Each of these locations is identified in a filtering criterion in a configuration file to filter transaction data at that location, and the resulting reduced data set for that location is then written to a target public cloud storage resource (e.g., a target S3 bucket). In one embodiment, the location is identified as a reduce predicate in the configuration file, which is used to store the filtered, complete data set on public cloud storage. Figure 4BExample configuration files with a set of different filtering criteria for different countries are shown, where configuration file 410 includes: filtering criterion 411 for filtering transaction data for country #1; output destination or endpoint 412 (e.g., a bucket for mirroring data); and optional encryption policy 413 for specifying encryption of the data if encryption is enabled. Configuration file 420 includes: filtering criterion 421 for filtering transaction data for country #N; output destination or endpoint 422 (e.g., a bucket for mirroring data); and optional encryption policy 423 for specifying encryption of the data if encryption is enabled.

[0072] Additional Replication Phase Examples

[0073] In one embodiment, replication phase 311 observes the output buckets of the shrunk data group defined in the configuration file and schedules a replication task whenever the shrunk phase 310 writes a new shrunk data group. In one embodiment, a remote mirror (or a set of mirrors) of the shrunk data to be replicated is defined in the configuration file. Therefore, in one embodiment, replication phase 311 detects one or more output buckets and performs a replication task to copy the shrunk data group to a remote cloud-based location defined in the configuration file for the output. In one embodiment, this is accomplished by monitoring Simple Queuing Service (SQS) events associated with transactions written to the bucket.

[0074] In one embodiment, replication phase 311 is implemented as a corner job, which is used to list and differentiate source and mirror target buckets, and to propagate transaction data that has not yet been replicated using S3 replicas, and then read and write mirror data to some remote location (e.g., a country).

[0075] To support regions not covered by specific cloud providers, public cloud storage resources (e.g., S3) can be supported on other cloud providers. For example, if a region does not support cloud providers such as AWS but uses S3 buckets, other cloud providers such as Google Compute, Alibaba Cloud, etc., can be used as new replication targets.

[0076] In one embodiment, when the S3 storage device is used for remote mirrored data storage, a geographic profile is built that sets up multiple remote mirrored storage device locations, security groups, and public cloud storage resource (e.g., S3) targets on various cloud providers. Figure 4B The document shows an example of a set of configuration files.

[0077] Additional Inspection Phase Implementation Examples

[0078] As described above, inspection phase 330 enables access to mirrored data at a remote location. In one embodiment, the input to inspection phase 330 is a group of mirrored data stored in a mirrored region bucket, and the output of inspection phase 330 is some form of data inspection or extraction for local use. In other words, in one embodiment, inspection phase 330 is a service operating locally that makes the replicated data “available” for some form of inspection. In one embodiment, local use is the responsibility of a local regulator within a local regulatory body.

[0079] In one embodiment, inspection phase 312 is implemented using secure File Transfer Protocol (FTP) access. In another embodiment, the inspection phase is implemented using a front-end and a queryable service. In one embodiment, mirrored data is returned to a database (e.g., a Structured Query Language (SQL) instance) in the mirrored region. In this instance, a query front-end (FE) (e.g., Kibana) is used for data exploration.

[0080] The copying phase decrypts the data during the encryption / inspection phase.

[0081] To protect data in transit and at rest, in one embodiment, the data is encrypted during the copying phase as it passes through. Any form of encryption can be used. However, in one embodiment, the encryption is the Fast, Secure Advanced Encryption Standard (AES) or a similar form.

[0082] In one embodiment, the replication phase uses a transient symmetric encryption key to encrypt the exported data and replicates the data to foreign buckets.

[0083] In one embodiment, where mirroring supports multi-region replication for failover, data is encrypted as it passes through the pipeline, and a "post-replication phase" is added to the remote mirror where the data is decrypted. In another embodiment, where mirroring is performed to support data localization, data remains encrypted in a remote region, and decryption is part of inspection phase 330.

[0084] In one embodiment, the regulatory agency accesses locally stored data through a server that allows the agency to download and decrypt encrypted data using keys obtained through key exchange. In one embodiment, the service is a Secure File Transfer Protocol (sFTP) server, which allows the regulator to download data.

[0085] For example, in one embodiment, a Secure File Transfer Protocol (sFTP) server is used to access local data, encrypting data, and individuals (e.g., foreign government individuals) can download their sovereign data through the sFTP server. The sFTP server decrypts the data as it is downloaded. Figure 5 This illustrates an example of a specific group of locations where the server accesses transaction data. (See reference) Figure 5 Server 501 (e.g., FTP server) accesses a (scaled-down) transaction data storage device 503 in a specific location / country on behalf of a party (e.g., a regulatory body) 502 via network 302 (e.g., the Internet). In this embodiment, server 501 includes decryption processing hardware (e.g., one or more processors, circuitry, dedicated logic, etc.) and / or software to decrypt data downloaded from the transaction data storage device 503 in the specific location / country.

[0086] To make the decryption key usable for decryption, a key ceremony or other side-channel technology can be used to share the decryption key with a party (e.g., a foreign government or regulatory agency) and to encrypt the data at each stage of the data mirroring pipeline. For example, key exchange can be conducted with a regulatory entity that has access to mirrored data.

[0087] In one embodiment, after the current set of data has been decrypted, the decryption key is discarded as the data is encrypted with a different key in the future. This provides perfect advanced confidentiality.

[0088] Data transfer during the replication phase

[0089] In one embodiment, data is transferred to other locations (e.g., countries) using HTTP POST or Remote Copy Protocol (RCP), Secure Copy Protocol (SCP), and / or File Transfer Protocol (FTP).

[0090] To reduce costs, increase reliability (e.g., lower error rates), and improve the speed of copying large amounts of data over long distances—for example, the data movement mechanism of HTTP POST, which is fragile and slow due to a lack of linear parallelism and Transmission Control Protocol (TCP) fallback—alternative data transmission technologies can be employed. In one embodiment, parallel chunked copying is used to perform data transmission, which divides a large file into many pieces and attempts to copy many of these pieces in parallel. In one embodiment, parallel transmission is accomplished using parallel Rsync. In another embodiment, parallel transmission is accomplished using bittorrent. Of course, other parallel data transmission technologies can also be used.

[0091] Figure 6This is a flowchart illustrating a process for mirroring data in a global environment, as described in one embodiment. This process is executed by processing logic, which includes hardware (circuit, dedicated logic, etc.), software (e.g., software running on a chip), firmware, or a combination of all three. When the payment processing system is presented as a single system, in one embodiment, the payment processing system is implemented by multiple systems (e.g., multiple processing devices, servers, computer systems, etc.).

[0092] Reference Figure 6 The process begins by collecting a set of transaction data related to the payment processing transaction into a first public cloud storage resource (processing block 601) via processing logic. In one embodiment, this is performed by a payment processor (e.g., Stripe) in a manner known in the art.

[0093] Next, the processing logic uses a pipeline with multiple pipeline stages run by one or more processors to perform data mirroring across a heterogeneous cloud vendor group. These pipeline stages include: a first stage that filters transactional data sets stored in a first public cloud storage resource according to a configuration file of that resource with specified filtering criteria to create a reduced data set containing data associated with each transaction, each transaction being associated with a location specified in the filtering criteria; and a replication stage that monitors the target public cloud storage resource and performs a replication task to mirror the reduced data set to a remote cloud-based storage location defined in the configuration file for the target public cloud storage resource. This includes encrypting the data according to an encryption policy in the configuration file of the target public cloud storage resource and exchanging keys with another party (e.g., a regulatory entity) for decryption before mirroring the data to the remote cloud-based storage location. The remote cloud-based storage device is located in a first country, which is different from the second country where the first public cloud storage resource is located; and during the inspection phase, it is possible to access the mirrored data of the remote cloud-based storage device location, including optionally providing a secure server (e.g., an FTP server) to access the mirrored data and decrypting encrypted transaction data (processing block 602).

[0094] In one embodiment, the replication phase of processing block 602 is activated to perform a replication task in response to new data being written to a target public cloud storage resource (e.g., a bucket storing all transaction data to be mirrored from). In one embodiment, the replication phase is activated by monitoring queue service event information related to transactions being written to the first public cloud storage resource.

[0095] In one embodiment, the copying phase of processing block 602 encrypts the data according to the encryption policy in the configuration file of the target public cloud storage resource before mirroring the data to a remote cloud-based storage device location.

[0096] In one embodiment, processing block 602 includes performing a key exchange with a regulatory entity having data access rights at a remote cloud-based storage location, the key exchange providing a key for data decryption at the remote cloud-based storage location.

[0097] In one embodiment, the pipeline for processing block 602 includes an inspection phase capable of accessing mirrored data at a remote, cloud-based storage location. In one embodiment, the access is secure FTP access via a File Transfer Protocol (FTP) server, and the FTP server is operable to decrypt data as it is downloaded.

[0098] In one embodiment, the execution of the first and copy phases of the pipeline for processing block 602 is driven by scheduled tasks.

[0099] Figure 7 This is one embodiment of a computer system that can be used to support the systems and operations discussed herein. However, it will be apparent to those skilled in the art that other alternative systems with various system architectures are also possible.

[0100] Figure 7 The data processing system shown includes a bus or other internal communication method 715 for information communication, and a processor 710 connected to the bus 715 for processing information. The system also includes a random access memory (RAM) or other volatile storage device 750 (referred to as memory) connected to the bus 715 for storing information and instructions to be executed by the processor 710. The main memory 750 can also be used to store temporary variables or other intermediate information during instruction execution by the processor 710. The system also includes: a read-only memory (ROM) and / or static storage device 720 connected to the bus 715 for storing static information and instructions of the processor 710; and a data storage device 725, such as a magnetic disk or optical disk and its corresponding disk drive. The data storage device 725 is connected to the bus 715 for storing information and instructions.

[0101] The system can be further connected to a display device 770, such as a light-emitting diode (LED) display or liquid crystal display (LCD) connected to bus 715 via bus 765, to display information to the computer user. An alphanumeric input device 775, including alphanumeric keys and other keys, can also be connected to bus 715 via bus 765 for information communication and command selection with the processor 710. Additional user input devices, such as a touchpad, mouse, ball tracker, stylus, or cursor arrow keys, are connected to cursor control devices 780 on bus 715 via bus 765 for directional information communication and command selection with the processor 710, and for controlling the movement of the cursor on the display device 770.

[0102] Optionally, another device connected to the computer system 700 is a communication device 790 that accesses other nodes in the distributed system via a network. The communication device 790 may include any of a wide range of commercial IoT peripherals, such as those for connecting to Ethernet, Token Ring, the Internet, or a wide area network. The communication device 790 may further be a no-modem connection, or any other mechanism providing connectivity between the computer system 700 and the outside world. It should be noted that, as Figure 7 As shown, any or all components of this system and related hardware can be used in the various embodiments discussed herein.

[0103] In one embodiment, processor 710 runs stages of the data mirroring pipeline (e.g., reduction stage, replication stage, etc.) and uses its communication device 790 to send data to an output destination (e.g., public cloud storage resources, etc.) to complete the data replication.

[0104] Those skilled in the art will understand that any configuration of the system can be used for various purposes depending on a particular implementation. The control logic or software implementing the embodiments can be stored in main memory 750, mass storage device 725, or other storage media that are locally or remotely accessible to processor 710.

[0105] It will be apparent to those skilled in the art that the systems, methods, and processes described herein can be implemented as software stored in main memory 750 or read-only memory 720 and executed by processor 710. Such control logic or software may also reside on an article of manufacture including a computer-readable medium having the computer-readable program code implemented herein and readable by mass storage device 725, and causing processor 710 to operate in accordance with the methods and teachings herein.

[0106] The embodiments discussed herein can also be implemented in handheld or portable devices that include a subset of the computer hardware components described above. For example, a handheld device may be configured to include only a bus 785, a processor 710, and memories 750 and / or 725. A handheld device may also be configured to include a set of buttons or input signal components that a user can use to select from a set of available options. A handheld device may also be configured as an output device, such as a liquid crystal display (LCD) or a display element matrix, for displaying information to a user of the handheld device. Such a handheld device can be implemented using conventional methods. Based on the disclosure provided herein, embodiments of such devices will be readily apparent to those skilled in the art.

[0107] The embodiments discussed herein can also be implemented in special-purpose devices, including a subset of the computer hardware components described above. For example, such a device might include a processor 710, a data storage device 725, a bus 715, and a memory 750, and only have basic communication mechanisms, such as a small touchscreen that allows the user to communicate with the device in a basic manner. Generally, the more specialized the purpose of the device, the fewer components it requires to function.

[0108] Several example implementations are described in this article.

[0109] Example 1 is a method for localizing country-specific data, used to store data related to local transactions within the country where the transaction occurred. The method includes: collecting a set of transaction data related to payment processing transactions into a first public cloud storage resource; and performing data mirroring across a heterogeneous cloud provider group using a pipeline with multiple pipeline stages run by one or more processors. The multiple pipeline stages include: a first stage filtering the set of transaction data stored in the first public cloud storage resource according to a configuration file of the first public cloud storage resource with specified filtering criteria to create a reduced data set from the transaction data set, the reduced data set containing data associated with each transaction, each transaction being associated with a location specified in the filtering criteria, and writing the reduced data set to a target public cloud storage resource located at that location, specified as the output destination in the configuration file; and a replication stage monitoring the target public cloud storage resource and performing a replication task to mirror the reduced data set to a remote cloud-based storage location defined in the configuration file for the target public cloud storage resource, the remote cloud-based storage location being located in a first country, which is different from a second country where the first public cloud storage resource is located.

[0110] Example 2 is based on the method of Example 1, which may optionally include a replication phase being invoked to perform a replication task in response to new data being written to the target public cloud storage resource.

[0111] Example 3 is based on the method of Example 1, which may optionally include monitoring queue service event information related to transactions written to a first public cloud storage resource.

[0112] Example 4 is based on the method of Example 1, which may optionally include a replication phase operated to encrypt the data according to an encryption policy in the configuration file of the target public cloud storage resource before mirroring the data to a remote cloud-based storage device location.

[0113] Example 5 is based on the method of Example 4, which may optionally include performing a key exchange with a supervisory entity with data access rights at a remote cloud-based storage location, the key exchange providing a key for data decryption at the remote cloud-based storage location.

[0114] Example 6 is based on the method of Example 1, which may optionally include multiple pipeline stages including an inspection stage that enables access to mirrored data at a remote, cloud-based storage location.

[0115] Example 7 is based on the method of Example 6, which may optionally include access via secure FTP access through an FTP server.

[0116] Example 8 is based on the method of Example 7, which may optionally include the FTP server being operated to decrypt data while downloading data.

[0117] Example 9 is based on the method of Example 1, which may optionally include the execution of the first phase and the replication phase driven by scheduled tasks.

[0118] Example 10 is based on the method of Example 1, which may optionally include a replication phase operated to perform replication by copying data blocks in parallel from a target public cloud storage resource to a remote cloud-based storage device location.

[0119] Example 11 is a payment processing system for processing transactions from multiple merchants, wherein the payment processing system includes: a network interface; a memory for storing instructions; and one or more processors coupled to the memory and the network interface for executing the stored instructions to: collect a group of transaction data related to the payment processing transactions into a first public cloud storage resource via the network interface; and perform data mirroring across a heterogeneous cloud provider group using a pipeline having multiple pipeline stages run by one or more processors, the multiple pipeline stages including: a first stage filtering data stored in the first public cloud storage resource according to a configuration file of the first public cloud storage resource with specified filtering criteria. The process involves: a transaction data group, from which a reduced data group is created, the reduced data group containing data associated with each transaction, each transaction being associated with a location specified in the filtering criteria, and the reduced data group being written to a target public cloud storage resource specified as the output destination in a configuration file located at that location; and a replication phase, which monitors the target public cloud storage resource and executes a replication task to mirror the reduced data group to a remote cloud-based storage device location defined in the configuration file for the target public cloud storage resource, the remote cloud-based storage device location being located in a first country, which is different from the second country where the first public cloud storage resource is located.

[0120] Example 12 is a system based on Example 11, which may optionally include a replication phase being invoked to perform a replication task in response to new data being written to a target public cloud storage resource.

[0121] Example 13 is a system according to Example 11, which may optionally include one or more processors operated to monitor queue service event information related to transactions written to a first public cloud storage resource.

[0122] Example 14 is a system according to Example 11, which may optionally include a replication phase operated to encrypt the data according to an encryption policy in a configuration file of the target public cloud storage resource before mirroring the data to a remote cloud-based storage device location.

[0123] Example 15 is a system according to Example 14, which may optionally include one or more processors operated to perform a key exchange with a supervisory entity with data access rights at a remote cloud-based storage location, the key exchange providing a key for data decryption at the remote cloud-based storage location.

[0124] Example 16 is a system according to Example 11, which may optionally include multiple pipeline stages including an inspection stage, enabling access to mirrored data at remote, cloud-based storage device locations.

[0125] Example 17 is a system based on Example 16, which may optionally include access to secure FTP access via a text FTP server.

[0126] Example 18 is a system based on Example 17, which may optionally include an FTP server operated to decrypt data while it is being downloaded.

[0127] Example 18 is a system based on Example 11, which may optionally include the execution of the first phase and the replication phase driven by scheduled tasks.

[0128] Example 20 is a system according to Example 11, which may optionally include a replication phase operated to perform replication by copying data blocks in parallel from a target public cloud storage resource to a remote cloud-based storage device location.

[0129] Example 21 is a non-transitory computer-readable storage medium storing instructions that, when executed by a payment processing system having at least a processor and memory, cause the payment processing system to perform operations including: collecting a group of transaction data related to payment processing transactions into a first public cloud storage resource; and performing data mirroring across a heterogeneous cloud provider group using a pipeline having multiple pipeline stages run by one or more processors, the multiple pipeline stages including: a first stage filtering the group of transaction data stored in the first public cloud storage resource according to a configuration file of the first public cloud storage resource with specified filtering criteria, to extract the transaction data from the group of transaction data. The process involves creating a reduced data set containing data associated with each transaction, each transaction being associated with a location specified in the filtering criteria, and writing the reduced data set to a target public cloud storage resource specified as the output destination in a configuration file located at that location; and a replication phase in which the target public cloud storage resource is monitored and a replication task is executed to mirror the reduced data set to a remote cloud-based storage device location defined in the configuration file for the target public cloud storage resource, the remote cloud-based storage device location being located in a first country, which is different from the second country where the first public cloud storage resource is located.

[0130] Example 22 is based on the medium of Example 21, which may optionally include a replication phase being invoked to perform a replication task in response to new data being written to a target public cloud storage resource.

[0131] Example 23 is based on the medium of Example 21, which may optionally include queue service event information related to monitoring transactions written to a first public cloud storage resource.

[0132] Example 24 is based on the medium of Example 21, which may optionally include a replication phase operated to encrypt the data according to an encryption policy in a configuration file of a target public cloud storage resource before mirroring the data to a remote cloud-based storage location. This operation further includes a key exchange at the remote cloud-based storage location with a regulatory entity having data access rights, the key exchange providing a key for decrypting the data at the remote cloud-based storage location.

[0133] Example 25 is based on the medium of Example 21, which may optionally include the execution of the first phase and the replication phase driven by scheduled tasks.

[0134] The specific implementation schemes described above are given in the form of algorithms and symbolic representations of data bit operations within computer memory. These algorithmic descriptions and expressions are the most effective means for those skilled in the art of data processing to convey the essence of their work to others skilled in the art. Algorithms are shown in this paper and are generally conceived as self-consistent sequences of steps that produce the desired results. These steps are those that require physical manipulation of physical quantities. Typically, although not always necessary, these quantities take the form of electrical or magnetic signals that can be stored, transmitted, combined, compared, and otherwise manipulated. For general reasons, these signals are referred to as bits, values, elements, symbols, characters, terms, numbers, etc.

[0135] However, it should be noted that all such terms should be associated with appropriate physical quantities, and are merely concise expressions applicable to those quantities. Unless otherwise expressly stated in the following discussion, it should be understood that throughout this specification, discussions using terms such as “processing,” “computer calculation,” “calculation,” “determine,” or “display” refer to the actions and processes of a computer system or similar electronic computing device that manipulate and convert data, expressed in physical quantities (electronics), within the computer system's registers and memory into other data, expressed in physical quantities (electronics), within the computer system's memory or registers or other such information storage, transmission, or display devices.

[0136] The present invention also relates to means for performing the operations described herein. Such means may be specifically constructed for the desired purpose or may comprise a general-purpose computer selectively activated or reconfigured by a computer program stored in a computer. This computer program may be stored in a computer-readable storage medium, such as, but not limited to, any type of disk, including floppy disks, optical disks, optical disc drives (CD-ROMs) and magneto-optical disks, read-only memory (ROM), random access memory (RAM), programmable read-only memory (EPROM), electrically erasable read-only memory (EEPROM), magnetic cards or optical cards, or any type of medium suitable for storing electronic instructions, and each medium is coupled to a computer system bus.

[0137] The algorithms and displays presented herein are not inherently related to any particular computer or other device. Various general-purpose systems can be used with the programs taught herein, and more specialized devices can be readily constructed to perform the required method steps. The structures required for various such systems will appear in the following description. Furthermore, this invention is not described with reference to any particular programming language. It will be understood that the teachings of this invention as described herein can be implemented using a variety of programming languages.

[0138] Machine-readable media include any mechanism (e.g., a computer) that stores or transmits information in a machine-readable form. Examples of machine-readable media include read-only memory (ROM), random access memory (RAM), disk storage media, optical storage media, flash memory devices, and electrical, optical, acoustic, or other forms of propagated signals (e.g., carrier waves, infrared signals, digital signals, etc.).

[0139] While many changes and modifications to the present invention will undoubtedly become apparent to those skilled in the art after reading the above detailed embodiments, it should be noted that such changes or modifications should not be considered as limiting the scope of protection of this application. Therefore, the reference to details of various embodiments is not intended to limit the scope of protection of the claims, which themselves only record those technical features essential to the present invention.

Claims

1. A method for localizing country-specific data, used to store data related to local transactions within the country where the transaction occurs, wherein the method includes: The transaction data sets related to payment processing transactions are collected into the first public cloud storage resource; and Data mirroring is performed across a heterogeneous cloud vendor group using a pipeline with multiple pipeline stages running by one or more processors, the multiple pipeline stages including: In the first stage, the transaction data group stored in the first public cloud storage resource is filtered according to the configuration file of the first public cloud storage resource with specified filtering criteria to create a specific location data group that meets regulatory requirements from the transaction data group. The specific location data group contains data associated with each transaction, each transaction is related to a location specified in the filtering criteria, and the specific location data group is written to the target public cloud storage resource, which is specified as the output destination in the configuration file of the location specified in the filtering criteria. as well as During the replication phase, the target public cloud storage resource is monitored and a replication task is automatically executed in response to a new location-specific data group added to the target public cloud storage resource in the first phase, to mirror the location-specific data group to a remote cloud-based storage device location defined in the configuration file for the target public cloud storage resource, the remote cloud-based storage device location being located in a first country, which is different from the second country where the first public cloud storage resource is located.

2. The method of claim 1, wherein the replication phase is activated to perform the replication task in response to new data being written to the target public cloud storage resource.

3. The method according to claim 1, further comprising: Monitor queue service event information related to transactions written to the first public cloud storage resource.

4. The method of claim 1, wherein the replication phase is configured to encrypt the data according to an encryption policy in a configuration file of the target public cloud storage resource before mirroring the data to the remote cloud-based storage device location.

5. The method of claim 4, further comprising: The processor performs a key exchange with a supervisory entity with data access rights at the remote cloud-based storage location, the key exchange providing a key for data decryption at the remote cloud-based storage location.

6. The method of claim 1, wherein the plurality of pipeline stages includes an inspection stage, the inspection stage being capable of accessing mirrored data at the remote cloud-based storage device location.

7. The method of claim 6, wherein the access is secure FTP access via an FTP server.

8. The method of claim 7, wherein the FTP server is configured to decrypt the data while downloading the data.

9. The method of claim 1, wherein the operation of the first phase and the replication phase is driven by a scheduled task.

10. The method of claim 1, wherein the replication phase is operated to perform replication by copying data blocks in parallel from the target public cloud storage resource to the remote cloud-based storage device location.

11. A payment processing system for processing transactions from multiple merchants, the payment processing system comprising: Network interface; Memory, used to store instructions; One or more processors, connected to the memory and the network interface, are used to execute stored instructions: The transaction data set related to payment processing transactions is collected into the first public cloud storage resource through the network interface; and Data mirroring is performed across a heterogeneous cloud vendor group using a pipeline with multiple pipeline stages run by one or more processors, the multiple pipeline stages including: In the first stage, the transaction data group stored in the first public cloud storage resource is filtered according to the configuration file of the first public cloud storage resource with specified filtering criteria to create a specific location data group that meets regulatory requirements from the transaction data group. The specific location data group contains data associated with each transaction, each transaction is related to a location specified in the filtering criteria, and the specific location data group is written to the target public cloud storage resource, which is specified as the output destination in the configuration file of the location specified in the filtering criteria. as well as During the replication phase, the target public cloud storage resource is monitored and a replication task is automatically executed in response to a new location-specific data group added to the target public cloud storage resource in the first phase, to mirror the location-specific data group to a remote cloud-based storage device location defined in the configuration file for the target public cloud storage resource, the remote cloud-based storage device location being located in a first country, which is different from the second country where the first public cloud storage resource is located.

12. The payment processing system of claim 11, wherein the replication phase is activated to perform the replication task in response to new data being written to the target public cloud storage resource.

13. The payment processing system of claim 11, wherein the one or more processors are configured to monitor queue service event information related to transactions written to the first public cloud storage resource.

14. The payment processing system of claim 11, wherein the copying phase is configured to encrypt the data according to an encryption policy in a configuration file of the target public cloud storage resource before mirroring the data to the remote cloud-based storage device location.

15. The payment processing system of claim 14, wherein the one or more processors are configured to perform a key exchange with a regulatory entity having data access rights at the remote cloud-based storage location, the key exchange providing a key for data decryption at the remote cloud-based storage location.

16. The payment processing system of claim 11, wherein the plurality of pipeline stages includes an inspection stage, the inspection stage being capable of accessing mirrored data at the remote cloud-based storage device location.

17. The payment processing system of claim 16, wherein the access is secure FTP access via an FTP server.

18. The payment processing system of claim 17, wherein the FTP server is configured to decrypt the data when downloading the data.

19. The payment processing system of claim 11, wherein the operation of the first phase and the replication phase is driven by a scheduled task.

20. The payment processing system of claim 11, wherein the copying phase is operated to perform the copying by copying data blocks in parallel from the target public cloud storage resource to the remote cloud-based storage device location.

21. A non-transitory computer-readable storage medium storing instructions thereon, which, when executed by a payment processing system having at least a processor and a memory, cause the payment processing system to perform operations including: The transaction data sets related to payment processing transactions are collected into the first public cloud storage resource; and Data mirroring is performed across a heterogeneous cloud vendor group using a pipeline with multiple pipeline stages running by one or more processors, wherein the multiple pipeline stages include: In the first stage, the transaction data group stored in the first public cloud storage resource is filtered according to the configuration file of the first public cloud storage resource with specified filtering criteria to create a specific location data group that meets regulatory requirements from the transaction data group. The specific location data group contains data associated with each transaction, each transaction is related to a location specified in the filtering criteria, and the specific location data group is written to the target public cloud storage resource, which is specified as the output destination in the configuration file of the location specified in the filtering criteria. as well as During the replication phase, the target public cloud storage resource is monitored and a replication task is automatically executed in response to a new location-specific data group added to the target public cloud storage resource in the first phase, to mirror the location-specific data group to a remote cloud-based storage device location defined in the configuration file for the target public cloud storage resource, the remote cloud-based storage device location being located in a first country, which is different from the second country where the first public cloud storage resource is located.

22. The computer-readable storage medium of claim 21, wherein the copying phase is activated to perform the copying task in response to new data being written to the target public cloud storage resource.

23. The computer-readable storage medium of claim 21, wherein the operation further comprises: Monitor queue service event information related to transactions written to the first public cloud storage resource.

24. The computer-readable storage medium of claim 21, wherein the copying phase is operated to encrypt the data according to an encryption policy in a configuration file of the target public cloud storage resource before mirroring the data to the remote cloud-based storage device location, and the operation further includes the processor performing a key exchange with a supervisory entity with data access rights at the remote cloud-based storage device location, the key exchange providing a key for decrypting the data at the remote cloud-based storage device location.

25. The computer-readable storage medium of claim 21, wherein the operation of the first phase and the copying phase is driven by a scheduled task.

Citation Information

Patent Citations

  • Method and apparatus for performing transactions over a network using cross-origin communication

    US10134036B1

  • Apparatus for straightening milk-cans.

    US830596A

  • Method and apparatus for performing transactions over a network using cross-origin communication

    US9824354B1

  • Method for conducting a transaction between a merchant site and a customer's electronic device without exposing payment information to a server-side application of the merchant site

    US9830596B2

  • System architecture for improved storage of electronic health information, and related methods

    US20190378623A1