Auxiliary Account Generation for Cross-Partition Data Sharing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing online network systems face challenges in securely and compliantly sharing user data across geographically partitioned systems, as they must navigate different regulatory jurisdictions, requiring restrictions on data sharing to adhere to local laws and prevent sensitive information from being mismanaged.
Innovation Solution
Implementing an auxiliary account generation mechanism that creates a subset of user data within a geo-partition, based on a contract between systems, to facilitate cross-partition operations while ensuring compliance with local regulations, using a global identifier and unique identifiers to manage data sharing securely.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If user data is shared across geographically partitioned systems, then cross-partition operations can be facilitated, but regulatory compliance and data security are compromised
Solution Approach 1:
The patent segments user data into multiple partitions corresponding to different geographic jurisdictions. Each partition contains only the data relevant to that jurisdiction, allowing cross-partition operations to proceed while maintaining regulatory compliance. The segmentation is implemented through partition identification fields and selective data retrieval mechanisms that ensure each geo-partitioned system only accesses data it is authorized to handle.
Solution Approach 2:
The patent introduces an intermediary data sharing mechanism that mediates between different geo-partitions. This intermediary layer selectively shares only the minimum necessary data between partitions based on regulatory requirements and operational needs. The intermediary mechanism includes contract-based data sharing agreements and controlled data transmission protocols that prevent unauthorized data access while enabling necessary cross-partition operations.
2Ease of operation
If all user data is shared across partitions, then complete operational functionality is achieved, but sensitive information security is compromised
Solution Approach 1:
The patent extracts sensitive information from the data sharing process by implementing selective data retrieval. Only the specific data elements necessary for a given cross-partition operation are extracted and shared, while sensitive information remains isolated in its home partition. This extraction approach is implemented through targeted data queries that request only the minimum necessary information rather than comprehensive data sets.
Solution Approach 2:
The patent applies local quality by allowing different levels of data access and sharing in different geo-partitions based on local regulatory requirements and security needs. Each partition can enforce its own data protection standards and access control policies. This local quality approach enables complete operational functionality within each partition's security boundaries without requiring uniform data sharing across all partitions.
3Reliability
If data sharing restrictions are implemented to ensure compliance, then security is improved, but operational complexity increases
Solution Approach 1:
The patent implements a universal data sharing framework that handles multiple geo-partitions and regulatory regimes through a single standardized mechanism. The contract-based data sharing system and partition identification approach provide multi-functional capabilities that work across different jurisdictions and operational contexts. This universality reduces the need for separate complex implementations for each partition pair by providing a general-purpose data sharing infrastructure.
Data Source
AI summary
Techniques are disclosed for the sharing and transferring of user data in online network systems operating in multiple jurisdictions. The different jurisdictions may be, for example, different geo-partitions in an online network system. Various techniques are disclosed for providing cross-partition operational functionalities (e.g., cross-geo transactions) between geo-partitioned server systems through the sharing and transferring of data between the geo-partitions. The geo-partitions may have established permissions for data that can be shared between the geo-partitions. A server system in one geo-partition may generate an auxiliary account from a subset of data shared across the geo-partitions that complies with the data permissions. Complying with the established data permissions may inhibit overlapping between the different laws or regulations of the geo-partitions.


