Blockchain Container System for Cloud Compliance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cloud storage architectures rely on a trusted central authority model, making them vulnerable to security threats and challenging to comply with legal requirements such as geographic restrictions and data protection laws, especially in distributed cloud environments.

Innovation Solution

Implementing a blockchain-based system where containers are members of a distributed network with a public ledger that records encrypted copies of their data, allowing for secure, auditable, and compliant data management by defining a system boundary that enforces geographic restrictions and rights management through blockchain transactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a trusted central authority model is used for cloud storage, then ease of operation and centralized management are improved, but security vulnerability and compliance difficulty increase

Engineering Contradiction:
Improvecentralized managementVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces blockchain technology as an intermediary layer between the central authority and storage operations. The blockchain ledger acts as a mediator that records and verifies all data access and modification operations, providing security and auditability without requiring complete trust in the central authority. This resolves the contradiction by maintaining centralized management ease while adding cryptographic verification for security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces traditional mechanical trust-based security systems with cryptographic verification systems. Instead of relying on organizational trust and manual security procedures, the system uses digital signatures, hash functions, and blockchain consensus mechanisms to automatically verify operations. This substitution eliminates security vulnerabilities associated with human error and organizational trust while maintaining ease of operation.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Ease of operation

If traditional cloud storage architecture is used, then ease of operation is improved, but susceptibility to security threats increases

Engineering Contradiction:
Improveoperation simplicityVSAvoidsecurity threats
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary anti-action by embedding security verification mechanisms before any data operations occur. The blockchain ledger pre-records access policies and permissions, and digital signatures are prepared in advance for authorized operations. This prevents security threats by establishing verified trust relationships before data interactions, rather than reacting to threats after they occur.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The blockchain system serves as an intermediary that stands between data and potential security threats. It verifies all access requests through cryptographic proof before allowing operations, blocking unauthorized access attempts before they can affect the data. This intermediary layer maintains operation simplicity for authorized users while providing robust protection against security threats.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If blockchain technology is implemented in distributed cloud storage, then security and auditability are improved, but system complexity increases

Engineering Contradiction:
Improvesecurity and auditabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent makes the blockchain system multi-functional to reduce complexity. The same blockchain ledger serves multiple purposes: storing access policies, recording audit trails, verifying data integrity, and managing permissions. This universal approach consolidates what would otherwise require separate complex systems, achieving high security and auditability while managing system complexity through functional consolidation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The blockchain system is designed to be self-servicing in terms of security verification. Once the blockchain ledger is established with the necessary smart contracts and access policies, it automatically verifies and records all operations without requiring external security management infrastructure. This self-service capability reduces the complexity burden on the overall system while maintaining high reliability for security and auditability.

Inventive Principle:
Principle #25Self-service

4Reliability

If geographic restrictions are enforced through system boundaries, then compliance with legal requirements is improved, but adaptability to different jurisdictions decreases

Engineering Contradiction:
Improvecompliance with legal requirementsVSAvoidflexibility across jurisdictions
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic system boundaries through the blockchain ledger that can adapt to different jurisdictions. Access policies and geographic restrictions are stored as programmable smart contracts on the blockchain, allowing the system to dynamically adjust boundaries based on the specific data and jurisdiction involved. This enables compliance with local legal requirements while maintaining adaptability across different jurisdictions through flexible, code-based policy enforcement.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system applies local quality by allowing different geographic and access policies for different data sets or containers within the same blockchain network. Each data container can have its own specific jurisdictional requirements encoded in the blockchain, enabling compliance with local legal requirements while maintaining overall system flexibility. This localized policy enforcement resolves the contradiction between strict compliance and cross-jurisdictional adaptability.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10778442B2Container-based operating system and method
Publication Date: 2020.09.15 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10778442B2 patent drawing
  • US10778442B2 patent drawing
  • US10778442B2 patent drawing

AI summary

In a distributed network hosting a shared pool of configurable computing resources there is provided one or more system instances of a blockchain. Each system instance comprises a virtual machine and a set of containers. The containers are members of the blockchain in that the blockchain's public ledger records encrypted copies of at least selected directories of each container. Each container that is in the set can thus verify whether any other container also belongs to the same set with reference to the public ledger, since the transactions recorded on the public ledger are encrypted copies of the set's containers. The use of a blockchain thus allows a system boundary to be defined around a set of containers by the initial specification of the blockchain. The system boundary can be defined to ensure that the set of containers comply with legal requirements, such as a geographic restriction.