Centralized Key Management for Distributed Regional Data Storage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data storage systems struggle to manage data access and control across multiple regions, particularly when different regions have varying data storage rules and privacy laws, and there is a need for centralized data control while maintaining data in disparate locations.

Innovation Solution

A system utilizing a computer processor and distributed memory across multiple regions, where artificial intelligence models are built to govern data storage rules for each region, and region-based data keys are centralized in a single location to enable centralized data control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If data is stored in distributed locations across multiple regions, then data accessibility and local compliance are improved, but centralized data control becomes difficult

Engineering Contradiction:
Improvedata accessibilityVSAvoidcentralized control
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a key management system as an intermediary layer between the distributed data storage locations and the centralized control authority. This mediator manages cryptographic keys that enable or disable data accessibility in different regions without requiring direct control of the distributed storage nodes themselves, thus resolving the contradiction between distributed accessibility and centralized control.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If region-specific data storage rules are implemented, then local compliance is improved, but system complexity increases

Engineering Contradiction:
Improvelocal complianceVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by tailoring key management policies and cryptographic parameters to specific regional requirements. Each region can have customized data storage rules enforced through region-specific key management configurations, allowing local compliance without requiring a completely different system architecture for each region.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The key management system provides universal functionality that can accommodate multiple regional compliance requirements through a single unified platform. The system can manage different cryptographic standards, key policies, and access controls for multiple regions simultaneously, reducing overall system complexity compared to implementing separate systems for each region.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If multiple distributed keys are used for regional control, then data security is improved, but key management becomes complex

Engineering Contradiction:
Improvedata securityVSAvoidkey management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the management of multiple distributed keys into a single centralized key management system. While cryptographic keys remain distributed across different regions for security purposes, their generation, storage, rotation, and revocation are all managed through a unified key management platform that provides consistent security policies and simplifies administrative overhead.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS12314239B2Regionally-based data storage and control
Publication Date: 2025.05.27 BANK OF AMERICA CORP
  • US12314239B2 patent drawing
  • US12314239B2 patent drawing
  • US12314239B2 patent drawing

AI summary

A system for administering regionally-based data storage and control is provided. The system may include a computer processor and a distributed memory. The distributed memory may be distributed across a plurality of regions. The distributed memory may provide data storage. The system may build a plurality of artificial intelligence (AI) models. Each of the models may correspond to a set of data rules. Each of the data rules governs the storage of data in each of the plurality of regions. The system may further create, or otherwise access, a plurality of data keys. Each of the data keys preferably corresponds to one of the regions. The system preferably centralizes the location of the plurality of data keys in a central location such that control of the data in the plurality of regions can be administered by the processor, via the plurality of data keys, from the central location.