Cloud Hub-and-Spoke Architecture for Client Data Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cloud-based data management systems for marketing service providers face challenges in isolating client data securely while allowing access for shared services, risking data commingling and non-compliance with regulations like GDPR, especially when dealing with multiple clients across different jurisdictions.

Innovation Solution

A cloud-based hub-and-spoke account mechanism isolates client data through a Master Account, Uniform Data Layer Control Account, Core Accounts, and separate Analytic Client Accounts, with strict access controls and multi-factor authentication, ensuring data security and compliance by segregating data storage across geopolitical regions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a single AWS account is used to store multiple clients' data, then access control is simplified, but data isolation and security are compromised

Engineering Contradiction:
Improveaccess controlVSAvoiddata isolation
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the single AWS account into multiple virtualized environments using VPCs, subnets, and security groups. Each client's data is isolated in separate network segments while remaining accessible through the unified AWS account interface. This allows simplified access control at the account level while maintaining strict data isolation at the network level.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediary components including transit gateways, API gateways, and IAM roles that mediate between the unified AWS account and individual client data. These intermediaries enforce access policies and maintain isolation boundaries while allowing the account administrator to manage all clients through a single interface.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If separate AWS accounts are created for each client, then data isolation is improved, but system complexity and management overhead increase

Engineering Contradiction:
Improvedata isolationVSAvoidaccount management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal master AWS account that performs multiple functions: it manages all client data, enforces isolation policies, provides unified billing, and coordinates shared services. This single multi-functional account replaces the need for multiple separate accounts, reducing management complexity while maintaining data isolation through virtualization.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges multiple client environments into a single AWS account through virtualization. Separate VPCs, subnets, and security groups are combined under one account umbrella, allowing centralized management while maintaining logical separation. Shared services like logging, monitoring, and billing are merged at the account level for efficiency.

Inventive Principle:
Principle #5Merging (Combining)

3Ease of operation

If cloud storage is used for data accessibility, then data access from any location is improved, but compliance with jurisdictional regulations deteriorates

Engineering Contradiction:
Improvedata accessibilityVSAvoidregulatory compliance
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements local quality by creating region-specific VPCs and data storage configurations within the AWS account. Data for EU clients is stored in EU regions while US client data is stored in US regions, ensuring jurisdictional compliance. Each region has tailored security and access controls appropriate to local regulations, while the unified account provides centralized management.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent adds a geographic dimension to the cloud storage architecture by organizing resources across multiple AWS regions and availability zones. This multi-dimensional structure allows data to be accessible from anywhere in the world while physically residing in compliant jurisdictions. The architecture layers geographic compliance requirements over the unified cloud access model.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS11418509B2Cloud architecture to secure privacy of personal data
Publication Date: 2022.08.16 ACXIOM LLC
  • US11418509B2 patent drawing
  • US11418509B2 patent drawing

AI summary

A cloud-based storage architecture provides for the isolation of client data in a distributed manner using a hub-and-spoke account mechanism within the cloud. Individual client data is securely isolated while still providing a master account with access to all data, including providing access from common applications to all of the data. Thus complete client isolation is achieved while simultaneously sharing the code necessary to process the data in the cloud. A separate client account may be maintained for data stored at separate physical locations, such as may be required under various privacy laws and regulations; in this manner, no data is required to leave a specified geopolitical location in order for processing to occur.