Containerized Data Processing for Residency Compliance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing technologies face challenges in handling data residency restrictions across geographic, jurisdictional, and political boundaries, particularly when dealing with unstructured data like documents or files containing personally identifiable information (PII), which are subject to complex legal and regulatory requirements such as GDPR and HIPPA, making it difficult to transfer data while ensuring compliance and security.

Innovation Solution

A computer-implemented method generates a container image based on identified profile levels and data residency restrictions, configuring it for instantiation as a container on a host to process datasets into reformatted forms that comply with transfer restrictions, allowing safe transfer across boundaries while maintaining data security and compliance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If data is transferred across geographic boundaries to enable global information sharing, then information accessibility and collaboration are improved, but compliance with data residency restrictions and regulatory requirements deteriorates

Engineering Contradiction:
Improvedata transfer capabilityVSAvoidregulatory compliance
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

A data processing service acts as an intermediary between data subjects and data recipients. The service receives data subject to residency restrictions, processes it in controlled environments (containers), and outputs results that can be shared across boundaries without transferring the original restricted data, thus enabling collaboration while maintaining compliance.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments data processing into distinct functional components using containerization. Each container handles specific processing tasks for data with different compliance requirements, allowing selective processing of data elements based on their sensitivity and regulatory constraints while maintaining overall system flexibility.

Inventive Principle:
Principle #1Segmentation

2Loss of information

If unstructured data containing PII is processed to extract insights, then data value and information utility are improved, but data security risks and compliance complexity increase

Engineering Contradiction:
Improveinformation utilityVSAvoiddata security risk
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The system creates isolated copies of unstructured data within containerized environments for processing. These containers provide secure, temporary working copies that can be analyzed to extract insights without exposing the original sensitive data, enabling information utility while maintaining security through isolation.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system transforms data parameters during processing by converting unstructured data into structured formats and extracting only necessary insights. This parameter transformation allows the system to work with data at different levels of detail and sensitivity, reducing security risks while preserving information utility.

Inventive Principle:
Principle #35Parameter changes

3Manufacturing precision

If custom processing environments are created for each data residency requirement, then compliance accuracy is improved, but system complexity and resource consumption increase

Engineering Contradiction:
Improvecompliance accuracyVSAvoidsystem complexity
Core Design Contradiction:
Manufacturing precisionVSDevice complexity

Solution Approach 1:

The containerization platform provides a universal infrastructure that can host multiple specialized processing environments. Instead of creating entirely separate systems for each compliance requirement, the platform uses standardized containers that can be configured and deployed to meet different data residency and security requirements, reducing overall system complexity while maintaining compliance accuracy.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11855995B2Data security across data residency restriction boundaries
Publication Date: 2023.12.26 KYNDRYL INC
  • US11855995B2 patent drawing
  • US11855995B2 patent drawing
  • US11855995B2 patent drawing

AI summary

Data security across data residency restriction boundaries is provided by obtaining and profiling a dataset on which a desired analysis is to be performed, with some results of the desired analysis to be transferred from one location to another, the dataset subject to data residency restrictions that restrict transfer of the dataset across a boundary to the another location, and the profiling identifying a profile level for the dataset, then automatically generating a container image based on the profile level and the data residency restrictions that restrict the transfer of the dataset across the boundary, the container image configured for instantiation and execution to process the dataset into a reformatted dataset not restricted by the data residency restrictions for transfer across the boundary, and storing the container image to a container registry.