Network-Based Data Compliance Broker for Distributed Storage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing distributed data storage systems face challenges in enforcing data compliance policies across geographically distributed data centers and cloud computing environments, particularly when data transmission crosses jurisdictional boundaries, due to varying regulations and agreements.

Innovation Solution

The implementation of a distributed data system that utilizes network-based, real-time data brokers to manage and enforce data compliance policies through policy administration points, federated brokers, and proxy pointer stores, which apply and manage data access policies to determine where and how data is stored and accessed, ensuring compliance with local and international regulations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If data is stored in geographically distributed data centers to enable global access, then data accessibility and service availability are improved, but compliance with jurisdictional data storage regulations becomes difficult to enforce

Engineering Contradiction:
Improvedata accessibilityVSAvoidcompliance enforcement
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

A compliance broker is introduced as an intermediary component between data storage systems and jurisdictional regulations. The broker intercepts data access requests, determines applicable compliance policies based on data location and requester identity, and enforces appropriate access controls. This mediator enables global data accessibility while ensuring regulatory compliance by automatically applying the correct policies without requiring manual intervention or system redesign.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If data transmission across jurisdictional boundaries is enabled for global ICT services, then service versatility and user reach are improved, but regulatory compliance risks increase

Engineering Contradiction:
Improveservice versatilityVSAvoidregulatory compliance risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

Compliance policies are pre-configured and stored in a policy administration point before data transmission occurs. When data requests are made, the system automatically retrieves and applies the appropriate pre-established policies based on the data's jurisdictional attributes and the requester's location. This preliminary preparation of compliance rules enables versatile global data services while ensuring regulatory compliance is automatically enforced without adding complexity to service delivery.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If distributed data storage is implemented across multiple locations, then data availability and system resilience are improved, but the complexity of managing compliance policies increases

Engineering Contradiction:
Improvesystem resilienceVSAvoidpolicy management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The compliance broker is designed as a universal system that handles multiple compliance policies, jurisdictions, and data types through a single unified interface. Rather than requiring separate compliance management systems for each data center or jurisdiction, the broker automatically adapts to different regulatory requirements by retrieving appropriate policies from the policy administration point. This multi-functional approach maintains system resilience across distributed locations while simplifying policy management complexity through centralization and automation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10778693B2Network-based real-time distributed data compliance broker
Publication Date: 2020.09.15 CISCO TECHNOLOGY INC
  • US10778693B2 patent drawing
  • US10778693B2 patent drawing
  • US10778693B2 patent drawing

AI summary

In an embodiment, a data processing system comprises: one or more processors; one or more non-transitory computer-readable storage media storing sequences of instructions which, when executed by the one or more processors, cause the processor to perform: in a local data service, receiving a request for processing data; identifying one or more local policies applicable to the request; based, at least in part, on the one or more local policies, determining whether the request may be processed locally; in response to determining that the request may not be processed locally, transmitting the request to one or more remote brokers to cause the one or more remote brokers to determine a remote data service configured to process the request.