Distributed Data Domains for Subset Security and Secure Transfer
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing big data systems struggle to manage and secure large quantities of data efficiently, particularly in ensuring different subsets meet diverse security and access control requirements across various departments within an enterprise.
Innovation Solution
A method and system for organizing data into logical subsets within distributed data stores, applying security policies, and enabling secure movement of these subsets between systems, utilizing an application programming interface (API) for communication and metadata management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Quantity of substance
If data is stored in a highly distributed file system with millions of entities, then storage capacity and parallel processing capability are improved, but data management complexity and security control difficulty increase
Solution Approach 1:
The patent segments the large distributed data store into hierarchical groups and subgroups, allowing data to be organized in manageable units. This segmentation enables independent security policies to be applied to each group while maintaining overall system integrity, thus reducing management complexity despite the large scale of data storage.
Solution Approach 2:
The patent introduces an intermediary layer (the grouping and subgrouping structure with associated security policies) between the raw data and the access control mechanisms. This intermediary enables centralized management of security policies without requiring direct control over each individual data entity, thereby simplifying data management in large distributed systems.
2Reliability
If different security policies are applied to different data subsets for various departments, then data security and access control are improved, but system complexity and operational overhead increase
Solution Approach 1:
The patent divides data into hierarchical groups and subgroups that can be associated with different security policies. Each group can have its own access control rules, allowing different departments to have appropriate access to relevant data subsets while maintaining security. This segmentation enables fine-grained security control without requiring complex individual policies for every data element.
Solution Approach 2:
The patent merges multiple data entities into groups and subgroups that share common security policies. By combining data elements with similar security requirements into unified groups, the system reduces the number of individual policy configurations needed, thereby lowering system complexity while maintaining appropriate security controls for each department.
3Adaptability or versatility
If data subsets are moved between different locations or systems, then data flexibility and operational capability are improved, but security risk and data integrity challenges increase
Solution Approach 1:
The patent applies security policies to data groups and subgroups before movement occurs. By pre-configuring security policies, encryption requirements, and access controls on the source groups, the system ensures that data maintains its security and integrity during transfer to different locations or systems, thereby enabling flexibility without compromising reliability.
Data Source
AI summary
A system groups multiple entities in a large distributed data store (DDS), such as directories and files, into a subset called a domain. The domain is treated as a unit for defining policies to detect and treat sensitive data. Sensitive data can be defined by enterprise or industry. Treatment of sensitive data may include quarantining, masking, and encrypting, of the data or the entity containing the data. Data in a domain can be copied as a unit, with or without the same structure, and with transformations such as masking or encryption, into parts of the same DDS or to a different DDS. Domains can be the unit of access control for organizations, and assigned tags useful for identifying their purpose, ownership, location, or other characteristics. Policies and operations, assigned at the domain level, may vary from domain to domain, but within a domain are uniform, except for specific exclusions.


