Data Location Registry for Network Service Auditing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Distributed network services complicate tracking and auditing of physical data locations due to opaque implementation details, making it difficult for users to determine or restrict data storage and processing locations, which is crucial for compliance with legal, regulatory, and contractual requirements.

Innovation Solution

A system that registers and tracks the location of data within a distributed network service by generating location records and using a location registry to store and provide location information to clients, allowing for secure recording and auditing of data storage and migration across multiple network service elements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If distributed network services are used to provide flexible data processing and storage, then service flexibility and scalability are improved, but user ability to determine and control data location is worsened

Engineering Contradiction:
Improveservice flexibilityVSAvoiddata location transparency
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The patent introduces a location registry as an intermediary component that mediates between the distributed network service infrastructure and the user. This registry maintains location records that map data identifiers to physical computing resource locations, allowing users to query and control data locations without needing to understand or manage the complex distributed infrastructure directly. The location registry acts as a transparent layer that preserves user awareness and control of data locations while enabling the flexibility of distributed services.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If the service automatically determines data storage and processing locations based on system load and usage, then system efficiency and resource utilization are improved, but user control over geographic location restrictions is worsened

Engineering Contradiction:
Improvesystem efficiencyVSAvoiduser control capability
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The patent enables users to perform preliminary actions by specifying location restrictions and preferences for their data before the service begins automatic location management. The location registry stores these user-defined location constraints in association with data identifiers. The service then automatically determines actual data locations while respecting these pre-established user restrictions, allowing both automated efficiency and user control to coexist. Users can set geographic or facility-level restrictions that the automatic location determination process must honor.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If implementation details of distributed services are kept opaque to users, then service security and infrastructure protection are improved, but user ability to audit and comply with legal requirements is worsened

Engineering Contradiction:
Improveservice securityVSAvoiddata location auditability
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent extracts the location information function from the opaque service implementation details and places it in a separate, user-accessible location registry. This registry maintains location records that contain the necessary information for users to audit and track data locations without exposing the underlying service implementation details. The location registry provides a controlled interface that gives users visibility and audit capability while the main service infrastructure remains protected and opaque. Users can query location records to verify data locations for compliance purposes without accessing sensitive service infrastructure information.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS9166893B2Methods, apparatus and systems for monitoring locations of data within a network service
Publication Date: 2015.10.20 HEWLETT PACKARD ENTERPRISE DEV LP
  • US9166893B2 patent drawing
  • US9166893B2 patent drawing
  • US9166893B2 patent drawing

AI summary

In one embodiment, a data set is received at a network service element of a network service, a location record for that data set is generated, and the location record is sent to a location registry within the network service to monitored locations of that data set within a network service. The network service element is operatively coupled to a communications link. The location record is generated based on a portion of the data set and a cryptographic key associated with the network service element. The location record uniquely identifies the presence of the data set at the network service element.