Data Virtualization Layer for Secure Enterprise Governance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprises face challenges in securely managing and governing data across multiple departments and geographic locations, while ensuring compliance with regulations and preventing data duplication and exposure.

Innovation Solution

The system provides a data management service that enables secure data rights management and governance, interoperability, and analytics capabilities, using mechanisms such as identity and access management, data virtualization, secure execution environments, and time series database services to manage data securely and efficiently.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If data is accessed across multiple departments and geographic locations, then collaboration and data utility are improved, but data security and governance control are worsened

Engineering Contradiction:
Improvedata accessibilityVSAvoiddata exposure risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements a data virtualization layer that acts as an intermediary between data consumers and actual data sources. This layer provides controlled access to data across departments and locations without exposing the underlying data infrastructure, thereby maintaining security while enabling collaboration. The virtualization layer enforces access policies and masks data origins, allowing versatile data access while mitigating exposure risks.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If data is stored centrally for easier management, then governance control is improved, but data duplication prevention and security are worsened

Engineering Contradiction:
Improvedata management controlVSAvoiddata architecture complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent segments the data management system into multiple independent components: data source systems, virtualization layer, policy enforcement points, and consumption interfaces. This segmentation allows centralized governance control through the virtualization layer while maintaining distributed data storage, thereby avoiding the need for physical centralization and reducing associated security and complexity risks.

Inventive Principle:
Principle #1Segmentation

3Reliability

If access control mechanisms are strengthened to prevent data exposure, then data security is improved, but data collaboration and accessibility are worsened

Engineering Contradiction:
Improvedata securityVSAvoiddata collaboration efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements dynamic access control where permissions and policies are adjusted based on context such as user role, data sensitivity, and collaboration needs. The system automatically adapts security measures rather than applying static restrictions, thereby maintaining strong security controls while enabling efficient collaboration when appropriate. This dynamic approach allows security to be as permissive as necessary and as restrictive as required.

Inventive Principle:
Principle #15Dynamics

4Adaptability or versatility

If data is migrated to cloud for better accessibility, then data utility and collaboration are improved, but data sovereignty and security control are worsened

Engineering Contradiction:
Improvedata accessibilityVSAvoiddata sovereignty control
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent adds a new dimension of control by implementing a virtualization layer that operates above the physical storage location. This layer enables data sovereignty and security control regardless of whether data resides on-premises or in the cloud. The virtualization dimension separates logical data management from physical storage, allowing cloud accessibility while maintaining organizational control through policy enforcement at the virtualization layer.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS20250181706A1Data management and governance systems and methods
Publication Date: 2025.06.05 INTERTRUST TECH CORP
  • US20250181706A1 patent drawing
  • US20250181706A1 patent drawing
  • US20250181706A1 patent drawing

AI summary

This disclosure relates to, among other things, scalable data processing, storage, and/or management systems and methods. Certain embodiments disclosed herein provide for a data management architecture that allows for more secure storage of enterprise data, making it more secure, usable, and/or interoperable, facilitating data usage across information silos. Further embodiments provide for comprehensive data access authentication and/or authorization functionality between various services included in embodiments of the disclosed architecture.