Decentralized Policy Management via Blockchain and Distributed Storage
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing solutions for data protection and management in multi-cloud computing environments face challenges such as data silos, vendor lock-in, lack of efficient policy file publishing and querying, identity management, network bottlenecks, high latency, and integrity verification in decentralized systems.
Innovation Solution
A decentralized data protection and management system utilizing a combination of a blockchain network and content-addressed decentralized file system for policy publishing and querying, where policy files are stored in a decentralized storage network and metadata is managed on a blockchain, enabling secure, efficient, and unified access across multiple clouds.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a centralized server is used to store and manage policy files, then policy management is simplified, but network bottlenecks and high latency occur
Solution Approach 1:
The patent segments the centralized policy management system into a decentralized network of peer nodes. Each node can store, retrieve, and validate policy files independently through distributed hashing and peer-to-peer communication, eliminating the single-point bottleneck of centralized servers while maintaining policy management capabilities.
2Ease of operation
If policy files are stored in a centralized location, then retrieval is straightforward, but network bottlenecks and single points of failure occur
Solution Approach 1:
The patent divides the centralized policy storage into distributed segments across multiple peer nodes in the network. Each node holds copies or references to policy files through distributed hashing, enabling straightforward retrieval through peer-to-peer lookups while providing redundancy and eliminating single points of failure.
Solution Approach 2:
The patent introduces distributed hashing as an intermediary mechanism that enables direct peer-to-peer policy file retrieval without requiring a centralized coordinator. The hashing function maps policy files to specific peers, allowing nodes to locate and retrieve policies efficiently while maintaining system reliability through distribution.
3Speed
If all nodes store complete policy files, then access is fast, but storage requirements increase significantly
Solution Approach 1:
The patent uses distributed hashing to create virtual copies and references of policy files across the peer network rather than requiring each node to store complete copies. Nodes can retrieve policy files from any peer that holds them, achieving fast access through intelligent routing while minimizing total storage requirements across the network.
4Productivity
If a decentralized system is implemented, then network bottlenecks are reduced, but complexity of policy management increases
Solution Approach 1:
The patent replaces complex manual policy management mechanisms with automated distributed hashing and peer-to-peer protocols. The system automatically routes policy requests, validates files through cryptographic hashing, and manages distribution across peers without requiring complex coordination logic, thereby reducing operational complexity despite the decentralized architecture.
Data Source
AI summary
A given policy file is obtained at a publishing node of a decentralized system of nodes, wherein the given policy file defines a policy that applies to at least a subset of nodes in the decentralized system of nodes. The given policy file is sent to a decentralized storage network for storage therein. Storage metadata is received from the decentralized storage network, wherein the storage metadata represents address information associated with storage of the given policy file in the decentralized storage network. The publishing node generates policy file retrieval metadata based on the storage metadata received from the decentralized storage system. The policy file retrieval metadata is sent to a blockchain network for storage therein. One or more querying nodes of the decentralized system of nodes access the blockchain network to obtain the policy file retrieval metadata in order to then retrieve the policy file from the decentralized storage network.


