Distributed Data Domains for Secure Policy-Based Data Movement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing big data systems struggle to efficiently organize and secure large quantities of data into logical subsets with varying security and access control requirements, making it difficult to manage and move these subsets within or between systems.
Innovation Solution
A method and system that defines domains as logical subsets of directories, files, or collections in a distributed data store, assigns properties and policies to these domains, and enables secure copying and movement of these domains within or between data stores, using application programming interfaces and metadata management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data is organized into logical subsets with varying security policies, then data security and access control are improved, but system complexity increases
Solution Approach 1:
The patent segments the distributed data store into logical subsets called domains, where each domain can have its own security policies and access controls. This segmentation allows different security requirements to be applied to different data subsets without affecting the entire system, thereby improving data security while managing complexity through modular organization.
Solution Approach 2:
The patent introduces domain metadata and domain objects as intermediary layers between the physical data storage and the security management system. These intermediaries abstract the complexity of security policy enforcement, allowing security rules to be applied uniformly at the domain level while hiding the underlying complexity from users and applications.
2Manufacturing precision
If security policies are customized for different data subsets, then access control precision is improved, but management difficulty increases
Solution Approach 1:
By segmenting data into domains with distinct security policies, the system achieves precise access control for different data subsets. Each domain can enforce specific security rules tailored to its requirements, enabling fine-grained access control while simplifying management through domain-based organization rather than individual data element control.
Solution Approach 2:
The domain object serves as a universal container that can hold multiple data elements with different security requirements. This multi-functionality allows a single domain object to manage diverse data types and security policies, reducing management difficulty by providing a unified interface for security control across heterogeneous data subsets.
3Adaptability or versatility
If data subsets are moved between locations or systems, then data flexibility and mobility are improved, but security policy consistency becomes difficult to maintain
Solution Approach 1:
The patent uses domain metadata copying and replication to maintain security policy consistency when data subsets are moved. The domain metadata, which contains security policy information, is copied along with the data during transfer operations, ensuring that security policies are preserved and applied consistently at the destination location or system.
Solution Approach 2:
The system performs preliminary binding of security policies to domain metadata before data movement operations. By pre-associating security policies with the domain object and its metadata, the system ensures that security rules are automatically maintained during transfer, eliminating the need for post-movement policy reconfiguration and ensuring consistency.
Data Source
AI summary
A system groups multiple entities in a large distributed data store (DDS), such as directories and files, into a subset called a domain. The domain is treated as a unit for defining policies to detect and treat sensitive data. Sensitive data can be defined by enterprise or industry. Treatment of sensitive data may include quarantining, masking, and encrypting, of the data or the entity containing the data. Data in a domain can be copied as a unit, with or without the same structure, and with transformations such as masking or encryption, into parts of the same DDS or to a different DDS. Domains can be the unit of access control for organizations, and assigned tags useful for identifying their purpose, ownership, location, or other characteristics. Policies and operations, assigned at the domain level, may vary from domain to domain, but within a domain are uniform, except for specific exclusions.


