Distributed Data Management via Message Bus Policy Enforcement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Enterprise data environments face challenges in controlling data access and security, leading to unintentional exposure, security violations, and data corruption due to lack of effective data management systems that consider identity, location, and security standards.
Innovation Solution
A data management method that utilizes a message bus to receive requests for data communication between systems, references policies defining data sharing rules, and transforms data according to security protocols and storage durations, ensuring secure and controlled data access and transmission.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If data is freely shared between systems in a distributed computing environment, then data accessibility and integration are improved, but security violations and unintentional data exposure increase
Solution Approach 1:
The patent introduces a data management system as an intermediary between data sources and consuming systems. This intermediary enforces security policies, transforms data formats, and controls access based on defined rules, thereby maintaining data accessibility while preventing security violations and unauthorized exposure.
Solution Approach 2:
The system segments data management into distinct functional components: policy enforcement, data transformation, access control, and impact analysis. This segmentation allows each component to specialize in specific security and integration tasks, improving both accessibility and security independently.
2Reliability
If data access control policies are strictly enforced based on identity and location, then security and data protection are improved, but system complexity and operational overhead increase
Solution Approach 1:
The data management system implements universal policy enforcement mechanisms that handle multiple security requirements (identity-based control, location-based control, data transformation) through a single integrated framework. This reduces operational overhead by consolidating what would otherwise require multiple separate control systems.
Solution Approach 2:
The system automatically enforces access policies and performs data transformation without requiring manual intervention for each data access request. The automated policy enforcement engine evaluates access requests against defined rules and executes appropriate actions, reducing operational complexity while maintaining strict security controls.
3Reliability
If comprehensive impact analysis is performed for data changes across multiple systems, then data integrity and reliability are improved, but processing time and computational resources increase
Solution Approach 1:
The system performs preliminary impact analysis by pre-evaluating potential effects of data changes across the distributed system architecture. By analyzing data relationships and dependencies in advance, the system can quickly determine the scope and impact of changes without performing comprehensive analysis for every single data modification event.
Solution Approach 2:
The impact analysis mechanism performs analysis only when and where necessary based on data relationships and change types. Rather than进行全面 analysis for all systems, the system selectively applies impact analysis to affected subsystems, reducing processing time while maintaining data integrity for critical data elements.
Data Source
AI summary
A method for managing data in a distributed computing environment comprises receiving, on a message bus, a request to communicate data between a first system hosting data and a second system accessing data, referencing a policy defining rules for sharing data between the first system and the second system, compiling, based on the policy, a message indicating subscribers to receive the data to publish, and publishing, on the message bus, the compiled message.


