Distributed Data Management via Message Bus Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprise data environments face challenges in controlling data access and security, leading to unintentional exposure, security violations, and data corruption due to lack of effective data management systems that consider identity, location, and security standards.

Innovation Solution

A data management method that utilizes a message bus to receive requests for data communication between systems, references policies defining data sharing rules, and transforms data according to security protocols and storage durations, ensuring secure and controlled data access and transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If data is freely shared between systems in a distributed computing environment, then data accessibility and integration are improved, but security violations and unintentional data exposure increase

Engineering Contradiction:
Improvedata accessibilityVSAvoidsecurity violations
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a data management system as an intermediary between data sources and consuming systems. This intermediary enforces security policies, transforms data formats, and controls access based on defined rules, thereby maintaining data accessibility while preventing security violations and unauthorized exposure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments data management into distinct functional components: policy enforcement, data transformation, access control, and impact analysis. This segmentation allows each component to specialize in specific security and integration tasks, improving both accessibility and security independently.

Inventive Principle:
Principle #1Segmentation

2Reliability

If data access control policies are strictly enforced based on identity and location, then security and data protection are improved, but system complexity and operational overhead increase

Engineering Contradiction:
Improvedata protectionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The data management system implements universal policy enforcement mechanisms that handle multiple security requirements (identity-based control, location-based control, data transformation) through a single integrated framework. This reduces operational overhead by consolidating what would otherwise require multiple separate control systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system automatically enforces access policies and performs data transformation without requiring manual intervention for each data access request. The automated policy enforcement engine evaluates access requests against defined rules and executes appropriate actions, reducing operational complexity while maintaining strict security controls.

Inventive Principle:
Principle #25Self-service

3Reliability

If comprehensive impact analysis is performed for data changes across multiple systems, then data integrity and reliability are improved, but processing time and computational resources increase

Engineering Contradiction:
Improvedata integrityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary impact analysis by pre-evaluating potential effects of data changes across the distributed system architecture. By analyzing data relationships and dependencies in advance, the system can quickly determine the scope and impact of changes without performing comprehensive analysis for every single data modification event.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The impact analysis mechanism performs analysis only when and where necessary based on data relationships and change types. Rather than进行全面 analysis for all systems, the system selectively applies impact analysis to affected subsystems, reducing processing time while maintaining data integrity for critical data elements.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10356026B2Data management in a distributed computing environment
Publication Date: 2019.07.16 MICRO FOCUS LLC
  • US10356026B2 patent drawing
  • US10356026B2 patent drawing
  • US10356026B2 patent drawing

AI summary

A method for managing data in a distributed computing environment comprises receiving, on a message bus, a request to communicate data between a first system hosting data and a second system accessing data, referencing a policy defining rules for sharing data between the first system and the second system, compiling, based on the policy, a message indicating subscribers to receive the data to publish, and publishing, on the message bus, the compiled message.