Distributed Host Data Storage Segmentation for Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current user data storage methods, such as centralized and synchronous management, store data from multiple areas together, leading to potential data leakage and low security.

Innovation Solution

A data storage method that acquires user identification and data, determines appropriate distributed hosts in different areas for storage, and associates identity and data identifications for secure regional storage, using modules to manage user data across hosts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If user data for all areas are stored centrally to a core distributed host, then data management is simplified, but data security deteriorates due to potential leakage of full amount of user data

Engineering Contradiction:
Improvedata management complexityVSAvoiddata security
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments user data by geographic area and stores it in region-specific distributed hosts rather than centralizing all data in a single core host. Each area has its own data storage location, so that data leakage in one area does not compromise the entire system. This segmentation resolves the contradiction by distributing data across multiple independent storage units.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by allowing each region to have its own data storage characteristics and access control policies. Data is stored locally in each area's distributed host with area-specific security measures, rather than applying a uniform centralized storage approach. This enables tailored security strategies for different regions while maintaining overall system integrity.

Inventive Principle:
Principle #3Local quality

2Ease of operation

If user data for all areas are stored synchronously to distributed hosts in each area, then data accessibility is improved, but data security deteriorates due to increased attack surfaces and potential leakage

Engineering Contradiction:
Improvedata accessibilityVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the distributed host system into area-specific units, where each host serves a specific geographic region. This segmentation allows data to be accessible locally in each area while preventing widespread access that would occur with full synchronization across all hosts. The segmentation limits the attack surface to individual areas rather than the entire system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary mechanism through the data storage device that manages data distribution and access control between areas. This intermediary ensures that data is not simply synchronized across all hosts but is instead selectively distributed with proper authorization, maintaining security while enabling necessary accessibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If user identification and user data are stored together in the same host, then data processing efficiency is improved, but data security deteriorates due to concentrated storage of sensitive information

Engineering Contradiction:
Improvedata processing efficiencyVSAvoiddata security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the storage of user identification and user data into separate components within the distributed system. User identification is stored in one component while user data is stored in another, allowing efficient processing through proper indexing and retrieval mechanisms while preventing the concentration of all sensitive information in a single location.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts user identification information from the main user data storage and handles it separately through the determination module. This extraction allows the system to efficiently locate and access specific user data based on identification without storing all data together, thereby maintaining processing efficiency while enhancing security through separation.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS12045492B2Data storage method, apparatus, device and storage medium using distributed hosts for user identifications
Publication Date: 2024.07.23 CHINA UNIONPAY
  • US12045492B2 patent drawing
  • US12045492B2 patent drawing
  • US12045492B2 patent drawing

AI summary

This application provides a data storage method which is applied to a data storage device and includes: acquiring a first user identification and first user data of a first user; determining, from at least two preset distributed hosts in different areas, a first identification distributed host corresponding to the first user identification and a first data distributed host corresponding to the first user data; sending the first user identification to the first identification distributed host, so that the first identification distributed host stores the first user identification, and generates and stores a first identity identification corresponding to the first user identification; receiving the first identity identification; and sending the first identity identification and the first user data to the first data distributed host, so that the first data distributed host stores them in an associated manner.