Endpoint Telemetry Routing via Realm Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems face challenges in managing and routing endpoint telemetry data across different geographical regions, where varying data protection and privacy regulations, such as GDPR and CCPA, require complex compliance and data sovereignty management.

Innovation Solution

The solution involves segmenting data into realms within a computer network, where endpoint agents collect and route telemetry data based on realm definitions that adhere to specific data protection and privacy restrictions, ensuring compliance with regional regulations by defining governing data collection policies and permissible processing facilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If endpoint telemetry data is collected and routed across multiple geographical regions, then data processing capability and security monitoring are improved, but compliance with varying data protection and privacy regulations becomes more complex

Engineering Contradiction:
Improvecompliance with data protection regulationsVSAvoidcomplexity of compliance management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the network into distinct realms (e.g., EU realm, US realm, Asia realm) where each realm is governed by specific data protection regulations. Endpoint devices are assigned to realms based on their geographical location or organizational unit, and telemetry data is routed within realms rather than across all regions. This segmentation isolates compliance requirements to specific zones, reducing overall system complexity while maintaining regulatory adherence.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Each realm is configured with local data protection policies and privacy restrictions specific to its geographical region. The system applies different data collection, storage, and processing rules to different realms - for example, GDPR-compliant handling for EU realms versus different policies for US or Asian realms. This local quality approach ensures regulatory compliance without requiring a single complex unified compliance system.

Inventive Principle:
Principle #3Local quality

2Reliability

If telemetry data is collected from all endpoint devices globally, then security monitoring and audit capabilities are improved, but data sovereignty and local privacy restrictions are compromised

Engineering Contradiction:
Improvedata sovereignty complianceVSAvoidtelemetry collection efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system divides global endpoint devices into separate realms based on their geographical location or organizational affiliation. Telemetry data collection is segmented by realm, with each realm collecting and processing data according to its specific sovereignty and privacy requirements. This prevents unauthorized cross-border data transfer while maintaining comprehensive security monitoring within each region.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Each realm implements local data sovereignty policies that dictate what data can be collected, where it can be stored, and how it can be processed. For example, EU realms may collect and store data locally according to GDPR, while US realms follow different privacy laws. This local quality approach ensures data sovereignty compliance while allowing efficient telemetry collection within each region's legal framework.

Inventive Principle:
Principle #3Local quality

3Productivity

If data is routed to remote processing facilities, then centralized processing capability is improved, but network bandwidth consumption and latency increase

Engineering Contradiction:
Improvecentralized processing capabilityVSAvoidnetwork bandwidth consumption
Core Design Contradiction:
ProductivityVSLoss of energy

Solution Approach 1:

The patent implements realm-based segmentation that creates localized processing zones. Instead of routing all telemetry data to a single remote central facility, data is processed within or near its originating realm. This segmentation enables distributed processing that reduces the distance data must travel, thereby lowering network bandwidth consumption and latency while maintaining centralized processing capabilities through realm-level coordination.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Each realm is configured with local processing facilities that handle telemetry data within the realm before any necessary centralized processing occurs. This local quality approach allows immediate processing and analysis of data within the region, reducing the need for long-distance data transmission. Centralized processing capabilities are maintained at the realm level or through selective routing, optimizing the balance between centralized control and local processing efficiency.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20240403486A1Managing and routing of endpoint telemetry using realms
Publication Date: 2024.12.05 GOLDMAN SACHS BANK USA
  • US20240403486A1 patent drawing
  • US20240403486A1 patent drawing
  • US20240403486A1 patent drawing

AI summary

A computer network includes user endpoint devices geographically distributed relative to one another such that at least one of the endpoint devices is subject to a different set of data protection or privacy restrictions than other endpoint devices and data processing facilities coupled to the user endpoint devices over a network. The data processing facilities are in different geographical regions or sovereignties. A computer-based endpoint agent is in each of the endpoint devices. Each endpoint agent is configured to collect telemetry data relating to user activity at its associated endpoint device and transmit the collected telemetry data to a selected one of the data processing facilities, according to an applicable realm definition, in compliance with the data protection or privacy restrictions that apply to the agent's endpoint device.