Global Namespace Data Access Control Platform

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional data access management techniques are ineffective in controlling access to data across multiple geo-locations and cloud services, failing to protect data outside centralized locations and unable to track private data throughout its lifecycle, leading to vulnerabilities and compliance issues.

Innovation Solution

A data control platform that implements access controls independently of data location, using a global namespace to manage access policies, data record location descriptors, and compliance policies, ensuring secure data access and governance across distributed data platforms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If conventional centralized access controls are used to manage data access, then access control implementation is simplified, but data protection is lost when data moves outside the centralized location

Engineering Contradiction:
Improveaccess control implementationVSAvoiddata protection
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the access control mechanism from the data storage location. Instead of having access controls tied to a single centralized location, the system divides access control into portable policy components that can travel with data across multiple locations and transformations, enabling protection without requiring centralized control at each data point

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary access control system that sits between the data and various access points. This intermediary layer enforces access policies regardless of where the data is located or what transformations it has undergone, acting as a mediator that maintains security without requiring direct control over the underlying data storage

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If data is allowed to move freely across multiple locations and transformations, then data utility and accessibility are improved, but tracking and protecting private data becomes difficult

Engineering Contradiction:
Improvedata accessibilityVSAvoiddata tracking
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent applies local quality by attaching specific access control metadata and policy tags to individual data elements as they move through transformations. This allows the system to track and protect only the private portions of data that require protection, while allowing other data to move freely, thus maintaining data utility while enabling targeted tracking

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements feedback mechanisms that continuously monitor data movements and transformations. The system provides feedback about data location and transformation state to the access control engine, which then adjusts access decisions accordingly, enabling continuous tracking without blocking data flow

Inventive Principle:
Principle #23Feedback

3Reliability

If access controls are implemented at every data location and transformation point, then data protection is maintained, but system complexity increases significantly

Engineering Contradiction:
Improvedata protectionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal access control framework that handles multiple locations, storage systems, and transformation types through a single unified policy enforcement mechanism. This universal system reduces complexity by eliminating the need for separate access control implementations at each data point while maintaining comprehensive protection

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11388168B2Data governance operations in highly distributed data platforms
Publication Date: 2022.07.12 EMC IP HLDG CO LLC
  • US11388168B2 patent drawing
  • US11388168B2 patent drawing
  • US11388168B2 patent drawing

AI summary

A method in one embodiment comprises receiving a plurality of requests for data records from a plurality of clients. The data is in a plurality of data systems of a global namespace, and the plurality of data systems are in a plurality of locations. The method also comprises determining whether a given client is allowed access to one or more of the data records based on one or more of a plurality of data access policies, retrieving the data records from at least one of the data systems based on a determination that the given client is allowed access to the data records, and providing the data records to the given client. Retrieving the data records comprises determining a location for the data records, and generating a channel to the location through which the data records are retrieved.