Group-Based Data Storage Sharding for Enterprise Communication Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication systems face challenges in scaling securely while maintaining access control and administrative policies across multiple hardware systems, particularly in managing communication channels between independent enterprises.

Innovation Solution

A group-based data storage system with sharded databases and a remote computing platform that manages access based on channel and group membership, applying policies to ensure secure access and compliance with enterprise policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If communication channels are managed across multiple hardware systems to improve scalability, then system capacity increases, but security and access control become more difficult to maintain

Engineering Contradiction:
Improvesystem scalabilityVSAvoidaccess control security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The database is divided into multiple shards distributed across different hardware systems, with each shard containing a portion of the communication channel data. This segmentation allows the system to scale horizontally while maintaining security through distributed architecture, where no single point holds all data and access control can be enforced at each shard independently.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A remote computing platform acts as an intermediary between client devices and the sharded database system. This mediator correlates channel identifiers with group identifiers, manages access requests, and enforces security policies across the distributed shards, thereby maintaining access control security while enabling scalability through the intermediary layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If access control is restricted to maintain security across independent enterprises, then unauthorized access is prevented, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidaccess control mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The remote computing platform provides a universal access control mechanism that handles multiple enterprises and numerous communication channels through a single correlated identifier system. By using group identifiers that can represent multiple enterprises and channels, the system reduces complexity while maintaining security across independent enterprises.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system adds a group identifier dimension to the traditional channel identifier, creating a two-dimensional access control matrix. This dimensional expansion allows security to be managed at multiple levels (channel-level and group-level) simultaneously, simplifying the overall access control structure while maintaining granular security for independent enterprises.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Reliability

If real-time access control is implemented across sharded databases, then security is maintained, but system performance may degrade

Engineering Contradiction:
Improveaccess control enforcementVSAvoiddata access speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The remote computing platform performs preliminary actions by pre-correlating channel identifiers with group identifiers and pre-determining access permissions before actual data access requests. This preliminary setup of access control rules at the platform level enables faster real-time decisions at the shard level, maintaining security while improving access speed.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The complex access control logic and correlation operations are extracted from the individual database shards and centralized at the remote computing platform. This extraction allows the shards to focus on fast data retrieval while the platform handles security decisions, thereby maintaining real-time access control enforcement without degrading overall system performance.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS12056106B2Data storage architecture for an enterprise communication system
Publication Date: 2024.08.06 SALESFORCE INC
  • US12056106B2 patent drawing
  • US12056106B2 patent drawing
  • US12056106B2 patent drawing

AI summary

Various embodiments are directed to group-based data storage systems configured for maintaining data exchanged between client devices within channel-specific shards each corresponding with one or more group-identifiers to provide group-based access to those channel-specific shards and for applying group-specific policies for data stored within those channel-specific shards. Membership of particular users within particular groups and within particular channels may be monitored such that access to particular channel shards may be controlled based on group-memberships of the users, and access to data stored within particular channel shards may be controlled based on channel-memberships of the users.