Group-Based Data Storage Sharding for Enterprise Communication Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing communication systems face challenges in scaling securely while maintaining access control and administrative policies across multiple hardware systems, particularly in managing communication channels between independent enterprises.
Innovation Solution
A group-based data storage system with sharded databases and a remote computing platform that manages access based on channel and group membership, applying policies to ensure secure access and compliance with enterprise policies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If communication channels are managed across multiple hardware systems to improve scalability, then system capacity increases, but security and access control become more difficult to maintain
Solution Approach 1:
The database is divided into multiple shards distributed across different hardware systems, with each shard containing a portion of the communication channel data. This segmentation allows the system to scale horizontally while maintaining security through distributed architecture, where no single point holds all data and access control can be enforced at each shard independently.
Solution Approach 2:
A remote computing platform acts as an intermediary between client devices and the sharded database system. This mediator correlates channel identifiers with group identifiers, manages access requests, and enforces security policies across the distributed shards, thereby maintaining access control security while enabling scalability through the intermediary layer.
2Reliability
If access control is restricted to maintain security across independent enterprises, then unauthorized access is prevented, but system complexity increases
Solution Approach 1:
The remote computing platform provides a universal access control mechanism that handles multiple enterprises and numerous communication channels through a single correlated identifier system. By using group identifiers that can represent multiple enterprises and channels, the system reduces complexity while maintaining security across independent enterprises.
Solution Approach 2:
The system adds a group identifier dimension to the traditional channel identifier, creating a two-dimensional access control matrix. This dimensional expansion allows security to be managed at multiple levels (channel-level and group-level) simultaneously, simplifying the overall access control structure while maintaining granular security for independent enterprises.
3Reliability
If real-time access control is implemented across sharded databases, then security is maintained, but system performance may degrade
Solution Approach 1:
The remote computing platform performs preliminary actions by pre-correlating channel identifiers with group identifiers and pre-determining access permissions before actual data access requests. This preliminary setup of access control rules at the platform level enables faster real-time decisions at the shard level, maintaining security while improving access speed.
Solution Approach 2:
The complex access control logic and correlation operations are extracted from the individual database shards and centralized at the remote computing platform. This extraction allows the shards to focus on fast data retrieval while the platform handles security decisions, thereby maintaining real-time access control enforcement without degrading overall system performance.
Data Source
AI summary
Various embodiments are directed to group-based data storage systems configured for maintaining data exchanged between client devices within channel-specific shards each corresponding with one or more group-identifiers to provide group-based access to those channel-specific shards and for applying group-specific policies for data stored within those channel-specific shards. Membership of particular users within particular groups and within particular channels may be monitored such that access to particular channel shards may be controlled based on group-memberships of the users, and access to data stored within particular channel shards may be controlled based on channel-memberships of the users.


