Decentralized Hybrid Cloud Architecture for User-Controlled Data Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cloud systems, particularly hybrid cloud systems, are economically inaccessible and require complex design and management by third-party experts, posing security risks and high costs for private users, small and medium enterprises, and government bodies handling sensitive data.

Innovation Solution

A decentralized hybrid cloud system where users maintain direct control over their data through personal servers, integrating with public servers while ensuring data security and accessibility, using artificial intelligence for customized user experiences.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a private cloud system is used to ensure data security and control, then data security is improved, but the cost and complexity of infrastructure investment increase significantly

Engineering Contradiction:
Improvedata securityVSAvoidinfrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments cloud infrastructure into virtualized server devices that can be independently deployed and managed. Each server device virtualizes computing, storage, and networking resources, allowing organizations to build private cloud capabilities through modular components rather than monolithic infrastructure, thereby reducing overall complexity while maintaining security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A virtualization layer acts as an intermediary between physical hardware and cloud services, abstracting complex infrastructure management from end users. This virtualization intermediary handles resource allocation, networking, and security policies, simplifying the user experience while maintaining robust security controls behind the scenes.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If a public cloud system is used to reduce costs and simplify access, then ease of operation is improved, but data security and control deteriorate

Engineering Contradiction:
Improvecloud accessibilityVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system allows different security levels and control mechanisms to be applied to different data and workloads locally. Sensitive data can be stored and processed in isolated virtual environments with enhanced security controls, while less sensitive operations can utilize more accessible public cloud resources, enabling each data item to have its own security characteristics.

Inventive Principle:
Principle #3Local quality

3Reliability

If third-party experts are involved in designing and managing hybrid cloud systems, then system reliability is improved, but loss of information increases due to sharing sensitive data with external parties

Engineering Contradiction:
Improvesystem management qualityVSAvoiddata confidentiality
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system creates virtual copies of infrastructure resources that can be managed by third parties without exposing actual sensitive data. Virtualized environments replicate necessary functionality while maintaining data isolation, allowing external experts to perform management tasks on copies rather than accessing real confidential information.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system extracts and isolates sensitive data from the management plane, separating data access from administrative functions. Third-party managers can control and configure systems through virtualized interfaces that do not require direct access to sensitive data, extracting only the necessary control functions while leaving data confidential.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP4697653A1Decentralized hybrid cloud system
Publication Date: 2026.02.18 FXT DIGITAL SRL
  • EP4697653A1 patent drawingFigure 1
  • EP4697653A1 patent drawingFigure 2
  • EP4697653A1 patent drawingFigure 3

AI summary

A decentralized hybrid cloud system (30) comprising at least one service provider space (22), owned and controlled by a service provider, and a plurality of user spaces (32), each one owned and controlled directly and exclusively by a respective human user. The service provider space (22) comprises at least one public server device (16) which is configured to manage and provide respective data (18) and services (19), and is capable of coordinating and placing the user spaces (32) in communication with each other. Each user space (32) comprises at least one respective client device (20) which is configured to manage and run applications (21), and at least one user space (32) further comprises at least one personal server device (36) which is configured to manage and provide respective data (38) and services (39), and is capable of providing these data (38) and services (39) to other user spaces (32) as well. The client device (20) of the user space (32) is functionally connected to the public server device (16) of the service provider space (22) and/or to the personal server device (36) of the user space (32). The personal server device (36) of the user space (32) is functionally connected to the public server device (16) of the service provider space (22), and also to the personal server devices (36) and to the client devices (20) of the other user spaces (32). Each data item (45, 48, 55, 58) generated by the client device (20) or by the personal server device (36) of the user space (32) is owned and controlled directly and exclusively by the human user. Moreover, the data item (45, 48, 55, 58) is stored, managed, and protected in the public server device (16) of the service provider space (22) and/or in the personal server device (36) and/or in the client device (20) of the user space (32), as a function of specific information associated with the data item (45, 48, 55, 58) by the human user who owns and controls it. Moreover, the data item (45, 48, 55, 58) generated by the client device (20) or by the personal server device (36) of the user space (32) can be distributed, managed and protected in the personal server devices (36) and/or in the client devices (20) of the other user spaces (32), as a function of specific information associated with the data item (45, 48, 55, 58) by the human user who owns and controls it. The specific information associated with the data item (45, 48, 55, 58) comprises a security profile that configures the behavior of the system (30) with respect to the data item (45, 48, 55, 58), and which is used by all the services (19, 39), including those provided by way of artificial intelligence, to manage, use, process and protect the data item (45, 48, 55, 58) as a function of its criticality, thus ensuring a high level of protection of the sensitive data of the human user.