Hybrid Distributed Resource Architecture for Secure Zone Mapping

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional distributed resources are either private or public, lacking the ability to segment and provide multiple types of access in different zones, which limits their functionality and security.

Innovation Solution

A hybrid distributed resource architecture is implemented, allowing for secure asset mapping across network edges, enabling authorized access by projecting requested components from a private zone to a semi-private or public zone, while maintaining data integrity and privacy through authentication credentials and mapping tokens.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional distributed resources are used as either private or public, then simplicity of architecture is maintained, but the ability to segment and provide multiple types of access in different zones is lost

Engineering Contradiction:
Improveaccess control flexibilityVSAvoidarchitecture complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The distributed resource is segmented into multiple zones (first zone, second zone, third zone) with different access control characteristics. Each zone can have its own access policies, allowing the system to provide both private and public access capabilities simultaneously within a single distributed resource architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The distributed resource is designed to perform multiple functions by supporting different access types (private, public, semi-private) within the same architecture. This allows a single distributed resource to serve both internal organizational needs and external public access requirements.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If all components of a distributed resource are made visible across network zones, then accessibility is improved, but security and data privacy are compromised

Engineering Contradiction:
ImproveaccessibilityVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

Different zones of the distributed resource have different visibility and access characteristics tailored to their specific security requirements. The first zone may have restricted access for sensitive data, while the third zone may have broader access for public information, with intermediate zones providing graduated access levels.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system introduces intermediary mechanisms (access control layers, authentication protocols, zone boundary enforcement) that mediate between the need for accessibility and security requirements, allowing controlled visibility across zones without compromising sensitive data.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If authentication credentials are externally injected to subsequent blocks, then ease of access is improved, but security is weakened

Engineering Contradiction:
Improveaccess convenienceVSAvoidsecurity integrity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

Authentication credentials and authorization information are embedded within the block structure itself during the block creation process, rather than being injected externally later. This preliminary incorporation ensures that security credentials are tightly integrated with the immutable block data, preventing unauthorized modification while maintaining access functionality.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11140165B2System for selective mapping of distributed resources across network edge framework for authorized user access
Publication Date: 2021.10.05 BANK OF AMERICA CORP
  • US11140165B2 patent drawing
  • US11140165B2 patent drawing
  • US11140165B2 patent drawing

AI summary

A system for secure distributed resource asset mapping across network edge framework for authorized user access is provided. The system being configured to: receive a request from an external user to access a first distributed resource within a first zone of a network, wherein the request comprises authentication credentials associated with the external user and requested components of the first distributed resource; authorize the request from the external user based on the authentication credentials; collect the requested components of the first distributed resource in the first zone of the network based on the request; project the requested components across an edge from the first zone to a second zone of the network thereby forming a second distributed resource, wherein only the requested components of the first distributed resource are visible to the external user on the second distributed resource in the second zone; and extract data from the requested components.