Partitioned Data Storage System for Secure Cross-Organization Exchange
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current data storage systems lack comprehensive security measures for ensuring ownership and attribution protection during data exchanges between organizations on public cloud platforms, failing to securely manage sensitive data transactions and access rights.
Innovation Solution
A data storage system with separate storage partitions for each organization, including private and exchange partitions, where data processing requests are executed based on predefined strategies for authorization, change, and presentation requests, ensuring secure data management and access control.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If data is stored in a unified storage space without partitioning, then data access and exchange between organizations is simplified, but security and ownership protection during data exchanges cannot be ensured
Solution Approach 1:
The storage space is segmented into multiple storage partitions, with each partition corresponding to a different organization. This segmentation enables isolated data management while maintaining security boundaries, allowing each organization to control access to its data without compromising overall system security or operational simplicity.
2Reliability
If separate storage partitions are created for each organization, then security and ownership protection are improved, but system complexity increases
Solution Approach 1:
The storage partitioning mechanism serves multiple functions simultaneously: it provides security isolation, enables ownership attribution, facilitates data exchange control, and supports flexible access policies. This multi-functionality reduces the need for separate security mechanisms, thereby managing system complexity while achieving comprehensive protection.
3Reliability
If strict access control policies are enforced for all data requests, then data security is improved, but data exchange efficiency and productivity decrease
Solution Approach 1:
The access control system dynamically adjusts authorization levels based on the specific data processing request, storage partition types involved, and predefined policies. Rather than applying uniform strict controls to all requests, the system adapts security measures to the context of each operation, maintaining security while enabling efficient data exchange where appropriate.
Data Source
AI summary
The present disclosure discloses a data information processing method. A storage space corresponding to an organization is disposed in a data storage system. A data processing request type, the storage partition in which a project sending a data processing request is located, and the storage partition of the target data information corresponding to the data processing request are acquired when the data processing request is received. Subsequently, a processing strategy matching the storage partitions and the type is acquired. Finally, the target data information is processed according to the processing strategy and the data processing request. Thus, the isolation and rights control of different data in the same storage space can be achieved, and the security and mobility of data can be ensured.


