Personal Cloud Network Distributed Storage Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional network-based data storage solutions require large company resources and limit file sharing between individual users, often requiring users to store data on provider servers, which complicates administration and restricts data access.
Innovation Solution
A personal cloud network system allows individual users to establish and maintain a shared data storage area on a network-attached storage device, accessible via both public and private networks, with a central server registration and access control mechanisms to manage peer access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If conventional network-based data storage solutions are used, then data storage and access is provided, but large company resources are required and individual users cannot establish their own storage spaces
Solution Approach 1:
The system enables individual users to self-provision and manage their own distributed storage spaces using their existing personal devices and networks. Users install the storage agent on their own devices, configure shared folders, and manage access permissions without requiring provider intervention or infrastructure, thus achieving user control while avoiding large company resource requirements
Solution Approach 2:
The conventional centralized storage system is segmented into distributed storage nodes across multiple user devices. Each user's device becomes an independent storage node that can be accessed by authorized peers, transforming a monolithic provider-controlled system into a distributed network of user-controlled storage spaces
2Ease of operation
If FTP or VPN providers host storage units, then data storage is provided, but administration becomes complicated and users must store files on provider servers
Solution Approach 1:
The storage functionality is extracted from the provider server and placed directly on user devices. The storage agent running locally on each user's device manages file storage and sharing operations, eliminating the need for users to rely on provider-hosted storage units and complicated provider administration
Solution Approach 2:
The storage agent is designed to run on universal personal devices (computers, smartphones, tablets) that users already possess, rather than requiring specialized provider infrastructure. This multi-functional approach allows the same software to operate across different device types and networks, simplifying both deployment and administration
3Reliability
If users connect directly to each other's devices, then secure access is achieved, but network address discovery becomes difficult across public and private networks
Solution Approach 1:
The notification server acts as an intermediary that facilitates peer discovery and connection establishment without compromising security. When a user wants to access another user's storage space, the client sends a request through the notification server, which relays the connection information back to the client. This allows secure direct peer-to-peer data transfer while simplifying the connection establishment process across complex network environments
Data Source
AI summary
A distributed storage space for individual users and their selected peers is provided. The personal cloud system allows an individual user to establish and maintain a shared data storage area on a network attached storage device connected to the individual user's private network and accessible to one or more network devices via a public network and the private network. The personal cloud system registers the shared data storage area with a central server and sends an invitation to one or more network peers to join the shared data storage area. The personal cloud system then monitors incoming data packets at the network attached storage device to identify requests from invited network peers to access the shared data storage area. Access is provided in accordance with predetermined access controls upon validation of the request.


