Remote Log Repository Access Policy for Legal Compliance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Companies providing Internet access and services face challenges in efficiently maintaining access and activity logs due to the need to balance privacy, service integrity, and legal compliance, making it costly and inefficient to store complete logs indefinitely.

Innovation Solution

Implementing a remote logging system where access and activity logs are stored in a repository outside the local machine and jurisdiction, with a specific access policy controlling the type and duration of information available, allowing for flexible management and compliance with legal requirements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If complete logs are maintained indefinitely, then service integrity and legal compliance are improved, but privacy protection deteriorates and storage costs increase

Engineering Contradiction:
Improveservice integrityVSAvoidprivacy risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments log data into different retention periods based on legal requirements and business needs. Different types of log information are maintained for different durations, with complete logs kept only as long as legally required, while summary information is maintained longer. This segmentation resolves the contradiction by maintaining necessary logs for reliability while limiting long-term storage that creates privacy risks.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the parameter of log retention duration from indefinite to finite, matching legal requirements. By adjusting the retention period parameter to align with statutory obligations, the system maintains service integrity for required periods while automatically reducing privacy exposure by not storing logs indefinitely.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If complete logs are maintained indefinitely, then legal compliance is improved, but storage costs and operational complexity increase

Engineering Contradiction:
Improvelegal complianceVSAvoidlog management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic log retention policies that automatically adjust based on legal requirements and data age. The system dynamically transitions logs from complete detailed format to summarized format, and from active storage to archived storage, reducing management complexity while maintaining compliance. This dynamic approach eliminates the need for manual tracking of retention periods.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent establishes predetermined retention schedules based on legal requirements before logs are generated. By pre-defining retention periods and access policies, the system automatically complies with legal requirements without requiring complex real-time decision-making or manual intervention, thus reducing operational complexity.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If detailed log information is maintained, then abuse detection capability is improved, but privacy exposure and liability increase

Engineering Contradiction:
Improveabuse detection capabilityVSAvoidprivacy exposure
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies different quality levels of log detail to different time periods and access scenarios. Recent logs maintain full detail for abuse detection, while older logs are summarized or aggregated. This local quality differentiation allows effective abuse detection in the short term while reducing privacy exposure in the long term.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements partial retention of detailed log information, keeping complete details only for periods and cases where they are legally required or suspected abuse occurs. For routine operations and older periods, summary information suffices. This partial action approach maintains abuse detection capability when needed while minimizing unnecessary privacy exposure.

Inventive Principle:
Principle #16Partial or excessive action

4Reliability

If all log information is produced upon subpoena, then legal compliance is improved, but response cost and time increase

Engineering Contradiction:
Improvelegal complianceVSAvoidsubpoena response time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary organization of logs according to predetermined retention schedules and access policies before subpoenas are received. Logs are pre-categorized by retention period, access level, and legal requirement, enabling rapid identification and production of only relevant logs. This preliminary organization dramatically reduces subpoena response time while ensuring complete compliance.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent extracts and produces only the specific log information that falls within the retention period and meets legal requirements, rather than producing all logs indiscriminately. By extracting only relevant information based on pre-established criteria, the system achieves full legal compliance while minimizing response time and resource expenditure.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS8214482B2Remote log repository with access policy
Publication Date: 2012.07.03 CALLAHAN CELLULAR LLC
  • US8214482B2 patent drawing
  • US8214482B2 patent drawing
  • US8214482B2 patent drawing

AI summary

A method and apparatus for remote logging of access to and activity on a computerized network is provided. Logging information is transmitted to a remote log repository and is not maintained by the local log generating machine. After the logging information is stored in the remote repository, the access to the information is controlled by a specific policy that governs the type of information and the time period during which the information is available. No access is provided to information outside the bounds of the access policy. Preferably the remote log repository is outside the jurisdiction of relevant authorities. This allows the access policy between the log generating entity and the log repository to dictate precisely the information that is under the control of the log generating entity. The use of a remote log repository and a specific access policy affords flexibility to the log generating entity in balancing its multiple responsibilities and makes responding to subpoenas cost effective and efficient.