Restricted Data Zones for Backup Server Segregation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing backup and recovery systems face challenges in providing cost-effective solutions while ensuring privacy and autonomy for multiple users or organizations sharing a single server, as they struggle to segregate and manage data securely across distinct restricted zones.

Innovation Solution

Implementing a backup and recovery system that segregates resources into restricted data zones, allowing only authorized administrators to access and manage specific zones, with a top-level IT administrator overseeing the entire system and granting privileges to lower-level administrators for autonomous management within their designated zones.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of energy

If multiple users or organizations share a single backup and recovery server, then cost-effectiveness is improved, but privacy and data security are worsened due to inability to segregate data across distinct zones

Engineering Contradiction:
Improvecost-effectivenessVSAvoidprivacy and data security
Core Design Contradiction:
Loss of energyVSReliability

Solution Approach 1:

The backup and recovery server is divided into multiple isolated restricted data zones, where each zone can be independently accessed only by authorized administrators. This segmentation allows multiple organizations to share the same physical server infrastructure while maintaining complete data isolation and security boundaries, thus achieving both cost-effectiveness through resource sharing and privacy through zone isolation.

Inventive Principle:
Principle #1Segmentation

2Device complexity

If a single backup and recovery server is shared by multiple organizations, then device complexity is reduced, but managing autonomy and privacy for each organization becomes more difficult

Engineering Contradiction:
Improveserver infrastructureVSAvoidautonomous management
Core Design Contradiction:
Device complexityVSEase of operation

Solution Approach 1:

The server is segmented into restricted data zones with controlled access, allowing simplified shared infrastructure while maintaining organizational autonomy through zone-level permissions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Each restricted data zone is configured with specific access controls and permissions tailored to the needs of individual organizations, allowing localized management policies within the unified server environment.

Inventive Principle:
Principle #3Local quality

3Reliability

If restricted data zones are implemented with granular access controls, then privacy and security are improved, but system complexity and administrative overhead increase

Engineering Contradiction:
Improvedata securityVSAvoidsystem configuration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system uses segmented restricted data zones as the fundamental security unit, which simplifies access control configuration compared to granular file-level permissions, reducing administrative overhead while maintaining strong security boundaries.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10095587B1Restricted data zones for backup servers
Publication Date: 2018.10.09 EMC IP HLDG CO LLC
  • US10095587B1 patent drawing
  • US10095587B1 patent drawing
  • US10095587B1 patent drawing

AI summary

A method for backing up and recovering data is disclosed. Data representing an allocation of a plurality of backup resources to a plurality of restricted data zones is stored in a storage device. Any of the plurality of backup resources allocated to one restricted data zone is not allocated to another restricted data zone. A user is associated with one of the plurality of restricted data zones. Backup and recovery services are provided to the user using one or more backup resources allocated to the restricted data zone associated with the user. The backup and recovery services provided to the user are segregated from backup and recovery services provided to other users associated with restricted data zones that are different from the restricted data zone associated with the user.