Secure Node Placement for Sensitive Stream Processing Elements

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing stream processing technologies lack a method to ensure the secure processing of sensitive data across multiple nodes, which are physical or virtual, by identifying and assigning them to the most secure nodes based on their security states.

Innovation Solution

A detection program splits data jobs into processing elements, identifies sensitive data, determines if it exceeds a sensitivity threshold, and assigns these elements to secure nodes with optimal security states, ensuring secure processing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If data jobs are processed across multiple nodes in a stream processing environment, then processing capacity and throughput are improved, but the risk of data breaches increases due to potential security vulnerabilities on different nodes

Engineering Contradiction:
Improveprocessing capacityVSAvoiddata breach risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by assigning different security requirements to different processing elements based on their data sensitivity. Sensitive processing elements are routed to nodes with higher security states, while non-sensitive elements can use any available node. This creates a localized security approach where each node's security posture matches the requirements of the workloads it handles.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent introduces a security state assessment mechanism as an intermediary between the stream processing system and the underlying nodes. This intermediary evaluates the security state of each node and uses this information to make intelligent placement decisions, acting as a mediator that balances productivity and security concerns.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of time

If processing elements are assigned to nodes without security assessment, then assignment speed and system simplicity are improved, but security reliability deteriorates due to unknown vulnerability states of nodes

Engineering Contradiction:
Improveassignment timeVSAvoidsecurity reliability
Core Design Contradiction:
Loss of timeVSReliability

Solution Approach 1:

The patent implements preliminary action by pre-assessing the security state of all available nodes before assigning processing elements. The system maintains up-to-date security state information for each node, so when assignment decisions need to be made, the relevant security information is already available, minimizing assignment time while ensuring security reliability.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If all processing elements are assigned to the most secure nodes, then security reliability is improved, but device complexity and resource utilization worsen due to limited availability of highly secure nodes

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidnode management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent resolves this contradiction by applying local quality - not all processing elements require the same level of security. The system assesses the sensitivity of each processing element and assigns it to nodes with appropriate security states. This allows the system to maintain high security reliability while efficiently utilizing all available nodes, reducing management complexity.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent applies partial action by providing security assessment and differentiated placement only for processing elements that require it, rather than uniformly applying complex security measures to all elements. This selective approach maintains security reliability for sensitive data while simplifying node management for non-sensitive workloads.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12536292B2Secure placement of processing elements
Publication Date: 2026.01.27 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US12536292B2 patent drawing
  • US12536292B2 patent drawing
  • US12536292B2 patent drawing

AI summary

At least one job in a data processing environment is split into two or more processing elements. A determination is made whether at least one processing element of the two or more processing elements include sensitive data. In response to determining that at least one processing element of the two or more processing elements includes sensitive data, a set of secure nodes in the data processing environment which are available for processing are identified. A first subset of optimal nodes in the set of secure nodes for processing the at least one processing element is determined based on a security state of each node in the set of secure nodes. The at least one processing element is assigned to one or more nodes in the first subset of optimal nodes.