Security Metadata Synchronization for Data Consistency

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional computing data models are platform-centric, leading to challenges in maintaining data consistency and security across multiple devices, with traditional security systems failing to coordinate security processing effectively in information-centric data models, resulting in redundant and uncoordinated security operations.

Innovation Solution

A system and method for creating and synchronizing security metadata within a synchronized-data network, which includes identifying data objects, determining their trustworthiness, and generating security metadata, using a publish/subscribe protocol to synchronize data and security metadata across devices, while preventing redundant security operations and offloading resource-intensive tasks to more capable devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional platform-centric security systems are used to synchronize data across multiple devices, then data consistency can be maintained, but redundant and uncoordinated security operations occur

Engineering Contradiction:
Improvedata consistencyVSAvoidsecurity operation efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments security processing into two distinct components: security metadata (trustworthiness information) and data objects. Security metadata is synchronized independently from data objects, allowing receiving devices to make security decisions without performing complete security scans on each data object. This segmentation eliminates redundant security operations while maintaining data consistency across devices.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary security assessment by generating security metadata before data object synchronization. The security metadata contains pre-evaluated trustworthiness information that is synchronized alongside data objects. When devices receive data objects, they can immediately use the pre-synchronized security metadata to determine whether security operations are needed, avoiding redundant processing and improving security operation efficiency.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If security operations are performed on every data object at every device, then security trustworthiness can be ensured, but resource consumption increases

Engineering Contradiction:
Improvesecurity trustworthinessVSAvoiddevice resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent introduces security metadata as an intermediary that carries trustworthiness information between devices. Instead of performing resource-intensive security operations at every device, the security metadata acts as a mediator that provides pre-evaluated security information. Receiving devices can use this intermediary information to make security decisions without consuming significant local resources, thereby ensuring security trustworthiness while reducing device resource consumption.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates and synchronizes security metadata as a separate copy that travels with data objects. This security metadata copy contains the results of security evaluations performed by the originating device or a trusted authority. Receiving devices can use this copied security information instead of performing duplicate security operations, significantly reducing resource consumption while maintaining security trustworthiness across the distributed system.

Inventive Principle:
Principle #26Copying

3Speed

If data objects are synchronized without security metadata, then synchronization speed is fast, but security coordination between devices is lost

Engineering Contradiction:
Improvesynchronization speedVSAvoidsecurity coordination
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent merges data object synchronization and security metadata synchronization into a unified process. Both data objects and their associated security metadata are synchronized together through the same data synchronization mechanism. This merging ensures that security coordination information travels with data objects, maintaining security reliability while using the existing efficient synchronization infrastructure to preserve synchronization speed.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS8756656B1Systems and methods for creating and synchronizing security metadata within synchronized-data networks
Publication Date: 2014.06.17 COHESITY INC
  • US8756656B1 patent drawing
  • US8756656B1 patent drawing
  • US8756656B1 patent drawing

AI summary

A computer-implemented method for creating and synchronizing security metadata for data objects within a synchronized-data network is disclosed. This method may comprise: 1) identifying a data object, 2) determining the trustworthiness of the data object, 3) generating security metadata for the data object that identifies the trustworthiness of the data object, and 4) synchronizing the security metadata within the synchronized-data network. The method may also comprise identifying a need to perform a security operation on the data object to determine the trustworthiness of the data object and then offloading or load balancing the security operation within the synchronized-data network. Corresponding systems and computer-readable media are also disclosed.