Centralized Server Segmentation for Multi-Organization Data Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional centralized servers treat entire internal networks as a single entity, failing to address the distinct needs of different departments within an enterprise and compromising data security by making all data accessible to all departments.
Innovation Solution
A centralized server segregates data and resources by creating multiple organizations, allowing each to manage its own data and resources independently, with trusted relationships enabling secure sharing of resources between specific organizations while maintaining access restrictions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a centralized server treats the entire internal network as a single entity, then management simplicity is improved, but data security deteriorates because all data becomes accessible to all departments
Solution Approach 1:
The patent divides the single centralized server into multiple virtual servers, each dedicated to a specific department. This segmentation allows independent data management and access control for each department while maintaining the benefits of centralized infrastructure. Each virtual server can be managed separately, preventing other departments from accessing their data, thus resolving the security issue while keeping overall management simple.
2Device complexity
If a centralized server manages all departments uniformly, then system simplicity is improved, but adaptability deteriorates because distinct departmental needs cannot be addressed
Solution Approach 1:
The system segments the centralized server into separate virtual servers for each department, allowing each department to have customized management policies, applications, and access rights tailored to their specific needs. This maintains overall system simplicity through virtualization while enabling high adaptability at the departmental level.
Solution Approach 2:
Each virtual server is configured with local quality characteristics specific to its department, such as different user permissions, data storage policies, and application configurations. This allows each department to have optimized settings for their unique requirements while all departments share the same physical infrastructure.
3Ease of operation
If all data is made accessible to all departments, then ease of data access is improved, but data security deteriorates
Solution Approach 1:
The patent implements segmentation by creating separate virtual servers for each department, with each virtual server containing only the data and resources needed for that department's operations. This segmentation maintains ease of data access within each department while automatically preventing access to other departments' data, thus resolving the security issue.
Solution Approach 2:
The virtualization layer acts as an intermediary between the physical server and departmental access requirements. This intermediary provides a secure interface that allows departments to access their data easily through their dedicated virtual servers while blocking unauthorized access to other departments' data, thus mediating between accessibility and security needs.
Data Source
AI summary
Some embodiments of supporting trusted relationships between multiple organizations in a networked system have been presented. In one embodiment, a centralized server manages a networked system, which includes the centralized server and a set of computing machines coupled to each other within an internal network of a customer. The centralized server may segregate data and encapsulating resources within the networked system by a set of organizations created by the customer. Furthermore, a trusted relationship defined by a system administrator of the centralized server may be applied to a first one and a second one of the set of organizations.


