Centralized Server Segmentation for Multi-Organization Data Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional centralized servers treat entire internal networks as a single entity, failing to address the distinct needs of different departments within an enterprise and compromising data security by making all data accessible to all departments.

Innovation Solution

A centralized server segregates data and resources by creating multiple organizations, allowing each to manage its own data and resources independently, with trusted relationships enabling secure sharing of resources between specific organizations while maintaining access restrictions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a centralized server treats the entire internal network as a single entity, then management simplicity is improved, but data security deteriorates because all data becomes accessible to all departments

Engineering Contradiction:
Improvemanagement simplicityVSAvoiddata security
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent divides the single centralized server into multiple virtual servers, each dedicated to a specific department. This segmentation allows independent data management and access control for each department while maintaining the benefits of centralized infrastructure. Each virtual server can be managed separately, preventing other departments from accessing their data, thus resolving the security issue while keeping overall management simple.

Inventive Principle:
Principle #1Segmentation

2Device complexity

If a centralized server manages all departments uniformly, then system simplicity is improved, but adaptability deteriorates because distinct departmental needs cannot be addressed

Engineering Contradiction:
Improvesystem simplicityVSAvoiddepartmental customization
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The system segments the centralized server into separate virtual servers for each department, allowing each department to have customized management policies, applications, and access rights tailored to their specific needs. This maintains overall system simplicity through virtualization while enabling high adaptability at the departmental level.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Each virtual server is configured with local quality characteristics specific to its department, such as different user permissions, data storage policies, and application configurations. This allows each department to have optimized settings for their unique requirements while all departments share the same physical infrastructure.

Inventive Principle:
Principle #3Local quality

3Ease of operation

If all data is made accessible to all departments, then ease of data access is improved, but data security deteriorates

Engineering Contradiction:
Improvedata access easeVSAvoiddata security
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements segmentation by creating separate virtual servers for each department, with each virtual server containing only the data and resources needed for that department's operations. This segmentation maintains ease of data access within each department while automatically preventing access to other departments' data, thus resolving the security issue.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The virtualization layer acts as an intermediary between the physical server and departmental access requirements. This intermediary provides a secure interface that allows departments to access their data easily through their dedicated virtual servers while blocking unauthorized access to other departments' data, thus mediating between accessibility and security needs.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9241002B2Trusted relationships in multiple organization support in a networked system
Publication Date: 2016.01.19 RED HAT INC
  • US9241002B2 patent drawing
  • US9241002B2 patent drawing
  • US9241002B2 patent drawing

AI summary

Some embodiments of supporting trusted relationships between multiple organizations in a networked system have been presented. In one embodiment, a centralized server manages a networked system, which includes the centralized server and a set of computing machines coupled to each other within an internal network of a customer. The centralized server may segregate data and encapsulating resources within the networked system by a set of organizations created by the customer. Furthermore, a trusted relationship defined by a system administrator of the centralized server may be applied to a first one and a second one of the set of organizations.