Social Network Data Mesh Architecture for Local Storage and Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

User data on social networks remains accessible even after account deletion and is vulnerable to security breaches due to inadequate control over data dissemination and storage.

Innovation Solution

A method where user data is stored locally on a communicating device, with a server managing a mesh network associating unique identifiers with IP addresses, ensuring data accessibility only when the device is connected and online, and using security elements like SIM cards for authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If user data is stored on a centralized server, then data accessibility and management are improved, but data security and user control deteriorate

Engineering Contradiction:
Improvedata accessibilityVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the data storage architecture by dividing data into two categories: static data (stored on server) and dynamic data (stored on user device). This segmentation allows the system to maintain centralized management for static information while giving users direct control over dynamic information, thereby resolving the contradiction between accessibility and security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary mechanism where the server acts as a coordinator rather than a universal storage repository. The server manages the mesh network topology and facilitates connections, but actual dynamic data remains on user devices. This intermediary role allows centralized management benefits while preserving user control and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If user data is stored locally on user devices, then data security and user control are improved, but data accessibility and network management deteriorate

Engineering Contradiction:
Improvedata securityVSAvoiddata accessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements a universal mesh network protocol that enables peer-to-peer data sharing across diverse devices. Each user device can both store and retrieve data, and can act as both client and server. This multi-functionality ensures that data accessibility is maintained through multiple pathways while security is preserved through local storage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent incorporates feedback mechanisms where the centralized server continuously monitors and updates the mesh network topology, device availability, and connection status. This feedback enables the system to dynamically route data requests through available nodes, ensuring accessibility even when individual devices are offline, while maintaining local data control.

Inventive Principle:
Principle #23Feedback

3Device complexity

If centralized server stores all user data, then data management is simplified, but vulnerability to hacker attacks and data breaches increases

Engineering Contradiction:
Improvedata management complexityVSAvoidsecurity breaches
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the data repository into server-managed static data and device-managed dynamic data. This segmentation reduces the attack surface on centralized servers since they no longer hold complete user profiles including sensitive dynamic information. Even if servers are compromised, attackers cannot access dynamically stored personal data.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different security and management qualities to different data types. Static data (usernames, basic profiles) is managed centrally with simplified access control, while dynamic data (personal information, communications) is managed locally with enhanced security. This local quality approach allows simplified management where needed while maintaining high security where critical.

Inventive Principle:
Principle #3Local quality

4Reliability

If mesh network uses unique identifiers for authentication, then security is improved, but device complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service authentication where each user device automatically generates and manages its own unique identifier and cryptographic keys. The authentication process is embedded in the device's operating system or hardware security module, requiring no manual user configuration. This self-service approach provides strong security while keeping the user experience simple.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP2979435B1Method for processing data of a social network user
Publication Date: 2019.08.07 ORANGE SA
  • EP2979435B1 patent drawingFigure 1
  • EP2979435B1 patent drawingFigure 2
  • EP2979435B1 patent drawingFigure 3

AI summary

The invention relates to a method for processing user data to be displayed on an internet page of a social network. The user data is stored in a first communicating device (DIS1) and can be consulted remotely by at least one second communicating device (DIS2). A server (SERV) hosts the social network, which is organised according to a mesh network comprising said communicating devices. The server stores an IP address of the first device on a communication network being used by the first device (DIS1). Upon the request (REQ-DAT) of the second device (DIS2), the method includes the following steps: the server verifies (302) a relationship between said communicating devices; and, if need be, the server transmits (ENV-IP) the IP address of the first device (DIS1) to the second device (DIS2), for direct access to said user data in the first device, using the transmitted IP address.