Storage Layer Abstraction for Self-Sovereign Data Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data storage technologies do not allow users to maintain sovereign ownership of their information, as they lack control over where their data is stored, who has access, and how to configure different data hosts based on user needs.

Innovation Solution

A storage layer abstraction for distributed, self-sovereign content sharing is implemented, where a backend server per user manages multiple data hosts, allowing users to choose specific hosts for different data sets and configure storage settings, including security settings, while maintaining control over their data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If existing data storage technologies are used, then data can be stored, but users cannot maintain sovereign ownership or control over where their data is stored, who has access, and how to configure different data hosts

Engineering Contradiction:
Improveuser control over data storage configurationVSAvoidstorage system architecture
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a storage layer abstraction as an intermediary component that sits between users and multiple data hosts. This abstraction layer manages credentials, handles authentication, and coordinates data operations across different hosts, thereby giving users control without requiring them to directly manage the complexity of multiple storage systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the storage system into distinct components: users, storage layer abstraction, and multiple data hosts. This segmentation allows each component to have specific responsibilities, with the storage layer abstraction handling the complexity of managing multiple hosts while users maintain sovereign control over their data placement and access policies.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If users can choose specific hosts for different data sets with customized security settings, then data sovereignty is improved, but the complexity of managing multiple connections and credentials increases

Engineering Contradiction:
Improvehost selection and security configurationVSAvoidconnection management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent merges multiple data host connections and credential management into a single storage layer abstraction. This unified layer consolidates the complexity of managing multiple connections, protocols, and credentials, while still allowing users to specify different hosts and security settings for different data sets through a simplified interface.

Inventive Principle:
Principle #5Merging (Combining)

3Ease of operation

If a backend server per user manages multiple data hosts, then user control and data sovereignty are enhanced, but the system complexity and infrastructure requirements increase

Engineering Contradiction:
Improveuser control over dataVSAvoidbackend infrastructure
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent implements a self-service model where each user's backend server autonomously manages their own data across multiple hosts. The storage layer abstraction automatically handles credential storage, authentication, and data operations without requiring manual intervention, thereby enhancing user control while minimizing the operational burden of the enhanced infrastructure.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20250202884A1Storage layer abstraction for distributed, self-sovereign content sharing
Publication Date: 2025.06.19 SAP SE
  • US20250202884A1 patent drawing
  • US20250202884A1 patent drawing
  • US20250202884A1 patent drawing

AI summary

The present disclosure involves systems, software, and computer implemented methods for data sharing. An example method includes receiving, at an interface of a storage layer abstraction server, a first request for a first user to upload a first file to a first data host. A first unique identifier associated with the first file, the first user, and the first data host is generated. A first connection is established to the first data host using first credentials. The first file is sent, over the connection to the first data host for storage at the first data host for the first user. The first unique identifier is provided in response to the first request. A second request is received, at the interface of the storage layer abstraction server, for the first user to upload a second file to a second data host that is different than the first data host.