Web Service Provision System with Dual Database Routing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional SaaS systems face challenges in balancing cost efficiency with data security, particularly in managing sensitive user data that requires secure storage both within and outside a company's network.

Innovation Solution

A web service provision system is configured with a web application server, client terminal, and database server, where user information and security policies are managed to determine data storage destinations based on user attributes, allowing secure data storage within the company for sensitive information while using SaaS servers outside the company for less sensitive data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of energy

If all personal data is stored on the SaaS server outside the company, then cost efficiency is improved, but data security and control over sensitive information deteriorates

Engineering Contradiction:
Improvecost efficiencyVSAvoiddata security
Core Design Contradiction:
Loss of energyVSReliability

Solution Approach 1:

The patent segments personal data into two categories: general data stored on the SaaS server and sensitive data stored on the company's internal database server. This segmentation allows the system to maintain cost efficiency for non-sensitive data while ensuring security for sensitive information, resolving the contradiction between cost efficiency and data security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different storage policies to different types of data based on their sensitivity. Sensitive data is stored locally on the company's internal server with high security measures, while general data is stored remotely on the SaaS server for cost efficiency. This local quality approach allows simultaneous optimization of both cost efficiency and data security for different data types.

Inventive Principle:
Principle #3Local quality

2Reliability

If sensitive data is stored on the company's internal database server, then data security is improved, but system complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a database connection management unit as an intermediary that automatically manages connections between the web application server and the company's internal database server. This intermediary handles the complexity of dual-server management transparently, allowing sensitive data to be stored securely on the internal server while preventing the system from becoming overly complex for users.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements automatic determination of data storage locations based on sensitivity levels, with the database connection management unit automatically routing queries to the appropriate server. This self-service mechanism eliminates the need for manual configuration and management of complex dual-server architectures, reducing operational complexity while maintaining security.

Inventive Principle:
Principle #25Self-service

3Reliability

If dual database storage is implemented, then data security control is improved, but maintenance burden increases

Engineering Contradiction:
Improvedata security controlVSAvoidmaintenance burden
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The database connection management unit automatically determines which database server to use based on data sensitivity, eliminating the need for manual intervention in data routing. This automated self-service approach maintains security control through dual storage while significantly reducing the maintenance burden by preventing human errors in data management.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements a feedback mechanism where the database connection management unit continuously monitors data access patterns and automatically adjusts connections based on sensitivity levels. This feedback loop ensures proper data routing without manual intervention, reducing maintenance requirements while maintaining security control.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8689278B2Web service provision system, server device, and method
Publication Date: 2014.04.01 RICOH CO LTD
  • US8689278B2 patent drawing
  • US8689278B2 patent drawing
  • US8689278B2 patent drawing

AI summary

A web application server includes a user information management unit that manages user IDs and attributes such that each of the user IDs is associated with corresponding one of the attributes, a security policy management unit that manages security policies such that each of security policies is associated with corresponding one of the attributes, a security policy acquisition unit that acquires one of the security policies based on one of the attributes associated with one of the user IDs, and an HTML file generation unit that generates an HTML file in which a script to acquire personal data of corresponding one of users from an intra-company database server is embedded based on one of the security policies of the corresponding one of the users.