IP Library Granted Patent US 12,287,896
Granted Patent B2
US 12,287,896 · App. 18/639,267 · Granted Apr 29, 2025

System and method for implementing data sovereignty safeguards in a distributed services network architecture

Inventors: Richard D. Shriver (Tinton Falls, NJ); Edward T. Pieluc, Jr. (Howell, NJ); Daniel J. McDonald (Whitehouse Station, NJ); Hugh Beverly Appling (Hickory, NC); David Alan Hammaker (Oakland Park, FL); Zheng Sun (Greenacres, FL)
Assignee: OPEN TEXT HOLDINGS, INC.
G06F21/6218H04L63/20H04L67/1095H04L67/306G06F2221/2111H04L63/102H04L67/10H04W4/021
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,287,896
App. No.
18/639,267
Granted
Apr 29, 2025
Kind
B2
Abstract

Embodiments of systems and methods for implementing data sovereignty safeguards in a distributed services network architecture are disclosed. Embodiments of a distributed services system may have a number of distributed nodes that each implements a set of services. When a user requests a service at a particular node of a distributed services system, the node is configured to determine if that node is not (or is) data sovereign for a region associated with the user. If the node is not data sovereign for the user's region, the user may be directed to a corresponding service at a node of the distributed service system that is data sovereign for the user's region.

Claims (49)

1. A distributed service system, comprising:

a first node comprising one or more computing devices, the first node adapted for providing one or more services and providing a first interface for requesting a first service;

a second node comprising one or more computing devices, the second node adapted for providing one or more services and providing a second interface for requesting the first service;

wherein the first node is adapted for:

receiving a request for the first service, the request received through the first interface provided by the first node;

determining whether data sovereignty enforcement should be implemented with respect to the request;

when it is determined that data sovereignty enforcement should be implemented with respect to the request, determining whether the first service as provided by the first node is data sovereign for the request;

when it is determined that the first service as provided by the first node is not data sovereign for the request:

determining that the second node is data sovereign for the request;

determining a response including second node data; and

sending a communication to the second node or a user associated with the request, wherein the communication includes the determined response.

2. The distributed service system of claim 1 , wherein the first set of computing devices are physical or virtual computing devices.

3. The distributed service system of claim 1 , wherein the first node and second node are in different physical locations.

4. The distributed service system of claim 3 , wherein the determination of whether the first service as provided by the first node is data sovereign for the request is based on a user associated with the request, data associated with the request, or the first service.

5. The distributed service system of claim 4 , wherein the determination whether the first service as provided by the first node is data sovereign for the request is based on a physical location of the first node or a physical location of the user associated with the request.

6. The distributed service system of claim 1 , wherein the second node data includes an identifier associated with the second interface.

7. The distributed service system of claim 1 , wherein the first interface and second interface comprise a same interface associated with a first address and a second address.

8. A non-transitory computer-readable medium storing instructions for:

providing a first node comprising one or more computing devices, the first node adapted for providing one or more services and providing a first interface for requesting a first service;

providing a second node comprising one or more computing devices, the second node adapted for providing one or more services and providing a second interface for requesting the first service;

receiving a request for the first service, the request received through the first interface provided by the first node;

determining whether data sovereignty enforcement should be implemented with respect to the request;

when it is determined that data sovereignty enforcement should be implemented with respect to the request, determining whether the first service as provided by the first node is data sovereign for the request;

when it is determined that the first service as provided by the first node is not data sovereign for the request:

determining that the second node is data sovereign for the request;

determining a response including second node data; and

sending a communication to the second node or a user associated with the request, wherein the communication includes the determined response.

9. The non-transitory computer-readable medium of claim 8 , wherein the first set of computing devices are physical or virtual computing devices.

10. The non-transitory computer-readable medium of claim 8 , wherein the first node and second node are in different physical locations.

11. The non-transitory computer-readable medium of claim 10 , wherein the determination of whether the first service as provided by the first node is data sovereign for the request is based on a user associated with the request, data associated with the request, or the first service.

12. The non-transitory computer-readable medium of claim 11 , wherein the determination whether the first service as provided by the first node is data sovereign for the request is based on a physical location of the first node or a physical location of the user associated with the request.

13. The non-transitory computer-readable medium of claim 8 , wherein the second node data includes an identifier associated with the second interface.

14. The non-transitory computer-readable medium of claim 8 , wherein the first interface and second interface comprise a same interface associated with a first address and a second address.

15. A method, comprising:

providing a first node comprising one or more computing devices, the first node adapted for providing one or more services and providing a first interface for requesting a first service;

providing a second node comprising one or more computing devices, the second node adapted for providing one or more services and providing a second interface for requesting the first service;

receiving a request for the first service, the request received through the first interface provided by the first node;

determining whether data sovereignty enforcement should be implemented with respect to the request;

when it is determined that data sovereignty enforcement should be implemented with respect to the request, determining whether the first service as provided by the first node is data sovereign for the request;

when it is determined that the first service as provided by the first node is not data sovereign for the request:

determining that the second node is data sovereign for the request;

determining a response including second node data; and

sending a communication to the second node or a user associated with the request, wherein the communication includes the determined response.

16. The method of claim 15 , wherein the first set of computing devices are physical or virtual computing devices.

17. The method of claim 15 , wherein the first node and second node are in different physical locations.

18. The method of claim 17 , wherein the determination of whether the first service as provided by the first node is data sovereign for the request is based on a user associated with the request, data associated with the request, or the first service.

19. The method of claim 18 , wherein the determination whether the first service as provided by the first node is data sovereign for the request is based on a physical location of the first node or a physical location of the user associated with the request.

20. The method of claim 15 , wherein the second node data includes an identifier associated with the second interface.

21. The method of claim 15 , wherein the first interface and second interface comprise a same interface associated with a first address and a second address.

Assignments (3)
MERGER Recorded May 18, 2026
From: OPEN TEXT HOLDINGS, INC.
To: OPEN TEXT INC.
Reel/Frame 074679/0083 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 24, 2024
From: SHRIVER, RICHARD D.; PIELUC, EDWARD T., JR.; MCDONALD, DANIEL J.; APPLING, HUGH BEVERLY; HAMMAKER, DAVID ALAN; SUN, ZHENG
To: XPEDITE SYSTEMS, LLC
Reel/Frame 067212/0741 →
MERGER Recorded Apr 24, 2024
From: XPEDITE SYSTEMS, LLC
To: OPEN TEXT HOLDINGS, INC.
Reel/Frame 067212/0751 →
Continuity (6)
Continuation 18310457 · May 1, 2023
Continuation 17850613 · Jun 27, 2022
Continuation 16997568 · Aug 19, 2020
Continuation 15956045 · Apr 18, 2018
Provisional Application 62486757 · Apr 18, 2017
Related Publication 20240265127A1 · Aug 8, 2024
References Cited (6)
US 20130346522A1 · Lennstrom · 2013 [cited by examiner]
US 20150281453A1 · Maturana · 2015 [cited by examiner]
US 20150356433A1 · Sanchez · 2015 [cited by examiner]
US 20160124987A1 · Plumb · 2016 [cited by examiner]
US 20160125195A1 · Plumb · 2016 [cited by examiner]
US 20170099181A1 · Hawking · 2017 [cited by examiner]