Access Control Manager for Multi-Cloud Data Migration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In hybrid multi-cloud environments, traditional access control methods are ineffective, allowing unauthorized access and posing security risks, as data can be automatically migrated without proper access controls, potentially leading to compliance issues and legal penalties.

Innovation Solution

An access control manager is implemented to define and register resource-based policies using metadata, controlling access to files migrated from on-premises to off-premises storage systems, ensuring secure access based on defined labels and filters.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If data is automatically migrated to off-premises storage without access control policies, then migration efficiency is improved, but security and compliance are compromised

Engineering Contradiction:
Improvemigration efficiencyVSAvoidsecurity and compliance
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system defines and registers access control policies on the on-premises storage system before data migration occurs. The access control manager retrieves these policies and applies them to the cloud storage environment in advance, ensuring that security controls are already in place when migration happens, thus maintaining both efficiency and security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The access control manager acts as an intermediary component that bridges the on-premises storage system and the cloud storage environment. It retrieves access control policies from the on-premises system and translates/applies them in the cloud environment, enabling automated migration while maintaining security through policy enforcement.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If traditional access control methods are used in hybrid multi-cloud environments, then simplicity is maintained, but unauthorized access occurs and security risks increase

Engineering Contradiction:
Improveaccess control method simplicityVSAvoidunauthorized access and security risks
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The system creates a universal access control framework that works across hybrid multi-cloud environments. The access control manager retrieves policies from on-premises systems and applies them across different cloud storage environments, providing a multi-functional solution that maintains simplicity while enhancing security through consistent policy enforcement across diverse platforms.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If access control policies are not registered with off-premises storage systems, then migration process is simplified, but compliance issues and legal penalties arise

Engineering Contradiction:
Improvemigration process simplicityVSAvoidcompliance and legal adherence
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The access control manager automatically retrieves access control policies from the on-premises storage system and applies them to the cloud storage environment without requiring manual intervention. This self-service approach maintains operational simplicity while ensuring compliance through automatic policy enforcement.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11968210B2Management of access control in multi-cloud environments
Publication Date: 2024.04.23 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11968210B2 patent drawing
  • US11968210B2 patent drawing
  • US11968210B2 patent drawing

AI summary

A computer-implemented to control access to data on an off-premises storage system. The method includes defining an access policy for a plurality of files in a file system stored in an on-premises storage system. The method further includes registering the access policy with a first off-premises storage system. The method also includes creating a resource-based cloud access policy based on an on-premise access policy. The method includes determining a set of files from the plurality of files to migrate to the off-premises storage. The method also includes obtaining, for the set of files, an access policy as access metadata. The method further includes migrating the set of files and the access metadata to the off-premises storage.