Archived Object Access Policies With Time-Limited Restore Credentials

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Data stored in primary and remote storage systems are vulnerable to malicious actors who can exploit persistent connections to access, delete, or encrypt data, rendering recovery impossible without compliance with malicious demands.

Innovation Solution

A cloud-based management system implements a multi-layer security architecture that automatically manages access policies for archived objects, requiring a quorum of approvals before generating access policies and providing temporary credentials for authorized restore operations, thereby preventing unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If persistent connections are maintained between primary and remote sites for data access, then data accessibility and operational efficiency are improved, but security vulnerability to malicious access increases

Engineering Contradiction:
Improvedata accessibilityVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary actions by generating time-limited access credentials before any data access occurs. These credentials are automatically created with predetermined expiration times, ensuring that even if malicious actors compromise the system, their access window is strictly limited. The credentials are generated on-demand based on restore requests, preventing unauthorized access while maintaining operational efficiency.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary credentialing system that sits between the persistent connections and the archived data. Instead of allowing direct access through persistent connections, the system mediates all access through time-limited credentials that are automatically generated and revoked. This intermediary layer maintains data accessibility while neutralizing security vulnerabilities from persistent connections.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If access policies are manually managed for archived objects, then security control is improved, but operational complexity and time consumption increase

Engineering Contradiction:
Improvesecurity controlVSAvoidtime consumption
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system implements self-service automation where access credentials are automatically generated, managed, and revoked without human intervention. When a restore request is made, the system automatically creates time-limited credentials, tracks their usage, and revokes them after expiration or upon successful restore. This eliminates manual policy management while maintaining strict security control, significantly reducing time consumption and operational complexity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent dynamically changes the time parameter of access credentials. Instead of static, long-term access policies, the system generates credentials with predetermined expiration times that automatically change. This parameter transformation allows the system to maintain high security control while eliminating the time-consuming manual management of access policies, as the temporal parameter is automatically enforced by the system.

Inventive Principle:
Principle #35Parameter changes

3Productivity

If long-term access credentials are provided for restore operations, then operational efficiency is improved, but risk of data exfiltration and unauthorized access increases

Engineering Contradiction:
Improveoperational efficiencyVSAvoiddata exfiltration risk
Core Design Contradiction:
ProductivityVSObject-generated harmful factors

Solution Approach 1:

The system transitions from static, long-term credentials to dynamic, time-limited credentials. Access credentials are generated with predetermined expiration times and are automatically revoked after use or when the restore operation completes. This dynamic approach maintains operational efficiency by enabling quick restore operations while dramatically reducing data exfiltration risk, as malicious actors have only a narrow time window to exploit credentials before they automatically expire.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent employs disposable, short-living access credentials instead of permanent, reusable ones. Each credential is generated for a specific restore operation with a predetermined short lifespan. Once the restore completes or the time expires, the credential becomes invalid and is automatically revoked. This approach maintains productivity by enabling efficient restore operations while eliminating data exfiltration risk, as the credentials are designed to be used once and then discarded.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentUS12627674B2Automatically managing access policies for archived objects
Publication Date: 2026.05.12 COHESITY INC
  • US12627674B2 patent drawing
  • US12627674B2 patent drawing
  • US12627674B2 patent drawing

AI summary

An archival storage of data backed up from a repository storage of a primary storage is maintained. Access to data stored in archival storage is limited by one or more access policies based on whether a corresponding data restore has been authorized. A request for specific data stored in the archival storage is received. The one or more access policies are automatically managed based on status and timing of one or more data restore authorizations for the specific data stored in the archival storage.