Attribute-Based Access Control for Multi-Tenant Data Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional digital rights management systems fail to effectively verify the hardware and software environments in which data is accessed, particularly in multi-tenant storage systems, requiring trust in third-party providers or local management of cryptographic solutions, which limits data security and flexibility.

Innovation Solution

A method and system that allow data owners to specify access restrictions based on process and machine attributes, using an access control management system to verify that a machine executing a process meets these attributes, enabling secure data access without relying on third-party cryptographic solutions or local management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional digital rights management systems are used to authenticate user identity, then user access control is implemented, but verification of hardware and software environment is not performed

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments access control into multiple independent verification layers: user identity authentication, hardware environment verification, and software process validation. Each layer operates independently through standardized interfaces, allowing comprehensive security without monolithic system complexity

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

An intermediary verification module is introduced between the user authentication system and the data access system. This module independently verifies hardware and software attributes without requiring changes to existing authentication infrastructure, resolving the contradiction by adding verification capability without proportionally increasing overall system complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If data owners trust third-party storage providers, then multi-tenant storage systems can be leveraged, but data security control is reduced

Engineering Contradiction:
Improveease of using multi-tenant storageVSAvoiddata security control
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary verification of hardware and software attributes before data is made accessible to any user or process. By validating the execution environment in advance and enforcing attribute-based access controls, data owners maintain security control while utilizing third-party multi-tenant storage infrastructure

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Data owners implement self-service security control through automated verification of hardware and software attributes. The system automatically validates whether accessing processes meet required attributes without requiring manual intervention or trust in the storage provider, enabling both ease of operation and maintained security control

Inventive Principle:
Principle #25Self-service

3Reliability

If data owners implement local cryptographic solutions, then data security is maintained, but flexibility and cost-effectiveness are reduced

Engineering Contradiction:
Improvedata securityVSAvoidflexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system changes the security verification parameter from trusting specific cryptographic implementations to verifying observable hardware and software attributes. This allows data owners to maintain security through attribute validation rather than relying on specific cryptographic solutions, thereby increasing flexibility and cost-effectiveness while maintaining security

Inventive Principle:
Principle #35Parameter changes

4Reliability

If independent verification of hardware and software is implemented, then data access security is improved, but system complexity increases

Engineering Contradiction:
Improvedata access securityVSAvoidverification system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The verification module is designed with universal interfaces that can validate multiple hardware and software attributes through standardized methods. By creating a multi-functional verification system that handles diverse attribute types through a unified approach, the system improves data access security without proportionally increasing complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20230095504A1Methods and Systems for Restricting Data Access Based on Properties of At Least One of a Process and a Machine Executing the Process
Publication Date: 2023.03.30 VIRTRU CORP
  • US20230095504A1 patent drawing
  • US20230095504A1 patent drawing
  • US20230095504A1 patent drawing

AI summary

A method of restricting data access based on properties of at least one of a process and a machine executing the process includes receiving, by an access control management system, from a first computing device, information associated with an encrypted data object. The method includes requesting, by the access control management system, from a verifier, verification that a second computing device executes a process in accordance with a process attribute identified in the information associated with the encrypted data object. The method includes sending, by the access control management system, to the second computing device, the received information associated with the encrypted data object, responsive to the verification of the process attribute.