Specialized Access Key for Secure Backup System Troubleshooting

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data storage systems face challenges in securely authorizing service-level access to backup systems, as existing security measures may not adequately prevent unauthorized access or irreversible damage, especially when troubleshooting is required.

Innovation Solution

A specialized access key is implemented, embedded with a system identifier, timestamp, and digital signature, which is verifiable by the backup system, ensuring secure and controlled access by leveraging digital signatures and asymmetric encryption technologies to prevent reverse engineering and unauthorized use.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of repair

If service-level access is granted to allow troubleshooting operations, then system diagnostic capability is improved, but security risk increases due to potential unauthorized access or irreversible damage

Engineering Contradiction:
Improvetroubleshooting capabilityVSAvoidsecurity risk
Core Design Contradiction:
Ease of repairVSObject-affected harmful factors

Solution Approach 1:

The access key includes a timestamp parameter that limits its validity to a specific time window, and a system identifier that restricts its applicability to a particular backup system. These parameter changes ensure that even if the key is compromised, the window for potential damage is minimized and constrained to specific systems.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The access key is designed as a single-use, short-lived credential that becomes invalid after verification or expiration. This disposable nature means that if compromised, the security breach is temporary and limited, allowing troubleshooting access while minimizing long-term security risks.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

2Loss of time

If access key validity is extended to allow more troubleshooting time, then diagnostic effectiveness is improved, but exposure to security risks increases

Engineering Contradiction:
Improvetroubleshooting timeVSAvoidsecurity exposure window
Core Design Contradiction:
Loss of timeVSObject-affected harmful factors

Solution Approach 1:

The timestamp parameter in the access key defines a precise validity window that balances troubleshooting needs with security concerns. The key remains active long enough to complete necessary diagnostics but automatically expires to limit security exposure.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If the access key contains detailed system information for verification, then authentication accuracy is improved, but the key becomes more vulnerable to reverse engineering

Engineering Contradiction:
Improveauthentication accuracyVSAvoidreverse engineering vulnerability
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The digital signature acts as an intermediary that verifies system identity without exposing sensitive information. The backup system can authenticate the access key's validity and the system identifier it contains without the attacker being able to reverse-engineer how verification works or extract additional system secrets.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Adaptability or versatility

If the access key is made universally applicable across multiple backup systems, then operational flexibility is improved, but security control is reduced

Engineering Contradiction:
Improveaccess flexibilityVSAvoidunauthorized system access
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system identifier parameter in the access key restricts its applicability to a specific backup system. This ensures that even if the key is compromised, an attacker cannot use it to access other backup systems, maintaining security control while still providing flexible access to the authorized system.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11601285B2Securely authorizing service level access to a backup system using a specialized access key
Publication Date: 2023.03.07 EMC IP HLDG CO LLC
  • US11601285B2 patent drawing
  • US11601285B2 patent drawing
  • US11601285B2 patent drawing

AI summary

Described is a system (and method) for securely authorizing service level access to a backup system using an access key. The service level access (or access via a service account) may provide a user with an enhanced set of privileges to perform troubleshooting operations on the backup system. Such privileges may be unlocked by allowing a user to perform operations using an unrestricted interface of the backup system such as an operating system shell. To authorize such access, the system may provide a limited (or specialized) access key. The access key may be narrowly tailored to only provide access to a particular backup system and only remain viable for a limited duration. Accordingly, the access key may be configured to embed a system identifier, a timestamp, and a digital signature, which may be independently verifiable by the backup system before granting service level access.