Centralized Access Control for Cloud Database Resources
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional relational database management systems face challenges in centralized access control, particularly in cloud implementations, where managing permissions across multiple database servers is cumbersome, lacks scalability, and is prone to errors and policy drift.
Innovation Solution
A centralized access control system that manages external access policies externally to database servers, allowing for granular control from subscription level to column level, and enables sharing of permissions across clusters of database servers, eliminating the need for individual permission setup on each server.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional server-specific tools and individual permission management are used for each database server, then access control can be implemented at the server level, but managing permissions across multiple database servers becomes cumbersome and lacks scalability
Solution Approach 1:
The patent introduces a centralized access control system that acts as an intermediary between users and multiple database servers. This central system manages all access policies uniformly, eliminating the need to configure permissions individually on each server. The intermediary handles authentication and authorization requests, translating them into server-specific commands while maintaining centralized control.
Solution Approach 2:
The centralized access control system provides universal permission management that works across different database servers and cloud environments. A single policy definition can be applied universally to multiple servers, and the system adapts to different server types and cloud platforms, providing multi-functional access control without requiring server-specific configurations.
2Reliability
If permissions are managed individually on each database server, then local control is achieved, but policy drift and errors occur across the system
Solution Approach 1:
The centralized access control system implements continuous monitoring and feedback mechanisms that track access policies across all database servers. When policy drift or inconsistencies are detected, the system automatically identifies and corrects deviations, ensuring all servers maintain consistent security policies. The feedback loop provides real-time visibility into policy compliance across the entire system.
Solution Approach 2:
The system enables automatic policy propagation and enforcement without requiring manual intervention on each server. Once a policy is defined centrally, it automatically distributes itself to all relevant database servers and enforces compliance. The system self-corrects policy drift and maintains consistency autonomously, reducing operational burden while ensuring reliability.
3Productivity
If cloud-based database clusters are deployed to improve scalability, then system capacity increases, but managing access control across the cluster becomes more difficult
Solution Approach 1:
The patent extracts access control functionality from individual database servers and consolidates it into a separate centralized management system. This extraction allows database servers to focus on data processing while the centralized system handles all access control logic. The separation enables scalable cluster deployment without proportionally increasing access control management complexity, as the centralized system manages policies uniformly across all servers in the cluster.
Data Source
AI summary
Methods for centralized access control for cloud relational database management system resources are performed by systems and devices. The methods utilize a central policy storage, managed externally to database servers, which stores external policies for access to internal database resources at up to fine granularity. Database servers in the processing system each receive external access policies that correspond to users of the system by push or pull operations from the central policy storage, and store the external access policies in a cache of the database servers for databases. For resource access, access conditions are determined via policy engines of database servers based on an external access policy in the cache that corresponds to a user, responsive to a resource access request from a device of the user specifying the internal resource. Data associated with the resource is provided to the user based on the access condition being met.


