Cloud Data Access Through Rights Server Policy Mediation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cloud computing systems lack effective mechanisms for secure access control and key management, allowing unauthorized access and misuse of sensitive data by system administrators and external attackers, particularly in document and database applications.

Innovation Solution

Implement a rights application that communicates with a rights server to manage access control and encryption keys, ensuring that access requests are checked against a rights policy, allowing fine-grained control over user and server permissions, and logging access operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If data is stored in cloud computing systems, then accessibility and flexibility are improved, but security and control over the data deteriorate

Engineering Contradiction:
ImproveaccessibilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a rights server as an intermediary component that mediates between data owners and cloud service providers. The rights server evaluates access requests against defined rights policies and issues rights tokens to authorized clients, enabling fine-grained access control without requiring direct trust in the cloud provider's security mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The access control system is segmented into separate functional components: a rights server for policy evaluation, a rights token for authorization, and a rights application for enforcement. This segmentation allows the security function to be distributed and independent from the cloud storage infrastructure, maintaining control over data access while preserving cloud accessibility benefits.

Inventive Principle:
Principle #1Segmentation

2Reliability

If encryption is implemented for data protection, then security is improved, but ease of operation and data processing capability deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoiddata processing
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system dynamically manages encryption through rights tokens that are issued and revoked based on current access policies. The encryption state of data changes dynamically as rights are granted or removed, allowing secure data processing when authorized while maintaining operational flexibility through automated policy enforcement without manual intervention.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12452235B2Access to data stored in a cloud
Publication Date: 2025.10.21 SERVICENOW INC
  • US12452235B2 patent drawing

AI summary

Digital rights management is extended such that control over the access to data stored in a cloud remains with the originator of the data. The access information is coordinated between a rights application in the cloud and a rights server outside the cloud. A rights policy is used for fine-grained regulation of the access for users (user groups), computers (client, server) and validity periods. The access limits actions that can be performed with the data, such as a server application being provided with access to index said data without being able to access the complete contents of the data in the process. The access extension may be used for any type of distributed data processing in which the data are intended to be protected against unauthorized access operations.