Cloud Data Access Through Rights Server Policy Mediation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cloud computing systems lack effective mechanisms for secure access control and key management, allowing unauthorized access and misuse of sensitive data by system administrators and external attackers, particularly in document and database applications.
Innovation Solution
Implement a rights application that communicates with a rights server to manage access control and encryption keys, ensuring that access requests are checked against a rights policy, allowing fine-grained control over user and server permissions, and logging access operations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If data is stored in cloud computing systems, then accessibility and flexibility are improved, but security and control over the data deteriorate
Solution Approach 1:
The patent introduces a rights server as an intermediary component that mediates between data owners and cloud service providers. The rights server evaluates access requests against defined rights policies and issues rights tokens to authorized clients, enabling fine-grained access control without requiring direct trust in the cloud provider's security mechanisms.
Solution Approach 2:
The access control system is segmented into separate functional components: a rights server for policy evaluation, a rights token for authorization, and a rights application for enforcement. This segmentation allows the security function to be distributed and independent from the cloud storage infrastructure, maintaining control over data access while preserving cloud accessibility benefits.
2Reliability
If encryption is implemented for data protection, then security is improved, but ease of operation and data processing capability deteriorate
Solution Approach 1:
The system dynamically manages encryption through rights tokens that are issued and revoked based on current access policies. The encryption state of data changes dynamically as rights are granted or removed, allowing secure data processing when authorized while maintaining operational flexibility through automated policy enforcement without manual intervention.
Data Source
AI summary
Digital rights management is extended such that control over the access to data stored in a cloud remains with the originator of the data. The access information is coordinated between a rights application in the cloud and a rights server outside the cloud. A rights policy is used for fine-grained regulation of the access for users (user groups), computers (client, server) and validity periods. The access limits actions that can be performed with the data, such as a server application being provided with access to index said data without being able to access the complete contents of the data in the process. The access extension may be used for any type of distributed data processing in which the data are intended to be protected against unauthorized access operations.
