Cloud Storage Data Account Segmentation for Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face difficulties in separating data with different ownership rights and accessing specific portions of personal data stored in cloud-based storage services, as these services often cannot distinguish between different types of data or access rights within a user profile.

Innovation Solution

Implementing a system that uses unique account names and encryption keys for each data account within a user profile, allowing for secure separation and controlled access to data based on ownership and access rights, enabling users to manage which data is accessible to additional users.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a cloud-based storage service stores all data in a single user profile without separation, then the service is simple to operate and access, but the service cannot distinguish between data with different ownership rights, leading to unauthorized access

Engineering Contradiction:
Improvedata access controlVSAvoiddata account structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides a user profile into multiple data accounts, where each data account stores a specific type of data (e.g., work-related data, personal data) with distinct access control rules. This segmentation enables the cloud-based storage service to differentiate between data with different ownership rights and apply appropriate access controls to each data account independently, resolving the contradiction between maintaining simple operation and ensuring reliable access control.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If a cloud-based storage service allows unified access to all data in a user profile, then access operations are simple, but users cannot delegate access to specific portions of personal data without delegating access to all data

Engineering Contradiction:
Improvedata access delegationVSAvoidaccess rights management
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

By organizing data into separate data accounts within a user profile, the patent enables users to delegate access to specific data accounts independently. Each data account can have its own access control settings, allowing users to grant access to particular portions of their data (e.g., work-related data) while maintaining restricted access to other portions (e.g., personal data), thus resolving the contradiction between ease of operation and reliability of access rights management.

Inventive Principle:
Principle #1Segmentation

3Reliability

If an organization accesses all data in an employee's user profile via cloud-based storage service, then data access is comprehensive, but the organization accesses personal data without ownership rights

Engineering Contradiction:
Improveownership rights protectionVSAvoidaccess control mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the employee's user profile into distinct data accounts, with one data account for work-related data and another for personal data. The organization is granted access rights only to the work-related data account, while the personal data account remains inaccessible to the organization. This segmentation approach protects ownership rights by ensuring the organization cannot access personal data without proper authorization, while avoiding the need for complex access control mechanisms through clear structural separation.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8904503B2Systems and methods for providing access to data accounts within user profiles via cloud-based storage services
Publication Date: 2014.12.02 GEN DIGITAL INC
  • US8904503B2 patent drawing
  • US8904503B2 patent drawing
  • US8904503B2 patent drawing

AI summary

A computer-implemented method for providing access to data accounts within user profiles via cloud-based storage services may include (1) identifying a user profile associated with a user of a cloud-based storage service, (2) identifying a plurality of data accounts within the user profile associated with the user of the cloud-based storage service, (3) detecting a request from a client-based application associated with the user of the cloud-based storage service to access at least a portion of data stored in a data account within the user profile, (4) locating a unique account name that identifies the data account in the request, and then (5) satisfying the request from the client-based application associated with the user to access the portion of data stored in the data account via the cloud-based storage service. Various other methods, systems, and computer-readable media are also disclosed.