Compartment-Based Data Security Labels

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In the energy industry, data security becomes complex when data needs to be shared among numerous users across enterprise-wide or global resources, as existing solutions struggle to manage access rights and security effectively in multi-user systems.

Innovation Solution

A compartment-based security scheme is implemented, where users create and manage their own security labels for data objects, allowing them to define access rights and levels, and these labels are used to determine access permissions for other users, enabling fine-grained control while maintaining simplicity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If data is shared among numerous users across enterprise-wide or global resources, then data accessibility and collaboration are improved, but security management complexity increases

Engineering Contradiction:
Improvedata accessibilityVSAvoidsecurity management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments security management into user-defined compartments, where each user creates their own security labels and compartments for different data objects. This divides the monolithic security management task into smaller, manageable units that users can control independently, reducing overall system complexity while maintaining broad data accessibility.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Users autonomously manage their own data security by creating compartments, assigning security labels, and controlling access permissions without requiring centralized security administration. This self-service approach eliminates the need for complex centralized security management infrastructure while enabling widespread data sharing.

Inventive Principle:
Principle #25Self-service

2Ease of operation

If traditional security models are used in multi-user systems, then implementation is straightforward, but fine-grained access control is lost

Engineering Contradiction:
Improveimplementation simplicityVSAvoidaccess control granularity
Core Design Contradiction:
Ease of operationVSManufacturing precision

Solution Approach 1:

The patent applies different security labels and compartments to different data objects based on their specific access requirements. Each data object can have its own customized security policy defined by the user, enabling fine-grained access control where different levels of granularity are applied locally to different objects rather than uniformly across the system.

Inventive Principle:
Principle #3Local quality

3Reliability

If centralized security management is implemented, then consistent security policies are maintained, but system scalability is limited

Engineering Contradiction:
Improvesecurity policy consistencyVSAvoidsystem scalability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal compartment-based security framework that works across single-user and multi-user contexts. The same compartment and security label mechanisms that provide fine-grained control in multi-user systems also function effectively in single-user scenarios, allowing the system to scale from individual to enterprise-wide deployment without requiring different security models.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11030334B2Compartment-based data security
Publication Date: 2021.06.08 BAKER HUGHES CO
  • US11030334B2 patent drawing
  • US11030334B2 patent drawing
  • US11030334B2 patent drawing

AI summary

An embodiment of a method for securing stored data includes assigning a first user security label to a first user. The method further includes adding an object compartment created by the first user to the first user security label assigned to the first user. The method further includes assigning the object compartment to an object created by the first user by creating the object compartment in an object security label. The method further includes enabling a second user to access to the object created by the first user by assigning the object compartment assigned to the object to a second user security label of a second user. The method further includes determining, by a processing device, whether to permit the second user to access to the object based at least in part on the object security label and the second user security label.