Content-Based Dataset Access Control for Distributed Storage
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current data management systems struggle to efficiently manage and control large-scale datasets across multiple locations and environments, particularly in terms of data lifecycle management and access control, as they rely on location-based hierarchies that become inadequate with the exponential growth of data and increasing complexity.
Innovation Solution
Implementing a dataset management system that uses metadata to create logical datasets spanning multiple storage devices and environments, applying content-based protection policies and access controls through datasets, which automatically track data location changes and enforce Role-Based Access Control (RBAC) and Access Control Lists (ACL) based on data types rather than locations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If hierarchical directory structures are used to control access in filesystems, then access control can be implemented for organized data, but the control mechanism becomes insufficient when dealing with huge amounts of files and data across multiple locations
Solution Approach 1:
The patent introduces content-based dimensions (data type, creator, retention period) alongside traditional location-based hierarchy to create a multi-dimensional access control framework. This allows ACL and RBAC rules to be applied based on data characteristics rather than just directory paths, enabling effective control across distributed data without increasing hierarchical complexity
Solution Approach 2:
The patent introduces datasets as an intermediary layer between raw files and access control mechanisms. Datasets group files by content characteristics and serve as the target for ACL/RBAC policies, decoupling the access control logic from the physical file hierarchy and enabling scalable management of large-scale distributed data
2Reliability
If lifecycle rules are made data-specific to manage large datasets, then data protection compliance is improved, but the complexity of creating and managing these rules increases significantly
Solution Approach 1:
The system enables automated discovery and application of lifecycle rules based on dataset content characteristics. Instead of manually creating data-specific rules, the system automatically identifies data patterns and applies appropriate retention, backup, and access policies, reducing the burden on administrators while maintaining compliance
Solution Approach 2:
The patent transforms lifecycle management from static location-based rules to dynamic content-based parameters. Rules are defined in terms of data characteristics (type, creator, retention period) rather than file paths, allowing the same rule to automatically apply to matching data regardless of location and simplifying rule creation and maintenance
3Ease of operation
If traditional location-based access control is used, then simple filesystem organization is maintained, but the system cannot efficiently manage access to data across multiple locations and environments
Solution Approach 1:
The patent creates datasets that can span multiple filesystems, storage devices, and environments while presenting a unified access control interface. A single dataset can contain files from diverse locations, and a single ACL/RBAC policy applied to the dataset automatically enforces access control across all underlying locations, providing universal management capability
Data Source
AI summary
Providing content based data access protection for data stored in a system by creating a dataset by grouping metadata for data objects that are grouped together by one or more filters. The dataset can span multiple storage devices of different types to define a single data access protection unit for the corresponding content data. A user query generates the one or more filters, and an access rule is defined that allows or denies access to the dataset by users or processes as the single unit based on data content rather than location. The access rule can comprise at least one of an Access Control List (ACL) rule or a Role-Based Access Control (RBAC) rule, where the ACL lists permissions associated with certain data elements that grant access to specific users or processes, and the RBAC rules allow or deny access on the basis of role-permissions within the system.


