Content-Based Dataset Access Control for Distributed Storage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data management systems struggle to efficiently manage and control large-scale datasets across multiple locations and environments, particularly in terms of data lifecycle management and access control, as they rely on location-based hierarchies that become inadequate with the exponential growth of data and increasing complexity.

Innovation Solution

Implementing a dataset management system that uses metadata to create logical datasets spanning multiple storage devices and environments, applying content-based protection policies and access controls through datasets, which automatically track data location changes and enforce Role-Based Access Control (RBAC) and Access Control Lists (ACL) based on data types rather than locations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If hierarchical directory structures are used to control access in filesystems, then access control can be implemented for organized data, but the control mechanism becomes insufficient when dealing with huge amounts of files and data across multiple locations

Engineering Contradiction:
Improveaccess control capabilityVSAvoidcontrol mechanism complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces content-based dimensions (data type, creator, retention period) alongside traditional location-based hierarchy to create a multi-dimensional access control framework. This allows ACL and RBAC rules to be applied based on data characteristics rather than just directory paths, enabling effective control across distributed data without increasing hierarchical complexity

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The patent introduces datasets as an intermediary layer between raw files and access control mechanisms. Datasets group files by content characteristics and serve as the target for ACL/RBAC policies, decoupling the access control logic from the physical file hierarchy and enabling scalable management of large-scale distributed data

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If lifecycle rules are made data-specific to manage large datasets, then data protection compliance is improved, but the complexity of creating and managing these rules increases significantly

Engineering Contradiction:
Improvedata protection complianceVSAvoidrule management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system enables automated discovery and application of lifecycle rules based on dataset content characteristics. Instead of manually creating data-specific rules, the system automatically identifies data patterns and applies appropriate retention, backup, and access policies, reducing the burden on administrators while maintaining compliance

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent transforms lifecycle management from static location-based rules to dynamic content-based parameters. Rules are defined in terms of data characteristics (type, creator, retention period) rather than file paths, allowing the same rule to automatically apply to matching data regardless of location and simplifying rule creation and maintenance

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If traditional location-based access control is used, then simple filesystem organization is maintained, but the system cannot efficiently manage access to data across multiple locations and environments

Engineering Contradiction:
Improvefilesystem organizationVSAvoidmulti-location data management
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent creates datasets that can span multiple filesystems, storage devices, and environments while presenting a unified access control interface. A single dataset can contain files from diverse locations, and a single ACL/RBAC policy applied to the dataset automatically enforces access control across all underlying locations, providing universal management capability

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20240143810A1Access control list (ACL) and role-based access control (RBAC) management using content-based datasets
Publication Date: 2024.05.02 DELL PROD LP
  • US20240143810A1 patent drawing
  • US20240143810A1 patent drawing
  • US20240143810A1 patent drawing

AI summary

Providing content based data access protection for data stored in a system by creating a dataset by grouping metadata for data objects that are grouped together by one or more filters. The dataset can span multiple storage devices of different types to define a single data access protection unit for the corresponding content data. A user query generates the one or more filters, and an access rule is defined that allows or denies access to the dataset by users or processes as the single unit based on data content rather than location. The access rule can comprise at least one of an Access Control List (ACL) rule or a Role-Based Access Control (RBAC) rule, where the ACL lists permissions associated with certain data elements that grant access to specific users or processes, and the RBAC rules allow or deny access on the basis of role-permissions within the system.