Cross-Account Data Access Authorization for Secure Cloud Storage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network storage solutions allow multiple devices to access shared storage devices, leading to unauthorized data access and security issues, such as data deletion or copying without permission, which compromises data security.

Innovation Solution

Implement a data access method that involves generating access authorization requests and verification information through negotiation between devices and storage devices, using user-specific authorization to ensure secure access and sharing between different user accounts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If network storage solution allows multiple terminal devices to access the storage device, then data sharing capability is improved, but data security deteriorates due to unauthorized access and tampering

Engineering Contradiction:
Improvedata sharing capabilityVSAvoiddata security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the authorization process into multiple independent components: authorization information stored on the terminal device, verification information generated during access requests, and permission verification requests sent to the storage device. This segmentation allows each component to perform its specific function while maintaining overall security, resolving the contradiction between enabling multiple devices to access data and preventing unauthorized access.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary authorization where the terminal device must first obtain authorization information from the user before attempting to access stored data. The authorization verification information is generated in advance and stored on the terminal device, allowing the storage device to verify permissions before granting access. This preliminary action prevents unauthorized access while maintaining the ability for multiple devices to share data legally.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If access authorization process is implemented with multiple verification steps, then data security is improved, but device complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidaccess control mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary verification mechanism where the storage device sends permission verification requests to the terminal device, which then uses stored authorization information and verification information to respond. This intermediary approach distributes the complexity across multiple components rather than concentrating it in a single complex system, making the security mechanism more manageable while maintaining high security standards.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12475244B2Data access method and apparatus, and electronic device
Publication Date: 2025.11.18 HUAWEI TECH CO LTD
  • US12475244B2 patent drawing
  • US12475244B2 patent drawing
  • US12475244B2 patent drawing

AI summary

In an access method, when a first account logged in to a current device triggers a data access operation on user data, the current device generates a first access request corresponding to the data access operation. The current device sends the first access request to a storage device, and receives a permission verification request from the storage device. The current device generates an access authorization request based on the permission verification request, and sends the access authorization request to a first device. Thereafter, the current device receives authorization verification information from the first device. The current device then generates, based on the authorization verification information, a second access request corresponding to the data access operation, and sends the second access request to the storage device.