Data Container Access Points for Granular Policy Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data container storage systems are limited to a single point of access, restricting flexibility in access control and granularity, as access policies are applied uniformly across the entire data container, failing to provide tailored permissions and restrictions for different users or entities.
Innovation Solution
Implementing multiple access points for a data container, each with its own policy, allowing for varying levels of access and permissions, enabling customized access control through access point policies that can specify different grants and restrictions, and be associated with specific identifiers or names, thereby providing granular access management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a single access point with uniform access control policy is used for a data container, then the system structure is simple, but the access control flexibility and granularity are limited
Solution Approach 1:
The patent segments the access control mechanism by introducing multiple access points (first access point, second access point, etc.) for a single data container. Each access point has its own distinct access control policy, allowing different users or systems to access the same data container with different permissions and restrictions. This segmentation enables fine-grained access control without requiring multiple data containers.
Solution Approach 2:
The patent applies local quality by allowing each access point to have customized access control policies tailored to specific users, systems, or use cases. For example, the first access point may have a policy allowing full read-write access while the second access point may have a policy allowing only read access. This enables different parts of the access control system to have different properties and restrictions.
2Adaptability or versatility
If multiple access points with different policies are implemented, then access control granularity is improved, but the complexity of access policy management increases
Solution Approach 1:
The patent segments access control policies into separate, independently manageable units associated with each access point. This allows administrators to configure, modify, and manage policies for each access point separately, reducing the complexity of managing a single complex policy that would need to serve multiple access scenarios.
Solution Approach 2:
The patent creates a universal data container structure that can serve multiple access scenarios simultaneously through different access points. Each access point acts as a universal interface that can be configured for different purposes (e.g., public access, private access, administrative access) while maintaining a single underlying data container, thus simplifying management compared to creating separate containers for each access scenario.
3Ease of operation
If a data container-level policy is applied to all accesses, then the policy management is simple, but the ability to provide tailored permissions for different users is limited
Solution Approach 1:
The patent segments the monolithic data container-level policy into multiple access point-specific policies. Each policy is tailored to the specific needs of users or systems accessing through that access point. For example, one access point may have a policy optimized for high-frequency read operations while another may have a policy with stricter security restrictions.
Solution Approach 2:
The patent enables local quality by allowing each access point to have its own customized policy that reflects the specific requirements of that access scenario. This means that policies can be optimized locally for each access point's purpose while maintaining overall system consistency through the shared data container structure.
Data Source
AI summary
Disclosed are system architectures and techniques for multiple access points for a data container. Control plane and data plane APIs are disclosed for generating access points and associating the access points with data containers, as well as for generating access point policies that specify permissions for the access points. More than one access point may be associated with a single data container. A storage service receives requests directed to the access points, and grants or denies the requests based on the permissions specified in the corresponding policies. Various types of use cases for using access policies are contemplated such as default, regional, or network-based (e.g., VPC-based) use-cases or the like. A system may implement layers of policies such as identity and access management policies, access point policies and data container policies.


