Data Protection via Segmented Operation Accounts
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current data protection methods are unreliable as unauthorized system administrators can easily access sensitive data, compromising security.
Innovation Solution
A data protection method that uses a first operation account to request a decryption key, which is obtained from a data security area through a second operation account with appropriate permissions, ensuring authorized access and storing decrypted data in a partition accessible only to the first operation account, thereby preventing data leakage and enhancing security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data is encrypted and stored in a system, then data security is improved, but unauthorized system administrators can still access the data using system administrator accounts, making security unreliable
Solution Approach 1:
The patent divides the decryption key storage from the encrypted data storage by using separate operation accounts. The first operation account manages encrypted data while the second operation account manages decryption keys. This segmentation ensures that even if one account is compromised, the other remains secure, thereby resolving the issue of unauthorized system administrator access.
Solution Approach 2:
The patent introduces an intermediary mechanism where the decryption key is obtained through a second operation account that has specific permissions to access the data security area. This intermediary account acts as a mediator between the encrypted data and the decryption process, preventing direct access by system administrators and improving security reliability.
2Ease of operation
If a single operation account is used for both data access and decryption key management, then ease of operation is improved, but security is compromised as unauthorized access becomes possible
Solution Approach 1:
The patent segments the operation account into two distinct accounts: the first operation account for data access operations and the second operation account for decryption key management. This segmentation maintains ease of operation for data access while improving security by separating key management privileges, preventing unauthorized access even if data access accounts are compromised.
Solution Approach 2:
The patent applies local quality by assigning different permission levels to different operation accounts. The first operation account has local permission for data access, while the second operation account has local permission for key management in the data security area. This localized permission assignment maintains operational ease while enhancing security through differentiated access control.
Data Source
AI summary
A data protection method includes generating a decryption key acquisition request through a first operation account when encrypted data is received, obtaining the decryption key from a data security area through a second operation account in response that the decryption key acquisition request is an authorized request, using the decryption key to decrypt the encrypted data through the first operation account and obtaining decrypted data, mounting a data partition, and storing the decrypted data in the data partition through the first operation account.


