Data Protector Layer for Sustained Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional data protection techniques fail to maintain access control after data retrieval, leaving protected data vulnerable to unauthorized access.
Innovation Solution
Implementing a data protector layer that secures data by encrypting and applying access policies, ensuring that only authorized clients can access specific content within the protected data, even after retrieval.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional access control techniques are used to verify client permission before data retrieval, then data access security is improved, but data protection is lost after retrieval leaving data vulnerable to unauthorized access
Solution Approach 1:
The patent applies preliminary action by encrypting data before retrieval and establishing access control policies in advance. The data is secured with encryption keys and access permissions are defined before the data leaves storage, ensuring protection is already in place before any potential unauthorized access can occur.
Solution Approach 2:
The patent introduces an intermediary data protection layer that sits between the storage system and clients. This intermediary enforces access control policies and manages encryption keys, acting as a mediator that maintains security even after data retrieval by controlling what clients can do with the protected data.
2Ease of operation
If data is provided to clients in unprotected form after verification, then ease of operation is improved, but data integrity deteriorates
Solution Approach 1:
The patent changes the state of data from unprotected to protected by applying encryption. The data maintains its usability for authorized operations while its security parameters are transformed through encryption, allowing clients to work with data that remains secure rather than requiring unprotected forms.
Solution Approach 2:
The patent implements dynamic access control where permissions and encryption keys are actively managed based on client credentials and policies. Rather than static unprotected access after verification, the system dynamically adjusts what clients can access and do with the data based on their authorized permissions.
3Reliability
If encryption and access policies are applied to sustain protection after retrieval, then data protection is improved, but device complexity increases
Solution Approach 1:
The patent makes the data protection system universal by creating a layered protection mechanism that works across different clients, data types, and access scenarios. The same encryption and policy enforcement mechanisms apply throughout the system, providing sustained protection without requiring separate solutions for each access case.
Solution Approach 2:
The patent segments the data protection function into distinct layers: encryption layer, access control policy layer, and key management layer. This segmentation allows each component to be independently managed and optimized, reducing overall system complexity while maintaining comprehensive protection.
Data Source
AI summary
Among other things, one or more techniques and/or systems are provided for sustained data protection. In particular, a data protector may define a set of access levels associated with content within data using a set of access policies (e.g., a partial access level to inventory data for an inventory server, a full access level to inventory data and billing data for a shopping website server, etc.). The data protector may secure (e.g., encrypt) the data to create protected data, so that clients may be unable to access content of the protected data without obtaining access through the data protector. In this way, the data protector may selectively provide clients with access to content within the protected data according to respective access levels for the different clients (e.g., access to inventory data, but not billing data, may be provided to the inventory server by the data protector).


