Data Protector Layer for Sustained Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional data protection techniques fail to maintain access control after data retrieval, leaving protected data vulnerable to unauthorized access.

Innovation Solution

Implementing a data protector layer that secures data by encrypting and applying access policies, ensuring that only authorized clients can access specific content within the protected data, even after retrieval.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional access control techniques are used to verify client permission before data retrieval, then data access security is improved, but data protection is lost after retrieval leaving data vulnerable to unauthorized access

Engineering Contradiction:
Improvedata access securityVSAvoidunauthorized access after retrieval
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by encrypting data before retrieval and establishing access control policies in advance. The data is secured with encryption keys and access permissions are defined before the data leaves storage, ensuring protection is already in place before any potential unauthorized access can occur.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary data protection layer that sits between the storage system and clients. This intermediary enforces access control policies and manages encryption keys, acting as a mediator that maintains security even after data retrieval by controlling what clients can do with the protected data.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If data is provided to clients in unprotected form after verification, then ease of operation is improved, but data integrity deteriorates

Engineering Contradiction:
Improvedata accessibilityVSAvoiddata integrity
Core Design Contradiction:
Ease of operationVSStability of the object's composition

Solution Approach 1:

The patent changes the state of data from unprotected to protected by applying encryption. The data maintains its usability for authorized operations while its security parameters are transformed through encryption, allowing clients to work with data that remains secure rather than requiring unprotected forms.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent implements dynamic access control where permissions and encryption keys are actively managed based on client credentials and policies. Rather than static unprotected access after verification, the system dynamically adjusts what clients can access and do with the data based on their authorized permissions.

Inventive Principle:
Principle #15Dynamics

3Reliability

If encryption and access policies are applied to sustain protection after retrieval, then data protection is improved, but device complexity increases

Engineering Contradiction:
Improvesustained data protectionVSAvoiddata protection system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent makes the data protection system universal by creating a layered protection mechanism that works across different clients, data types, and access scenarios. The same encryption and policy enforcement mechanisms apply throughout the system, providing sustained protection without requiring separate solutions for each access case.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent segments the data protection function into distinct layers: encryption layer, access control policy layer, and key management layer. This segmentation allows each component to be independently managed and optimized, reducing overall system complexity while maintaining comprehensive protection.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9542536B2Sustained data protection
Publication Date: 2017.01.10 MICROSOFT TECHNOLOGY LICENSING LLC
  • US9542536B2 patent drawing
  • US9542536B2 patent drawing
  • US9542536B2 patent drawing

AI summary

Among other things, one or more techniques and/or systems are provided for sustained data protection. In particular, a data protector may define a set of access levels associated with content within data using a set of access policies (e.g., a partial access level to inventory data for an inventory server, a full access level to inventory data and billing data for a shopping website server, etc.). The data protector may secure (e.g., encrypt) the data to create protected data, so that clients may be unable to access content of the protected data without obtaining access through the data protector. In this way, the data protector may selectively provide clients with access to content within the protected data according to respective access levels for the different clients (e.g., access to inventory data, but not billing data, may be provided to the inventory server by the data protector).