Data Store File Location Attribute for Secure Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data storage systems lack a secure and trustworthy method to track and manage the geographical location of data elements, leading to potential authenticity issues and inadequate access control.
Innovation Solution
Incorporating a location attribute stored with the data elements, accessible only by a single trusted entity like the operating system, which is updated when the data is moved or replicated, and utilizing a metadata service to enforce location-based access control policies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If location data is stored with data elements and made accessible to multiple entities, then location information is more readily available to users and applications, but the authenticity and trustworthiness of the location data cannot be ensured
Solution Approach 1:
The patent introduces a metadata service as an intermediary between the location data storage and users/applications. This service acts as a trusted mediator that verifies and manages access to location information, allowing broad accessibility while maintaining authenticity through centralized control and verification mechanisms.
2Adaptability or versatility
If location attributes are writable by multiple entities, then location information can be updated by various applications, but the trustworthiness of the location data is compromised
Solution Approach 1:
The patent applies different access rights to different entities regarding location attributes. The operating system has exclusive write access to ensure authenticity, while other entities have read-only access. This differentiated access control allows the system to maintain trustworthiness for critical operations while still providing broad read accessibility.
3Reliability
If location-based access control policies are enforced, then security is improved, but system complexity increases due to policy management requirements
Solution Approach 1:
The metadata service performs multiple functions including location information management, access control policy enforcement, and verification. By consolidating these functions in a single service, the system achieves improved security without proportionally increasing complexity, as the same infrastructure serves multiple purposes.
Data Source
AI summary
A data store including a file location attribute is described. In an embodiment, the location attribute for a data element, such as a file or database record, is stored with the bytes of data and records the geographic location of the data element. Writing to this attribute is limited to a single trusted entity, such as an operating system, to ensure that the location data can be trusted and when a data element is moved or replicated, the attribute is updated to reflect the new location of the data element. This location data is made available to users and applications by a metadata service which tracks the locations of data elements and responds to requests from users. Access control policies can been defined in terms of location and stored at the metadata service and the metadata service can then enforce these policies when responding to requests.


