Data Store File Location Attribute for Secure Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data storage systems lack a secure and trustworthy method to track and manage the geographical location of data elements, leading to potential authenticity issues and inadequate access control.

Innovation Solution

Incorporating a location attribute stored with the data elements, accessible only by a single trusted entity like the operating system, which is updated when the data is moved or replicated, and utilizing a metadata service to enforce location-based access control policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If location data is stored with data elements and made accessible to multiple entities, then location information is more readily available to users and applications, but the authenticity and trustworthiness of the location data cannot be ensured

Engineering Contradiction:
Improveaccessibility of location informationVSAvoidauthenticity of location data
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a metadata service as an intermediary between the location data storage and users/applications. This service acts as a trusted mediator that verifies and manages access to location information, allowing broad accessibility while maintaining authenticity through centralized control and verification mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If location attributes are writable by multiple entities, then location information can be updated by various applications, but the trustworthiness of the location data is compromised

Engineering Contradiction:
Improveability to update location informationVSAvoidtrustworthiness of location data
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies different access rights to different entities regarding location attributes. The operating system has exclusive write access to ensure authenticity, while other entities have read-only access. This differentiated access control allows the system to maintain trustworthiness for critical operations while still providing broad read accessibility.

Inventive Principle:
Principle #3Local quality

3Reliability

If location-based access control policies are enforced, then security is improved, but system complexity increases due to policy management requirements

Engineering Contradiction:
Improvesecurity of data accessVSAvoidcomplexity of policy management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The metadata service performs multiple functions including location information management, access control policy enforcement, and verification. By consolidating these functions in a single service, the system achieves improved security without proportionally increasing complexity, as the same infrastructure serves multiple purposes.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8656454B2Data store including a file location attribute
Publication Date: 2014.02.18 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8656454B2 patent drawing
  • US8656454B2 patent drawing
  • US8656454B2 patent drawing

AI summary

A data store including a file location attribute is described. In an embodiment, the location attribute for a data element, such as a file or database record, is stored with the bytes of data and records the geographic location of the data element. Writing to this attribute is limited to a single trusted entity, such as an operating system, to ensure that the location data can be trusted and when a data element is moved or replicated, the attribute is updated to reflect the new location of the data element. This location data is made available to users and applications by a metadata service which tracks the locations of data elements and responds to requests from users. Access control policies can been defined in terms of location and stored at the metadata service and the metadata service can then enforce these policies when responding to requests.