Secure Database Appliance Multi-Factor Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional user and role-based security models for access control are inadequate for ensuring consistent, flexible, and adaptable security, particularly in environments requiring compliance with multiple governance requirements, as they are difficult to implement, administer, and maintain, and often necessitate custom application code.

Innovation Solution

A secure database appliance that employs a multi-factored approach to access control, using factors such as physical, implementation, and environmental characteristics to determine security levels, and enforces mandatory access controls through a centralized auditing system, minimizing the need for custom code and enhancing ease of implementation and maintenance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If traditional user and role-based security models are used, then implementation is straightforward, but security consistency and adaptability to multiple governance requirements deteriorate

Engineering Contradiction:
Improveease of implementationVSAvoidsecurity consistency
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent segments security control into multiple independent factors (user identity, role, device characteristics, location, time, etc.) that can be individually evaluated and combined. This segmentation allows the system to maintain security consistency across different governance requirements while keeping implementation manageable through modular factor evaluation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a composite security model that combines traditional user/role-based access control with mandatory access control principles and multiple environmental factors. This composite approach integrates disparate security mechanisms into a unified framework that achieves both consistency and adaptability across different governance requirements.

Inventive Principle:
Principle #40Composite materials

2Ease of manufacture

If traditional user and role-based security models are used, then implementation is straightforward, but administration and maintenance complexity increases

Engineering Contradiction:
Improveease of implementationVSAvoidadministration complexity
Core Design Contradiction:
Ease of manufactureVSDevice complexity

Solution Approach 1:

The patent implements self-service mechanisms where the security system automatically evaluates multiple factors and makes access decisions without requiring manual administrative intervention for each decision. The system self-manages the complexity of evaluating user, device, location, and time factors, reducing administrative burden while maintaining security consistency.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent changes the parameters of security control from static user/role assignments to dynamic multi-factor evaluation. By introducing adjustable parameters such as device characteristics, location, and time factors, the system adapts to different governance requirements without increasing administrative complexity, as these parameters are automatically evaluated.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If high levels of security are provided through traditional systems, then security coverage is comprehensive, but ease of operation deteriorates

Engineering Contradiction:
Improvesecurity levelVSAvoidease of administration
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces an intermediary security appliance that sits between users and protected resources, automatically evaluating multiple security factors and making access decisions. This intermediary handles the complexity of comprehensive security evaluation, presenting a simple interface to users while maintaining high security standards through multi-factor assessment.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements feedback mechanisms where the security system continuously monitors and evaluates user actions against multiple factors (device state, location, time, etc.) and dynamically adjusts access decisions. This feedback loop maintains high security coverage while simplifying operation, as the system automatically responds to changing conditions without requiring manual administrative input.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS7814076B2Data vault
Publication Date: 2010.10.12 ORACLE INT CORP
  • US7814076B2 patent drawing
  • US7814076B2 patent drawing
  • US7814076B2 patent drawing

AI summary

A secure database appliance leverages database security in a consistent framework providing consistent, flexible, and adaptable security using mandatory access controls in addition to user and role based security for access control and accountability. A database system comprises a plurality of database objects, each database object having a level of security, a plurality of factors, each factor representing a characteristic of a user of the database system, at least one database session of the user in the database, the database session having a level of security, the user connected to the database with a network domain, each network domain having a level of security, wherein the database system is operable to grant or deny access to the data to a user based on the factors associated with the user, based on the level of security of the data, based on the level of security of the database session, and based on the level of security of the network domain.