Secure Database Appliance Multi-Factor Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional user and role-based security models for access control are inadequate for ensuring consistent, flexible, and adaptable security, particularly in environments requiring compliance with multiple governance requirements, as they are difficult to implement, administer, and maintain, and often necessitate custom application code.
Innovation Solution
A secure database appliance that employs a multi-factored approach to access control, using factors such as physical, implementation, and environmental characteristics to determine security levels, and enforces mandatory access controls through a centralized auditing system, minimizing the need for custom code and enhancing ease of implementation and maintenance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If traditional user and role-based security models are used, then implementation is straightforward, but security consistency and adaptability to multiple governance requirements deteriorate
Solution Approach 1:
The patent segments security control into multiple independent factors (user identity, role, device characteristics, location, time, etc.) that can be individually evaluated and combined. This segmentation allows the system to maintain security consistency across different governance requirements while keeping implementation manageable through modular factor evaluation.
Solution Approach 2:
The patent creates a composite security model that combines traditional user/role-based access control with mandatory access control principles and multiple environmental factors. This composite approach integrates disparate security mechanisms into a unified framework that achieves both consistency and adaptability across different governance requirements.
2Ease of manufacture
If traditional user and role-based security models are used, then implementation is straightforward, but administration and maintenance complexity increases
Solution Approach 1:
The patent implements self-service mechanisms where the security system automatically evaluates multiple factors and makes access decisions without requiring manual administrative intervention for each decision. The system self-manages the complexity of evaluating user, device, location, and time factors, reducing administrative burden while maintaining security consistency.
Solution Approach 2:
The patent changes the parameters of security control from static user/role assignments to dynamic multi-factor evaluation. By introducing adjustable parameters such as device characteristics, location, and time factors, the system adapts to different governance requirements without increasing administrative complexity, as these parameters are automatically evaluated.
3Reliability
If high levels of security are provided through traditional systems, then security coverage is comprehensive, but ease of operation deteriorates
Solution Approach 1:
The patent introduces an intermediary security appliance that sits between users and protected resources, automatically evaluating multiple security factors and making access decisions. This intermediary handles the complexity of comprehensive security evaluation, presenting a simple interface to users while maintaining high security standards through multi-factor assessment.
Solution Approach 2:
The patent implements feedback mechanisms where the security system continuously monitors and evaluates user actions against multiple factors (device state, location, time, etc.) and dynamically adjusts access decisions. This feedback loop maintains high security coverage while simplifying operation, as the system automatically responds to changing conditions without requiring manual administrative input.
Data Source
AI summary
A secure database appliance leverages database security in a consistent framework providing consistent, flexible, and adaptable security using mandatory access controls in addition to user and role based security for access control and accountability. A database system comprises a plurality of database objects, each database object having a level of security, a plurality of factors, each factor representing a characteristic of a user of the database system, at least one database session of the user in the database, the database session having a level of security, the user connected to the database with a network domain, each network domain having a level of security, wherein the database system is operable to grant or deny access to the data to a user based on the factors associated with the user, based on the level of security of the data, based on the level of security of the database session, and based on the level of security of the network domain.


