Database Access Control Automation via Policy Labels

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current database management systems face increased load and human error in implementing and monitoring access control based on security certification standards, particularly as the number of tables and roles grows, leading to inefficiencies and potential oversights in access control design and compliance.

Innovation Solution

A database management program that stores policy labels in metadata for target tables, references policy management information to specify access control for each role pattern, and creates access control information based on these specifications, reducing the burden on administrators and auditors by automating access control design and monitoring.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If access control is manually implemented and monitored for each table and role, then security compliance is achieved, but the workload and complexity increase significantly as the number of tables and roles grows

Engineering Contradiction:
Improvesecurity complianceVSAvoidaccess control management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments access control management by introducing policy labels that categorize data sensitivity levels and role patterns that define access behaviors. Instead of managing access control individually for each table-role combination, the system divides the management into reusable policy units that can be applied across multiple tables and roles, reducing overall complexity while maintaining security compliance

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates templates for policy labels and role patterns that can be copied and reused across multiple tables and roles. Once a policy label is defined for a specific data type or sensitivity level, it can be referenced by multiple tables. Similarly, role patterns are defined once and applied to multiple roles, eliminating redundant configuration work and reducing management complexity

Inventive Principle:
Principle #26Copying

2Manufacturing precision

If detailed access control policies are defined for each table and role, then security precision is improved, but the time and effort required for implementation increases

Engineering Contradiction:
Improveaccess control specification precisionVSAvoidaccess control implementation time
Core Design Contradiction:
Manufacturing precisionVSLoss of time

Solution Approach 1:

The patent performs preliminary action by pre-defining policy labels for different data types and sensitivity levels, and pre-defining role patterns for different access behaviors. These templates are created in advance and stored in the database system, so when new tables or roles are added, the access control policies are already available and can be applied immediately without requiring time-consuming custom configuration

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates universal policy labels and role patterns that serve multiple functions across different tables and roles. A single policy label can be applied to multiple tables with similar data characteristics, and a single role pattern can define access behavior for multiple roles with similar responsibilities, reducing the total number of policies that need to be created and maintained

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If manual monitoring of access control compliance is performed, then security oversight is achieved, but human error increases with the scale of the database system

Engineering Contradiction:
Improveaccess control monitoringVSAvoidcompliance accuracy
Core Design Contradiction:
ReliabilityVSManufacturing precision

Solution Approach 1:

The patent implements feedback mechanisms where the database system automatically monitors and reports on access control compliance. The system tracks which policy labels are applied to which tables, which role patterns are assigned to which roles, and whether access operations comply with the defined policies. This automated feedback reduces reliance on manual monitoring and minimizes human error in compliance verification

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20240184907A1Computer-readable recording medium storing database management program, database management method, and information processing device
Publication Date: 2024.06.06 FUJITSU LTD
  • US20240184907A1 patent drawing
  • US20240184907A1 patent drawing
  • US20240184907A1 patent drawing

AI summary

A recording medium stores a program for causing a computer to execute processing including: storing a first policy label according to a data type to be stored in a target table in metadata of the target table; referring to policy management information that defines content of access control that is performed on each role pattern and specifying the content of the access control that is performed on the each role pattern that corresponds to the first policy label stored in the metadata, for each of policy label that includes the first policy label; and referring to role management information that represents a correspondence between the each role pattern and roles in the target table and creating access control information that represents content of access control that is performed on a role based on the specified content of the access control that is performed on the each role pattern.