Domain-Based Application Data Access Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data access isolation techniques are too simple and rigid, limiting the flexibility in sharing data between applications, particularly for trusted applications from the same manufacturer, and fail to meet complex application data isolation requirements.

Innovation Solution

Implementing a domain-based data access isolation method that uses hierarchical relationships between domains, where applications within the same domain or child domains can access each other's data, and dynamically adjusts domain attributes to allow or deny access based on predefined rules and conditions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If UID-based isolation technique is used to allow applications with the same signature to access each other's data, then data sharing among trusted applications is achieved, but the isolation technique becomes too rigid and cannot satisfy complex application data isolation requirements

Engineering Contradiction:
Improvedata sharing capabilityVSAvoidisolation mechanism complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the isolation mechanism from a single UID-based approach into a multi-dimensional system involving UID, GID, and domain attributes. This segmentation allows independent control over different aspects of data access, enabling both simple same-signature sharing and complex hierarchical domain-based sharing without rigidity

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds another dimension to the isolation mechanism by introducing domain attributes and hierarchical domain relationships beyond the traditional UID-based single dimension. This dimensional expansion enables complex data isolation requirements to be satisfied while maintaining flexibility for trusted applications to share data

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If strict isolation technique is used to prevent applications from accessing each other's data, then data security is improved, but data sharing among trusted applications becomes difficult

Engineering Contradiction:
Improvedata securityVSAvoiddata sharing capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements a dynamic access control system where isolation permissions are not fixed but can be adjusted based on domain relationships. Applications can dynamically share data within their domain while maintaining isolation from other domains, achieving both security and flexibility through conditional rather than absolute isolation

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent introduces domain attributes as an intermediary layer between the application and the data access control mechanism. This intermediary enables trusted applications to share data by establishing common domain relationships, while still maintaining security through the domain-based access control framework

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10831915B2Method and system for isolating application data access
Publication Date: 2020.11.10 BANMA ZHIXING NETWORK HONGKONG CO LTD
  • US10831915B2 patent drawing
  • US10831915B2 patent drawing
  • US10831915B2 patent drawing

AI summary

Isolating application data access is disclosed including receiving a request from a first application to access data of a second application, determining whether the first application is in a domain that has access authorization to the data of the second application, in response to a determination that the first application is in a domain that has access authorization to the data of the second application, permitting the first application to perform the access operation, and in response to a determination that the first application is not in a domain that has access authorization to the data of the second application, denying the first application permission to perform the access operation.