Domain-Based Application Data Access Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data access isolation techniques are too simple and rigid, limiting the flexibility in sharing data between applications, particularly for trusted applications from the same manufacturer, and fail to meet complex application data isolation requirements.
Innovation Solution
Implementing a domain-based data access isolation method that uses hierarchical relationships between domains, where applications within the same domain or child domains can access each other's data, and dynamically adjusts domain attributes to allow or deny access based on predefined rules and conditions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If UID-based isolation technique is used to allow applications with the same signature to access each other's data, then data sharing among trusted applications is achieved, but the isolation technique becomes too rigid and cannot satisfy complex application data isolation requirements
Solution Approach 1:
The patent segments the isolation mechanism from a single UID-based approach into a multi-dimensional system involving UID, GID, and domain attributes. This segmentation allows independent control over different aspects of data access, enabling both simple same-signature sharing and complex hierarchical domain-based sharing without rigidity
Solution Approach 2:
The patent adds another dimension to the isolation mechanism by introducing domain attributes and hierarchical domain relationships beyond the traditional UID-based single dimension. This dimensional expansion enables complex data isolation requirements to be satisfied while maintaining flexibility for trusted applications to share data
2Reliability
If strict isolation technique is used to prevent applications from accessing each other's data, then data security is improved, but data sharing among trusted applications becomes difficult
Solution Approach 1:
The patent implements a dynamic access control system where isolation permissions are not fixed but can be adjusted based on domain relationships. Applications can dynamically share data within their domain while maintaining isolation from other domains, achieving both security and flexibility through conditional rather than absolute isolation
Solution Approach 2:
The patent introduces domain attributes as an intermediary layer between the application and the data access control mechanism. This intermediary enables trusted applications to share data by establishing common domain relationships, while still maintaining security through the domain-based access control framework
Data Source
AI summary
Isolating application data access is disclosed including receiving a request from a first application to access data of a second application, determining whether the first application is in a domain that has access authorization to the data of the second application, in response to a determination that the first application is in a domain that has access authorization to the data of the second application, permitting the first application to perform the access operation, and in response to a determination that the first application is not in a domain that has access authorization to the data of the second application, denying the first application permission to perform the access operation.


