Dual-Party Authentication for Data Retention Compliance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Data retention policies in storage systems are vulnerable to unauthorized deletion due to the potential circumvention of authentication requirements, especially when managing storage hardware, leading to inadvertent deletion of retained data.
Innovation Solution
Implementing a retention lock compliance mode that requires dual-party authentication for modifying data, which ties the filesystem's authentication mechanism to the remote access controller's authentication, ensuring that all previous user accounts are reset and new accounts are created with limited privileges to maintain data integrity and adherence to retention policies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a remote access controller is implemented to manage storage hardware, then ease of operation is improved, but data retention compliance is worsened due to potential circumvention of authentication requirements
Solution Approach 1:
The patent introduces a retention lock mechanism as an intermediary between the remote access controller and the filesystem. This retention lock acts as a mediator that enforces dual-party authentication requirements, preventing the remote access controller from circumventing authentication procedures while still allowing hardware management operations to proceed through the authorized channel.
2Reliability
If dual-party authentication is enforced for all data modifications, then data retention compliance is improved, but device complexity is worsened due to additional authentication mechanisms
Solution Approach 1:
The patent segments the authentication mechanism into distinct components: a retention lock that manages dual-party authentication for data modifications, and a remote access controller that handles hardware management. This segmentation allows each component to have specialized authentication logic, reducing overall system complexity while maintaining strong security controls.
3Reliability
If previous user accounts are reset and new accounts with limited privileges are created, then data integrity is improved, but ease of operation is worsened due to authentication requirements
Solution Approach 1:
The patent implements preliminary action by resetting user accounts and establishing new accounts with limited privileges before allowing any data modification operations. This preliminary authentication setup ensures data integrity is established beforehand, and subsequent operations can proceed more smoothly within the constrained framework of predefined authorized actions.
Data Source
AI summary
Described is a system for maintaining dual-party authentication requirements for data retention compliance in systems with remote access components. When administering a data retention policy, an operating system component may require a dual-party authentication mechanism to prevent data deletion, while a different authentication mechanism may control access to the remote access controller. Access to the remote access controller by a single privileged user, however, may enable overriding or compromising the retention lock compliance implemented by the operating system. Accordingly, the system may tie the dual-party authentication requirement to the remote access controller authentication mechanism.


