Dual-Party Authentication for Data Retention Compliance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Data retention policies in storage systems are vulnerable to unauthorized deletion due to the potential circumvention of authentication requirements, especially when managing storage hardware, leading to inadvertent deletion of retained data.

Innovation Solution

Implementing a retention lock compliance mode that requires dual-party authentication for modifying data, which ties the filesystem's authentication mechanism to the remote access controller's authentication, ensuring that all previous user accounts are reset and new accounts are created with limited privileges to maintain data integrity and adherence to retention policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a remote access controller is implemented to manage storage hardware, then ease of operation is improved, but data retention compliance is worsened due to potential circumvention of authentication requirements

Engineering Contradiction:
Improveease of operationVSAvoiddata retention compliance
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a retention lock mechanism as an intermediary between the remote access controller and the filesystem. This retention lock acts as a mediator that enforces dual-party authentication requirements, preventing the remote access controller from circumventing authentication procedures while still allowing hardware management operations to proceed through the authorized channel.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If dual-party authentication is enforced for all data modifications, then data retention compliance is improved, but device complexity is worsened due to additional authentication mechanisms

Engineering Contradiction:
Improvedata retention complianceVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication mechanism into distinct components: a retention lock that manages dual-party authentication for data modifications, and a remote access controller that handles hardware management. This segmentation allows each component to have specialized authentication logic, reducing overall system complexity while maintaining strong security controls.

Inventive Principle:
Principle #1Segmentation

3Reliability

If previous user accounts are reset and new accounts with limited privileges are created, then data integrity is improved, but ease of operation is worsened due to authentication requirements

Engineering Contradiction:
Improvedata integrityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements preliminary action by resetting user accounts and establishing new accounts with limited privileges before allowing any data modification operations. This preliminary authentication setup ensures data integrity is established beforehand, and subsequent operations can proceed more smoothly within the constrained framework of predefined authorized actions.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11341230B1Maintaining dual-party authentication requirements for data retention compliance
Publication Date: 2022.05.24 EMC IP HLDG CO LLC
  • US11341230B1 patent drawing
  • US11341230B1 patent drawing
  • US11341230B1 patent drawing

AI summary

Described is a system for maintaining dual-party authentication requirements for data retention compliance in systems with remote access components. When administering a data retention policy, an operating system component may require a dual-party authentication mechanism to prevent data deletion, while a different authentication mechanism may control access to the remote access controller. Access to the remote access controller by a single privileged user, however, may enable overriding or compromising the retention lock compliance implemented by the operating system. Accordingly, the system may tie the dual-party authentication requirement to the remote access controller authentication mechanism.