Dual-Party Authentication for Distributed Storage Retention Locks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In distributed data storage systems, the risk of unauthorized data deletion exists due to the potential circumvention of authentication requirements, particularly in environments with numerous interconnected components, leading to inadvertent deletion of retained data during storage configuration changes.

Innovation Solution

Implementing a retention lock compliance mode that enforces dual-party authentication for accessing the remote access controller, using a configuration manager to propagate and maintain authentication settings across the distributed environment, ensuring that only authorized users can modify or delete data, and creating limited user accounts for restricted operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If dual-party authentication is implemented for data retention compliance, then data security is improved, but system complexity increases due to multiple interconnected components

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a configuration manager as an intermediary component that centralizes the management of authentication settings and retention lock configurations. This mediator coordinates between the filesystem's dual-party authentication mechanism and the remote access controller, simplifying the overall system architecture by providing a single point of control rather than requiring direct integration between multiple authentication components.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the authentication system into distinct functional modules: the filesystem layer handling dual-party authentication for data access, the remote access controller managing hardware-level permissions, and the configuration manager coordinating between them. This segmentation allows each component to maintain its own authentication requirements while working together through standardized interfaces.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If remote access controller allows storage configuration changes, then ease of operation is improved, but risk of unauthorized data deletion increases

Engineering Contradiction:
Improvestorage configuration changesVSAvoidunauthorized data deletion
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary anti-action by implementing retention locks on data before any configuration changes can be made. The configuration manager checks the authentication settings and prevents the remote access controller from allowing storage configuration changes that would affect locked data. This preemptive measure blocks potential unauthorized deletion before it can occur, rather than attempting to recover from it later.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The configuration manager continuously monitors the authentication settings of the remote access controller and provides feedback to maintain compliance. When the remote access controller's authentication mechanism drifts from the required dual-party authentication standard, the configuration manager detects this through status checks and automatically corrects the settings or alerts administrators, ensuring continuous compliance without manual intervention.

Inventive Principle:
Principle #23Feedback

3Reliability

If authentication settings are propagated across distributed environment, then data retention compliance is improved, but loss of time increases due to propagation delays

Engineering Contradiction:
Improvedata retention complianceVSAvoidpropagation delays
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The configuration manager performs preliminary actions by pre-configuring and caching authentication settings locally at each node in the distributed environment. When authentication requirements are updated, the configuration manager proactively propagates these changes to all relevant components before they are actually needed, rather than waiting for requests to come in. This reduces the perceived delay by having settings ready in advance.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system maintains continuous propagation of authentication settings through the distributed environment using persistent background processes. Rather than batch updates, the configuration manager continuously synchronizes authentication configurations across all nodes, ensuring that compliance is maintained at all times without periodic interruptions or delays. This continuous action eliminates gaps where compliance might be compromised.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS11601425B1Maintaining dual-party authentication requirements for data retention compliance within a distributed server environment
Publication Date: 2023.03.07 EMC IP HLDG CO LLC
  • US11601425B1 patent drawing
  • US11601425B1 patent drawing
  • US11601425B1 patent drawing

AI summary

Described is a system for maintaining dual-party authentication requirements for data retention compliance in a distributed storage environment that includes servers or nodes with remote access components. When administering a data retention policy, an operating system component may require a dual-party authentication mechanism to prevent data deletion, while a different authentication mechanism may control access to the remote access components. Access to the remote access component by a single privileged user, however, may enable overriding or compromising the retention lock compliance implemented by the operating system. Accordingly, the system may tie the dual-party authentication requirement to the authentication mechanism of the remote access components.