Dynamic Access Rights Management for Encrypted Data Vaults

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing access rights for secret data in dynamic user groups is challenging due to high user attrition rates and security risks, especially when third-party entities are involved, leading to increased administrative costs and security vulnerabilities.

Innovation Solution

Implementing a system that communicates with group management services like MS Teams or Slack to automatically verify user membership and adjust access rights, using a vault key for encryption that is updated based on user group activity, thereby reducing manual administrative tasks and enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual administrative techniques are used to modify access rights for stored data, then access control can be managed, but administrative costs increase and security risks increase due to human error and high user attrition rates

Engineering Contradiction:
ImprovesecurityVSAvoidadministrative overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system enables automatic access rights management where the storage service autonomously communicates with the group management system to verify membership and update access permissions. This self-service mechanism eliminates manual administrative tasks, reduces human error, and maintains security without increasing administrative overhead.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The storage service continuously receives membership data from the group management system and automatically adjusts access rights based on current group membership status. This feedback loop ensures that access permissions are always synchronized with actual group membership, preventing security risks from outdated permission data.

Inventive Principle:
Principle #23Feedback

2Reliability

If third-party entities are used to store secret data, then higher levels of security are provided against certain threats, but security vulnerabilities increase against malicious users or administrators of the third-party service

Engineering Contradiction:
ImprovesecurityVSAvoidsecurity risks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system segments the access control functionality by implementing a group management system that operates independently from the storage service. This segmentation allows the group management system to verify membership and provide access rights information without exposing the storage service to direct administrative control, thereby reducing security risks from malicious third-party administrators.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The group management system acts as an intermediary between users and the storage service. Instead of the storage service directly managing user permissions, it receives verified membership data from the group management system and automatically adjusts access rights accordingly. This intermediary layer protects the storage service from direct security threats while maintaining controlled access.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If access rights are manually updated when users join or leave groups, then access control accuracy is maintained, but productivity decreases due to manual administrative tasks

Engineering Contradiction:
Improveaccess control accuracyVSAvoidadministrative efficiency
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system replaces manual mechanical administrative tasks with automated computer-based processes. The storage service automatically communicates with the group management system to verify membership and update access rights, eliminating the need for manual intervention while maintaining precise access control accuracy.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system performs preliminary verification of group membership status before granting or revoking access rights. By proactively checking membership data from the group management system and pre-adjusting access permissions based on verified membership status, the system ensures accurate access control without requiring reactive manual updates.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11455412B2Enhanced management of access rights for dynamic user groups sharing secret data
Publication Date: 2022.09.27 MICROSOFT TECHNOLOGY LICENSING LLC
  • US11455412B2 patent drawing
  • US11455412B2 patent drawing
  • US11455412B2 patent drawing

AI summary

This disclosure provides enhanced management of access rights for dynamic groups of users sharing secret data. Instead of relying on traditional administrative techniques for modifying access rights for stored data, the techniques disclosed herein allow a storage service to communicate with a group management system to verify membership of user groups, e.g., channels, chat session, or meetings, and automatically change access rights to stored data as users leave or join a group. Encrypted data can be stored within a storage vault. The storage vault can be dedicated to storing encrypted data shared between a user group, e.g. a channel. A server managing the storage vault can receive membership data from a group management service. As users join the group or leave a group managed by the group management service, each user's access permissions to the storage vault can be added, removed or modified.