Dynamic Access Rights Management for Encrypted Data Vaults
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Managing access rights for secret data in dynamic user groups is challenging due to high user attrition rates and security risks, especially when third-party entities are involved, leading to increased administrative costs and security vulnerabilities.
Innovation Solution
Implementing a system that communicates with group management services like MS Teams or Slack to automatically verify user membership and adjust access rights, using a vault key for encryption that is updated based on user group activity, thereby reducing manual administrative tasks and enhancing security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual administrative techniques are used to modify access rights for stored data, then access control can be managed, but administrative costs increase and security risks increase due to human error and high user attrition rates
Solution Approach 1:
The system enables automatic access rights management where the storage service autonomously communicates with the group management system to verify membership and update access permissions. This self-service mechanism eliminates manual administrative tasks, reduces human error, and maintains security without increasing administrative overhead.
Solution Approach 2:
The storage service continuously receives membership data from the group management system and automatically adjusts access rights based on current group membership status. This feedback loop ensures that access permissions are always synchronized with actual group membership, preventing security risks from outdated permission data.
2Reliability
If third-party entities are used to store secret data, then higher levels of security are provided against certain threats, but security vulnerabilities increase against malicious users or administrators of the third-party service
Solution Approach 1:
The system segments the access control functionality by implementing a group management system that operates independently from the storage service. This segmentation allows the group management system to verify membership and provide access rights information without exposing the storage service to direct administrative control, thereby reducing security risks from malicious third-party administrators.
Solution Approach 2:
The group management system acts as an intermediary between users and the storage service. Instead of the storage service directly managing user permissions, it receives verified membership data from the group management system and automatically adjusts access rights accordingly. This intermediary layer protects the storage service from direct security threats while maintaining controlled access.
3Measurement precision
If access rights are manually updated when users join or leave groups, then access control accuracy is maintained, but productivity decreases due to manual administrative tasks
Solution Approach 1:
The system replaces manual mechanical administrative tasks with automated computer-based processes. The storage service automatically communicates with the group management system to verify membership and update access rights, eliminating the need for manual intervention while maintaining precise access control accuracy.
Solution Approach 2:
The system performs preliminary verification of group membership status before granting or revoking access rights. By proactively checking membership data from the group management system and pre-adjusting access permissions based on verified membership status, the system ensures accurate access control without requiring reactive manual updates.
Data Source
AI summary
This disclosure provides enhanced management of access rights for dynamic groups of users sharing secret data. Instead of relying on traditional administrative techniques for modifying access rights for stored data, the techniques disclosed herein allow a storage service to communicate with a group management system to verify membership of user groups, e.g., channels, chat session, or meetings, and automatically change access rights to stored data as users leave or join a group. Encrypted data can be stored within a storage vault. The storage vault can be dedicated to storing encrypted data shared between a user group, e.g. a channel. A server managing the storage vault can receive membership data from a group management service. As users join the group or leave a group managed by the group management service, each user's access permissions to the storage vault can be added, removed or modified.


