Mass Storage Bucket Access Control via Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mass storage systems face challenges in securely managing access to data, particularly in allowing selective access to specific data parts while preventing unauthorized access by third parties, especially for critical data stored by individuals.

Innovation Solution

A network architecture that employs a server with a storage application and instruction service to manage access through 'buckets' organized by policies, where each bucket has associated policies, permissions, and instructions controlling access, slicing, encryption, and digital rights management, ensuring secure and controlled data storage and transfer.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a mass storage system is made available to multiple customers for a fee, then the system can provide data storage services to multiple clients, but it becomes difficult to secure data and limit access to appropriate clients

Engineering Contradiction:
Improvemulti-client storage serviceVSAvoiddata security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the mass storage system into multiple isolated buckets, each belonging to a specific customer. Each bucket is further segmented into sub-buckets for different data types or access levels. This segmentation isolates customer data, preventing unauthorized access between clients while maintaining secure multi-client service capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary access control mechanism that mediates between clients and the mass storage system. This intermediary layer verifies client credentials, enforces access policies, and manages authentication tokens, thereby securing data access without compromising the multi-client service model.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If selective access to specific data parts is allowed, then authorized clients can access needed data, but the system complexity increases with policies and permissions management

Engineering Contradiction:
Improveselective data accessVSAvoidaccess control system
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by pre-configuring access policies and permissions for each bucket before data access requests occur. Access control rules, client credentials, and permission levels are established in advance, enabling selective data access without requiring complex real-time decision-making systems.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces dynamic access control through time-limited authentication tokens and session-based permissions. Access rights can be dynamically granted, modified, or revoked based on client needs and security requirements, providing flexible selective access while managing system complexity through standardized token mechanisms.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS8321915B1Control of access to mass storage system
Publication Date: 2012.11.27 AMAZON TECH INC
  • US8321915B1 patent drawing
  • US8321915B1 patent drawing
  • US8321915B1 patent drawing

AI summary

Disclosed are various systems, methods, and other embodiments for the control of access to a mass storage system. In one example, a plurality of buckets are maintained in mass storage system, each of the buckets being employed to store at least one data file. In a server, a use of the buckets by a plurality of entities that use a plurality of clients is facilitated for the storage of a plurality of files over a public network. The use of one of the buckets by the one of the entities is restricted to a namespace.