Mass Storage Bucket Access Control via Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Mass storage systems face challenges in securely managing access to data, particularly in allowing selective access to specific data parts while preventing unauthorized access by third parties, especially for critical data stored by individuals.
Innovation Solution
A network architecture that employs a server with a storage application and instruction service to manage access through 'buckets' organized by policies, where each bucket has associated policies, permissions, and instructions controlling access, slicing, encryption, and digital rights management, ensuring secure and controlled data storage and transfer.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a mass storage system is made available to multiple customers for a fee, then the system can provide data storage services to multiple clients, but it becomes difficult to secure data and limit access to appropriate clients
Solution Approach 1:
The patent segments the mass storage system into multiple isolated buckets, each belonging to a specific customer. Each bucket is further segmented into sub-buckets for different data types or access levels. This segmentation isolates customer data, preventing unauthorized access between clients while maintaining secure multi-client service capability.
Solution Approach 2:
The patent introduces an intermediary access control mechanism that mediates between clients and the mass storage system. This intermediary layer verifies client credentials, enforces access policies, and manages authentication tokens, thereby securing data access without compromising the multi-client service model.
2Ease of operation
If selective access to specific data parts is allowed, then authorized clients can access needed data, but the system complexity increases with policies and permissions management
Solution Approach 1:
The patent implements preliminary action by pre-configuring access policies and permissions for each bucket before data access requests occur. Access control rules, client credentials, and permission levels are established in advance, enabling selective data access without requiring complex real-time decision-making systems.
Solution Approach 2:
The patent introduces dynamic access control through time-limited authentication tokens and session-based permissions. Access rights can be dynamically granted, modified, or revoked based on client needs and security requirements, providing flexible selective access while managing system complexity through standardized token mechanisms.
Data Source
AI summary
Disclosed are various systems, methods, and other embodiments for the control of access to a mass storage system. In one example, a plurality of buckets are maintained in mass storage system, each of the buckets being employed to store at least one data file. In a server, a use of the buckets by a plurality of entities that use a plurality of clients is facilitated for the storage of a plurality of files over a public network. The use of one of the buckets by the one of the entities is restricted to a namespace.


