Multi-admin verification for data store security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Role-based access control (RBAC) and multi-factor authentication (MFA) techniques fall short in providing sufficient security for data stores, as they are vulnerable to spoofing and misbehavior by authorized entities, including corruption over time, leading to potential unauthorized data operations.
Innovation Solution
Implementing multi-admin verification (MAV) systems that require multiple distinct electronic approvals from different credentials within specific timeframes and security clearance levels, with rules specifying authorized credentials for approval and execution, and prohibiting self-approvals and self-executions, to enhance data store security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If RBAC and MFA techniques are implemented, then access control security is improved, but security gaps remain vulnerable to spoofing and misbehavior by authorized entities
Solution Approach 1:
The patent segments the approval process into multiple independent stages: request initiation by one credential, approval by a different credential, and execution by yet another credential. This segmentation ensures that no single credential can complete the entire operation alone, preventing spoofing and misbehavior by dividing security responsibilities across multiple trusted entities.
Solution Approach 2:
The patent introduces an intermediary approval mechanism where a second credential acts as a mediator between the first credential (requestor) and the data operation. This intermediary verification layer prevents direct access even for authorized entities, requiring independent validation by a separate trusted credential before any data operation can proceed.
2Reliability
If multiple distinct electronic approvals are required, then security is strengthened, but system complexity increases
Solution Approach 1:
The patent implements a universal multi-admin verification framework that can be applied to any data operation type and any number of credentials. The system uses a standardized set of rules that work across different scenarios, managing complexity through reusable, multi-functional components rather than custom solutions for each case.
Solution Approach 2:
The patent manages complexity by making the verification rules configurable through parameters such as the number of required approvals, time span constraints, and credential relationships. By changing these parameters, the system can adapt to different security requirements without restructuring the entire verification mechanism, thus controlling system complexity.
3Reliability
If approval timeframes are enforced, then security against untimely actions is improved, but operational flexibility decreases
Solution Approach 1:
The patent implements dynamic time span constraints that can be adjusted based on the specific data operation and security requirements. The time span parameter allows the system to enforce security constraints when needed while permitting longer or shorter windows for approvals depending on the operational context, thus maintaining both security and flexibility.
Data Source
AI summary
Systems/techniques that facilitate multi-admin verification (MAV) for improved security of data stores are provided. In various embodiments, auto-execution of electronic requests may be facilitated. For example, an electronic approval of an electronic request may be received from an approver credential. A determination can be made that the electronic approval is a final electronic approval that causes a threshold number of valid electronic approvals for placing the electronic request in an approved state to be met. The electronic request is marked as being in the approved state in response to determining that the electronic approval is the final electronic approval. The electronic request is executed automatically after the electronic request has entered the approved state when the electronic request has been designated for auto-execution.


