Object Addressable Storage Access Control via Security Content Units
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing storage systems, particularly block I/O systems, face challenges in managing access to content units as location changes require updates in access requests, whereas object addressable storage systems lack efficient mechanisms for user authentication and access control, especially in large-scale systems like My World information brokerage concepts.
Innovation Solution
Implementing a method within object addressable storage systems to store security information in security content units, associate them with object identifiers, and use these identifiers for access control, allowing users to grant access privileges to specific content units and create sub-pools for controlled access, while employing a security server for authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If object addressable storage systems store security information in separate security content units, then user authentication and access control become more efficient and scalable, but the system complexity increases due to the need to manage security content units alongside regular content units
Solution Approach 1:
The patent segments the storage system into regular content units and separate security content units. Each security content unit stores authentication information for specific object identifiers, allowing the system to efficiently verify user credentials without scanning entire content repositories. This segmentation improves access control efficiency while maintaining manageable system complexity through clear functional separation.
Solution Approach 2:
The patent introduces security content units as intermediary structures that mediate between users and content units. These security content units contain authentication information that acts as a mediator, enabling the storage system to verify user credentials and enforce access control policies without requiring complex authentication logic in the main storage operations.
2Measurement precision
If block I/O storage systems use logical volume and block addresses to identify data units, then data location can be precisely specified, but any location changes require updates to access requests and host awareness
Solution Approach 1:
The patent inverts the traditional block I/O approach by using object identifiers that remain constant regardless of physical or logical storage location. Instead of specifying location and hoping to identify the object, the system uses immutable object identifiers to access content, allowing the storage system to transparently handle location changes without requiring host awareness or access request updates.
Solution Approach 2:
The object identifier system provides self-service functionality where the identifier inherently contains or references the location information needed for access. When a host provides an object identifier, the storage system automatically resolves the current location and retrieves the content, eliminating the need for hosts to track or update location information manually.
3Ease of operation
If storage systems allow users to grant access privileges to specific content units, then fine-grained access control is achieved, but the mechanism for managing these privileges becomes more complex
Solution Approach 1:
The patent extracts authentication information into separate security content units that are independently managed. Each security content unit is associated with specific object identifiers and contains the necessary credentials and access control data. This extraction allows users to grant fine-grained access privileges to specific content units while the system manages the complexity of tracking and enforcing these privileges through dedicated security structures rather than embedding complex logic in every access operation.
Data Source
AI summary
Aspects of the invention relate to sharing content stored on an object addressable storage (OAS) system among a plurality of users of the OAS system and authenticating users to an OAS system. In some embodiments, a user may store content units on the OAS system and control access by other users to these content units. In some embodiments, when a user grants one or more other users access to a content unit stored on the OAS system, the OAS system may send a notification of grant of access to the other user(s).


