Centralized RBAC API Proxy for Storage Server Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current storage management systems face challenges in providing centralized, seamless access control for multiple storage servers, especially in large organizations with many administrators, and require efficient management of access privileges and integration with third-party applications.
Innovation Solution
Implementing a centralized network server that proxies requests to storage servers, using a storage management software with an API proxy to enforce role-based access control (RBAC) and manage access privileges, allowing third-party applications to access storage servers transparently while maintaining per-API, per-user, and per-object control.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If the same username and password are assigned to each storage server, then administrative users can access all storage servers with a single credential set, but the system becomes unwieldy for large organizations with many administrators and cannot enforce different access privileges for different users
Solution Approach 1:
The patent segments access control into multiple hierarchical levels: domains contain organizations, which contain departments, which contain users. Each level can be independently managed with its own credentials and policies. This allows large organizations to divide their administrator base into manageable segments rather than managing all administrators uniformly across the entire organization.
Solution Approach 2:
The patent introduces hierarchical dimensions to access control by adding domain, organization, and department layers between the user and storage server. Instead of a flat credential system, access is controlled through multiple nested dimensions, allowing fine-grained permission management while maintaining ease of access through the hierarchical structure.
2Reliability
If different usernames and passwords are assigned to different administrators with different privileges, then access security is improved, but the credential management becomes particularly cumbersome for large organizations
Solution Approach 1:
The patent creates universal domain credentials that can be used across multiple storage servers and organizations within a domain. A single domain credential set can authenticate users to multiple storage servers without requiring separate credentials for each server, while still enforcing different access privileges through the hierarchical permission structure.
Solution Approach 2:
The patent allows credentials and permission sets to be copied and reused across different organizations and departments within the hierarchical structure. Once a credential set and permission profile are defined at a higher level, they can be replicated and assigned to multiple users or organizations, reducing the burden of creating unique credentials for each user while maintaining security.
3Device complexity
If centralized control of access is implemented through storage management software, then access privileges can be enforced for different users, but third-party applications cannot easily access storage servers
Solution Approach 1:
The patent introduces domain credentials as an intermediary mechanism between third-party applications and storage servers. Instead of requiring third-party applications to directly implement complex authentication with individual storage servers, they can use domain credentials as a mediator that facilitates access while the centralized system enforces permission policies.
Solution Approach 2:
The patent makes domain credentials universally applicable across multiple storage servers and organizations. Third-party applications can use the same domain credential set to access multiple storage servers without needing to implement separate authentication mechanisms for each server, while the centralized system maintains control over access privileges.
4Reliability
If multiple storage servers are managed with individual access control, then security is maintained, but scalability to large organizations with many servers becomes difficult
Solution Approach 1:
The patent merges access control policies and credentials across multiple storage servers into a unified hierarchical domain structure. Instead of managing access control independently for each storage server, the system combines them into domain-level policies that automatically apply across multiple servers, maintaining security while enabling scalable administration.
Solution Approach 2:
The patent creates universal domain-level access control that functions across multiple storage servers simultaneously. A single domain credential and policy set can manage access to numerous storage servers, allowing the system to scale to large organizations without requiring proportional increases in administrative overhead.
Data Source
AI summary
Centralized role-based access control (RBAC) for storage servers can include operating multiple storage servers, each configured to provide a set of clients with access to stored data, and using a separate network server to provide centralized RBAC. The network server may include an API proxy to proxy requests to access individual APIs of a storage server by an application which is external to the network server and the storage server and may control access to the individual APIs of the storage servers on a per-API, per-user and per-object basis. The API proxy may filter responses to API calls based on the access privileges of the user of the application which sent the API call. In some embodiments, the network server may implement a Windows domain server, an LDAP server or the like to evaluate security credentials of administrative users on behalf of multiple storage servers.


