Scoped Permissions for Granular Storage Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional role-based access control (RBAC) techniques in storage systems authorize access at an operational level, leading to accidental and intentional data loss and unauthorized data access, and centralize administrative tasks, reducing user experience by requiring limited skilled personnel for management of virtualized storage systems.
Innovation Solution
Implementing a system that scopes access to storage system resources and operations at both the operational and storage object levels, using scoped permissions to restrict user actions and resource flags, allowing for more granular control and delegation of administrative tasks through resource group inheritance and storage tiers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If conventional RBAC techniques authorize access at an operational level only, then administrative control is simplified, but data security deteriorates leading to accidental and intentional data loss
Solution Approach 1:
The patent segments access control into two distinct levels: operational level (create, delete, modify operations) and storage object level (specific volumes, files, or directories). By dividing the previously unified access control mechanism into separate authorization layers, the system achieves both simplified administrative structure and enhanced data security through granular permissions.
Solution Approach 2:
The patent implements local quality by allowing different permission settings for different storage objects. Each storage volume, file, or directory can have its own access control list (ACL) with specific users and groups assigned particular permissions. This enables security policies to be tailored locally to each object's requirements while maintaining overall system-wide access control consistency.
2Device complexity
If conventional RBAC techniques use centralized administrative control, then security management is simplified, but user experience deteriorates requiring limited skilled personnel for all management tasks
Solution Approach 1:
The patent enables self-service by allowing users to manage their own storage resources within their authorized scope. Users can perform administrative tasks such as creating storage volumes, managing snapshots, and configuring settings for their own data without requiring intervention from skilled system administrators. The system automatically enforces permission boundaries, enabling users to autonomously manage their resources.
Solution Approach 2:
The patent adds a new dimension to access control by introducing resource-specific permission scopes alongside traditional operational permissions. This dimensional expansion allows the system to differentiate between what operations a user can perform and what specific resources they can access, enabling more flexible delegation of administrative tasks to multiple users with varying levels of authority.
3Adaptability or versatility
If conventional RBAC techniques assign broad operational privileges to a role, then operational flexibility is improved, but data protection deteriorates allowing unauthorized data access
Solution Approach 1:
The patent segments permissions into operational permissions (what actions can be performed) and resource permissions (which specific objects can be accessed). A user role can be granted broad operational flexibility to perform various storage operations while simultaneous resource-level ACLs restrict access to only authorized data objects, preventing unauthorized access even when operational privileges are extensive.
Solution Approach 2:
The patent implements dynamic permission evaluation by checking both operational permissions and resource-specific ACLs at the time of each access request. This dynamic two-layer authorization mechanism adapts to each specific operation-object combination, allowing operational flexibility where permitted while automatically blocking unauthorized access attempts, thereby protecting against data breaches while maintaining system versatility.
Data Source
AI summary
Systems and methods authorizing access to storage system resources are presented herein. A scoped permission assignment can be associated with an operation related to a type of at least one resource. The scoped permission assignment can be assigned to a role; and the role can be associated with user(s). A resource, or one or more resources of a resource group, can be associated with user(s) or user group(s). Further, a user can be authorized to perform the operation on the resource and/or one or more resources based on, at least in part, permission assignments directly granted to the user or granted in a role of the user. In addition, one or more resource flags can be assigned to the one or more resources. Accordingly, the user can be authorized to perform the operation based on, at least in part, the one or more resource flags and the scoped permission assignment.


