Secure Database Appliance Mandatory Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional user and role-based security models for access control are inadequate for ensuring consistent, flexible, and adaptable security, particularly in environments requiring compliance with multiple governance requirements, as they are difficult to implement, administer, and maintain, and often necessitate custom application code.

Innovation Solution

A secure database appliance that implements a consistent framework for database security, utilizing mandatory access controls and a multi-factored approach to provide adaptable security, minimizing the need for custom application code, by leveraging Oracle GRID architecture and integrating features like Real Application Clusters, Label Security, and Partitioning to enforce security policies across network domains.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional user and role based security model is used, then access control can be provided, but security consistency and adaptability deteriorate and administration complexity increases

Engineering Contradiction:
Improvesecurity consistencyVSAvoidadministration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments security policies into discrete, manageable units that can be independently configured and enforced. Security policies are divided into specific rules that can be applied to different data sets, allowing administrators to manage security in modular components rather than as a monolithic system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal security framework that handles multiple security requirements through a single system. The security appliance provides a unified interface that can enforce various types of security policies (lockdown, administration, integration, enforcement) without requiring separate systems or custom code for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If high level security is implemented, then security protection is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvesecurity protectionVSAvoidease of administration
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The security appliance enables self-service security enforcement by automatically applying security policies to data based on configured rules. The system autonomously evaluates security conditions and enforces access control without requiring manual intervention or custom application code, reducing the operational burden on administrators.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent allows security parameters to be dynamically configured and adjusted through a standardized interface. Administrators can modify security policy parameters (such as access levels, data classifications, and enforcement rules) without changing the underlying system architecture or writing custom code, making high-level security adaptable and easy to operate.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If custom application code is developed to support security policies, then security enforcement capability is improved, but device complexity and maintenance difficulty increase

Engineering Contradiction:
Improvesecurity enforcement capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security appliance acts as an intermediary layer between the database and application code. It provides a standardized interface that handles security enforcement internally, eliminating the need for applications to contain embedded security logic. The appliance mediates all security-related operations through统一的APIs and policy mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements security policies as reusable templates or copies that can be applied across multiple data sets and applications. Instead of developing custom security code for each application, administrators can replicate and adapt standardized security policy templates, reducing complexity and maintenance requirements.

Inventive Principle:
Principle #26Copying

4Reliability

If multiple security features are integrated in existing database, then security coverage is improved, but difficulty of detecting and measuring security status increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidsecurity administration difficulty
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent merges multiple security features and functions into a single integrated security appliance. By consolidating authentication, authorization, auditing, and policy enforcement into one unified system, the patent simplifies the detection and measurement of security status. Administrators can monitor and assess security through a centralized interface rather than tracking multiple separate security mechanisms.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS8732856B2Cross-domain security for data vault
Publication Date: 2014.05.20 ORACLE INT CORP
  • US8732856B2 patent drawing
  • US8732856B2 patent drawing
  • US8732856B2 patent drawing

AI summary

A secure database appliance leverages database security in a consistent framework provides consistent, flexible, and adaptable security using mandatory access controls in addition to user and role based security for access control and accountability. A database system communicatively connected to a plurality of network domains, each network domain having a level of security, the database system comprises at least one database accessible from all of the plurality of network domains, the database comprising data, each unit of data having a level of security and access control security operable to provide access to a unit of data in the database to a network domain based on the level of security of the network domain and based on the level of security of the unit of data.