Self-Protecting Data Objects for Zero-Trust Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security systems rely on network and application trust, which can be compromised, leading to vulnerabilities in infrastructure security.
Innovation Solution
A rules-based policy driven engine that employs a zero-trust security principle, enabling self-protecting data objects to make access decisions based on embedded policies and variables, independent of network or application trust.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If network and application trust models are used for security, then access control can be simplified, but security reliability deteriorates when trust is compromised
Solution Approach 1:
The data object performs self-protection by embedding security policies directly within itself and autonomously evaluating access requests against these policies. The data object independently makes access decisions without relying on external network or application trust models, thereby maintaining security reliability while simplifying the access control process.
Solution Approach 2:
Instead of the traditional model where the network or application controls access based on trust, this invention inverts the approach by making the data object itself the controller of its own access. The data object actively evaluates access requests and denies access to untrusted sources, reversing the passive trust-based model into an active security model.
2Reliability
If zero-trust security principles are implemented, then security reliability improves, but device complexity increases
Solution Approach 1:
The security function is segmented and embedded within each individual data object rather than being centralized in the network or application layer. Each data object contains its own security policies and evaluation logic, distributing the complexity across multiple small units rather than concentrating it in a single complex system.
Solution Approach 2:
The invention merges the data object with its security policies, creating a unified self-protecting entity. By combining the data storage function with the security evaluation function within the same object, the system reduces overall complexity while improving security reliability through integrated design.
Data Source
AI summary
In an aspect, an apparatus is presented. An apparatus may include a processor and a memory communicatively coupled to the processor. A memory may contain instructions to cause the processor to receive a variable. A processor may compare a variable to one or more policies. A processor may apply one or more rules to a variable base don a comparison to one or more policies. A processor may instruct an actor to perform an action with a variable based on one or more rules. A processor may produce an output based on an action performed, wherein the output is produced using a zero-trust security principle.


