Session-Based Secure Access Control for Data Storage Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Recording systems lack secure access control and data protection mechanisms, making it difficult to ensure the confidentiality, integrity, and availability of recorded data, particularly in sensitive applications like security services and industrial monitoring, where data protection requirements are stringent.

Innovation Solution

A method for session-based and secure access control to a data storage system, which involves detecting an activation signal to initiate access, determining a free storage subarea, protecting data using cryptographic encryption, and managing access through authentication and authorization, ensuring that data from previous sessions is inaccessible without authorization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If access protection mechanisms (encryption, authentication) are implemented in recording systems, then data security and confidentiality are improved, but device complexity and computational requirements increase

Engineering Contradiction:
Improvedata securityVSAvoidaccess control complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a storage medium with an integrated data processing system as an intermediary between the recording system and the data storage system. This intermediary handles all access control, authentication, and encryption operations independently, allowing the recording system to remain simple while still achieving secure data protection. The storage medium acts as a self-contained security module that mediates all access requests.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The storage medium is designed to be self-sufficient with its own data processing system that autonomously manages authentication, authorization, and encryption without requiring the recording system to have built-in security capabilities. The storage medium serves itself by handling all security operations internally, eliminating the need for complex security infrastructure in the recording system.

Inventive Principle:
Principle #25Self-service

2Reliability

If session-based access control with selective storage subarea assignment is implemented, then data protection against unauthorized access is improved, but storage management complexity increases

Engineering Contradiction:
Improveaccess control securityVSAvoidstorage management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the data storage system into multiple selectively assignable storage subareas, with each subarea dedicated to specific write sessions. This segmentation ensures that data from different sessions are isolated in separate physical regions, providing inherent security against unauthorized access. The storage medium manager automatically manages this segmentation without requiring complex external control.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary assignment of storage subareas to write sessions before data is actually written. By pre-allocating and securing storage subareas in advance, the system ensures that each session has its own protected space from the outset, eliminating the need for complex real-time security checks during data operations.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If cryptographic encryption is applied to protect data during write sessions, then data confidentiality is improved, but processing time and energy consumption increase

Engineering Contradiction:
Improvedata confidentialityVSAvoiddata processing speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The storage medium's integrated data processing system autonomously handles all cryptographic encryption and decryption operations without requiring the recording system or external processors to perform these computationally intensive tasks. This self-service approach allows encryption to occur without impacting the productivity of the main recording system.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The storage medium acts as an intermediary that absorbs the computational overhead of cryptographic operations. By offloading encryption/decryption tasks to the storage medium's dedicated processing resources, the patent protects data confidentiality while preventing these operations from bottlenecking the overall data processing speed of the recording system.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20230274016A1Methods and systems for session-based and secure access control to a data storage system
Publication Date: 2023.08.31 SWISSBIT AG
  • US20230274016A1 patent drawing
  • US20230274016A1 patent drawing
  • US20230274016A1 patent drawing

AI summary

A method, in particular a computer-implemented method, for session-based and secure access control to a data storage system, comprising: detecting an activation signal for initiating access to the data storage system; and at least one write session to write write session-related data to the data storage system. In the method, each of the at least one write sessions comprises: in response to detecting the activation signal, determining a free physical storage subarea of the data storage system to be used during the write session to write the data, and selectively assigning this storage subarea to this write session; receiving or generating the data to be written in the context of the write session; protecting the data using an access protection, in particular assigned individually to the write session, which protects it from later access from unauthorized other access sessions to the data storage system; and outputting the access-protected data in order to write it to the storage subarea of the data storage system that is selectively assigned to the write session, or to cause this to be done.