Smart Storage Policy Enforcement for Context-Aware Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional binary access systems for sensitive information storage are inadequate for modern applications, as they rely solely on digital keys or passphrases, failing to consider additional criteria for access control, which can lead to insecure information release.
Innovation Solution
Implementing smart storage devices with processing capabilities that enforce policy-based access control, using contextual information from personal sensors and biometric measurements to dynamically manage access policies, allowing conditional access checks based on user states and contexts.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If binary access control using digital keys is used, then access security is provided, but access control flexibility and adaptability are insufficient
Solution Approach 1:
The patent implements dynamic access policies that can change based on contextual conditions such as user identity, time, location, and device state. Instead of static binary access control, the system continuously evaluates multiple criteria and adjusts access decisions in real-time, allowing the access control mechanism to adapt to different situations while maintaining security requirements.
Solution Approach 2:
The system changes the parameters of access control by introducing multiple evaluation criteria beyond simple key verification. It considers contextual parameters such as user profile, request timing, device characteristics, and environmental conditions, transforming the access control from a single-parameter (key presence) to multi-parameter decision-making process.
2Adaptability or versatility
If smart storage with policy-based access control is implemented, then access control flexibility is improved, but device complexity increases
Solution Approach 1:
The patent introduces a policy evaluation module as an intermediary between the storage system and access requests. This mediator component handles the complex policy evaluation logic, separating it from the core storage functionality. The policy module acts as a bridge that translates high-level access policies into concrete access decisions, managing complexity in a modular and maintainable way.
Solution Approach 2:
The access control system is segmented into distinct functional components: policy definition, policy evaluation, contextual data collection, and access decision-making. Each component handles a specific aspect of the access control process, allowing independent development, testing, and maintenance of individual modules while reducing overall system complexity.
3Reliability
If contextual information collection is added for policy-based access, then access security is enhanced, but information processing requirements increase
Solution Approach 1:
The system implements partial evaluation of contextual information by collecting and processing only the most relevant criteria for each access request. Instead of evaluating all possible contextual parameters uniformly, the policy evaluation mechanism selectively processes information based on the specific access context, reducing unnecessary computational overhead while maintaining security effectiveness.
Data Source
AI summary
Systems and methods for storing data and retrieving data from a smart storage device is provided, where smart storage includes processing capabilities along with the ability to store information. In one aspect, a method includes detecting via bidirectional settings one or more capabilities of rules enforcement logic associated with a storage device and selecting a set of criteria and policies to be downloaded from a host or a management server that are to be downloaded onto the storage device. This includes dynamically generating conditional context aware policies syntax based on user settings or network policy and downloading a set of policies onto the storage device for future policy enforcement.


