Multi-Party Snapshot Authorization Against Ransomware Changes
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing role-based access control (RBAC) models in computing clusters are insufficient in preventing malicious or inadvertent data modifications, particularly in the context of phishing attacks that compromise administrator credentials, allowing ransomware to encrypt data.
Innovation Solution
Implementing multi-party authorization (MPA) within an identity and access management regime to require consensus from multiple parties before allowing data modifications, enhancing RBAC with MPA workflows and watchdog timers to thwart malicious operations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If role-based access control (RBAC) is used to manage permissions in computing clusters, then access control is simplified and easier to implement, but security against phishing attacks and ransomware is insufficient
Solution Approach 1:
The patent segments the authorization process into multiple independent parties (MPA parties). Instead of a single RBAC decision, critical operations require separate authorizations from multiple designated parties. This segmentation ensures that compromise of one credential does not grant full access, as each MPA party operates independently with limited scope.
Solution Approach 2:
The patent adds a new dimension to the traditional RBAC model by introducing multi-party authorization workflows. Beyond the traditional user-role-permission hierarchy, a temporal and collaborative dimension is added where multiple parties must coordinate their authorizations over time. This dimensional expansion transforms single-point authorization into a distributed, time-aware consent mechanism.
2Reliability
If multi-party authorization is implemented to prevent ransomware attacks, then security against malicious operations is improved, but system complexity increases
Solution Approach 1:
The patent implements preliminary action by pre-designating MPA parties and their authorization scopes before any critical operations occur. The system establishes the multi-party authorization framework, assigns parties to specific roles, and defines their permissions in advance. This preparation eliminates the need for complex real-time decision-making during operations, as the authorization structure is already in place.
Solution Approach 2:
The patent introduces an intermediary authorization system that mediates between the requesting operation and the final execution. The MPA authorization workflow acts as a mediator that coordinates between multiple parties, validates their consents, and only permits the operation if all required parties have authorized. This intermediary layer simplifies the overall system by centralizing the complexity of multi-party coordination in a dedicated framework.
3Reliability
If multi-party authorization workflows are used for critical operations, then data modification security is enhanced, but operational speed and efficiency are reduced
Solution Approach 1:
The patent applies local quality by making multi-party authorization mandatory only for critical operations with high security requirements, while allowing standard operations to proceed with simpler RBAC controls. Not all data modifications trigger MPA workflows—only those marked as critical. This selective application optimizes the balance between security enhancement and operational efficiency.
Solution Approach 2:
The patent uses preliminary action by pre-establishing MPA party designations and authorization frameworks before critical operations occur. Since the multi-party structure is pre-configured with defined roles, contacts, and procedures, the actual execution phase requires only coordination among pre-identified parties rather than complex real-time setup, reducing the time penalty of multi-party authorization.
Data Source
AI summary
Methods, systems, and computer program products for thwarting a malware attack. A data storage system stores data items, some of which data items correspond to snapshots. Upon identification of a possible ransomware attack on a data item, the system identifies a version of the snapshot that is not subject to the ransomware attack and seeks to protect the data state of the system from further damage (e.g., due to performance of unauthorized operations on the version of the snapshot that is not subject to the ransomware attack) by requiring consensus from a multi-party authorization (MPA) consensus regime before carrying out requested operations over the snapshot. The MPA consensus regime operates by determining that the operation is subject to a role-based access control (RBAC) as well as a multi-party authorization (MPA) consensus protocol, and then allowing or denying execution of the requested operations based on achieving consensus from among candidate approvers.


