Storage Access Control System for Backup Data Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional security systems fail to maintain data access controls when secondary copies of sensitive information are created for backup purposes, leading to increased accessibility and potential unauthorized access to confidential data.

Innovation Solution

A storage access control system that leverages preexisting security infrastructures to apply access control information to secondary data copies, using metadata and Access Control Lists (ACLs) to ensure similar protection as the original data, and integrates with Active Directory for user management, while encrypting data for secure offsite storage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If secondary copies of data are created for backup purposes, then data recovery capability is improved, but data access security deteriorates

Engineering Contradiction:
Improvedata recovery capabilityVSAvoidunauthorized access to data
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary security system that sits between the backup storage and access requests. This intermediary layer validates access credentials and enforces security policies without preventing the backup function itself, thus maintaining data recovery capability while blocking unauthorized access paths.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates security metadata copies that mirror the access control structure of original data. By copying access control lists and security descriptors to secondary copies, the system maintains identical security properties in backups as in primary storage, preventing the security deterioration that normally occurs with data duplication.

Inventive Principle:
Principle #26Copying

2Speed

If backup files are stored in publicly accessible locations, then data restoration speed is improved, but data access control is weakened

Engineering Contradiction:
Improvedata restoration speedVSAvoiddata access control
Core Design Contradiction:
SpeedVSEase of operation

Solution Approach 1:

The patent segments the backup storage system into publicly accessible storage regions and securely controlled access regions. The storage infrastructure is divided such that physical accessibility is maintained for speed, while logical access control is enforced through segmented security boundaries and access control lists.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different security qualities to different parts of the backup system. Publicly accessible locations maintain open access for authorized restoration operations, while specific data regions within the backup storage enforce restricted access controls based on original data security requirements.

Inventive Principle:
Principle #3Local quality

3Productivity

If indexed search is enabled on backup data, then data search capability is improved, but security protection is reduced

Engineering Contradiction:
Improvedata search capabilityVSAvoidexposure of sensitive information
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary search processing layer that sits between search requests and indexed backup data. This intermediary validates user credentials, checks access permissions against security policies, and filters search results accordingly, enabling search functionality while preventing direct exposure of sensitive information.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates security-aware copies of index structures that include access control metadata. By copying security descriptors alongside index entries, the search system can evaluate access permissions during search operations without requiring direct access to the underlying sensitive data, thus maintaining security protection.

Inventive Principle:
Principle #26Copying

4Ease of manufacture

If traditional security systems are used for backup data, then administrative effort is reduced, but security effectiveness deteriorates

Engineering Contradiction:
Improveadministrative effortVSAvoidsecurity effectiveness
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent creates a universal security framework that handles multiple security functions through a single integrated system. The security subsystem provides centralized credential validation, access policy enforcement, and security metadata management that works across primary storage, backup storage, and search operations, reducing administrative effort while improving security effectiveness through consistent enforcement.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent performs preliminary security processing during backup creation operations. Access control lists and security descriptors are copied and validated in advance, before data is written to backup storage. This preliminary action ensures security effectiveness is maintained without requiring additional administrative effort during restoration or search operations.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8880466B2System and method for storage operation access security
Publication Date: 2014.11.04 COMMVAULT SYSTEMS INC
  • US8880466B2 patent drawing
  • US8880466B2 patent drawing
  • US8880466B2 patent drawing

AI summary

A method and system for controlling access to stored data is provided. The storage access control system leverages a preexisting security infrastructure of a system to inform the proper access control that should be applied to data stored outside of its original location, such as a data backup. The storage access control system may place similar access control restrictions on the backup files that existed on the original files. In this way, the backed up data is given similar protection as that of the original data.