Data Storage Access Control via Metadata-Driven Role Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data storage systems face challenges in efficiently managing user access and access control across multiple storage resources, particularly in large networks with varying data protection requirements, leading to complex and impractical manual configuration processes for IT managers.

Innovation Solution

A method and system for controlling user access in a data storage system that utilizes role-based access control (RBAC) by storing access control information for user accounts and roles, determining access permissions based on data structure metadata, and managing access through a user interface controller and resource handling controllers to ensure secure and efficient access to primary and secondary data structures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Manufacturing precision

If manual configuration of access control policies is implemented at a granular level for each data type, regulation, and repository location, then access control precision and compliance are improved, but the complexity of configuration and ease of operation deteriorate

Engineering Contradiction:
Improveaccess control precisionVSAvoidconfiguration complexity
Core Design Contradiction:
Manufacturing precisionVSDevice complexity

Solution Approach 1:

The system segments access control configuration into hierarchical levels: organization-wide policies, department-level policies, and user-specific assignments. This segmentation allows precise control at each level without requiring manual configuration of every individual data-access combination, thereby maintaining access control precision while reducing configuration complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary action by automatically generating access control policies based on pre-defined templates and regulatory requirements. When a new user or data type is added, the system automatically applies relevant policies without requiring manual configuration, thus maintaining precision while reducing the burden on IT managers.

Inventive Principle:
Principle #10Preliminary action

2Quantity of substance

If the number of storage resources and client computers increases, then data storage capacity and network coverage are improved, but the complexity of managing access control across all resources increases

Engineering Contradiction:
Improvestorage capacityVSAvoidaccess control management complexity
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The system implements universal access control policies that can be applied across multiple storage resources and client computers simultaneously. A single policy definition can govern access to numerous data types, repositories, and locations, allowing the system to scale storage capacity without proportionally increasing management complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system introduces policy templates and automated rule engines as intermediaries between administrators and the growing number of storage resources. These intermediaries automatically interpret and apply access control rules across the expanded infrastructure, reducing the direct management burden on IT staff as the system scales.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If multiple repositories at multiple locations are used for data archiving, then data protection and compliance with retention requirements are improved, but the complexity of tracking and managing access across locations increases

Engineering Contradiction:
Improvedata protectionVSAvoidaccess tracking complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system merges access control management across multiple repository locations into a unified policy framework. Access control decisions are made centrally based on user roles and data classifications, while the actual data may be distributed across multiple locations. This combining approach maintains strong data protection across all locations without requiring separate tracking mechanisms for each site.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11036401B2Method, apparatus, and system for controlling user access to a data storage system
Publication Date: 2021.06.15 HITACHI VANTARA LLC
  • US11036401B2 patent drawing
  • US11036401B2 patent drawing
  • US11036401B2 patent drawing

AI summary

User access to a data storage system including one or more nodes providing a plurality of data storage resources is controlled, the plurality of data storage resources storing one or more user-accessible primary data structures and one or more user-accessible secondary data structures, each secondary data structures being stored on the basis of a respective associated primary data structure, wherein the data storage system stores, for each secondary data structure, data structure metadata which is indicative of a parent data storage resource and an owner data storage resource of the respective secondary data structure. Upon receiving a user request to access a certain secondary data structure of the one or more secondary data structures stored on a respective parent data storage resource, based on data structure metadata stored for the certain secondary data structure, the respective owner data storage resource of the certain secondary data structure is determined.