Data Storage Access Control via Metadata-Driven Role Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current data storage systems face challenges in efficiently managing user access and access control across multiple storage resources, particularly in large networks with varying data protection requirements, leading to complex and impractical manual configuration processes for IT managers.
Innovation Solution
A method and system for controlling user access in a data storage system that utilizes role-based access control (RBAC) by storing access control information for user accounts and roles, determining access permissions based on data structure metadata, and managing access through a user interface controller and resource handling controllers to ensure secure and efficient access to primary and secondary data structures.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Manufacturing precision
If manual configuration of access control policies is implemented at a granular level for each data type, regulation, and repository location, then access control precision and compliance are improved, but the complexity of configuration and ease of operation deteriorate
Solution Approach 1:
The system segments access control configuration into hierarchical levels: organization-wide policies, department-level policies, and user-specific assignments. This segmentation allows precise control at each level without requiring manual configuration of every individual data-access combination, thereby maintaining access control precision while reducing configuration complexity.
Solution Approach 2:
The system performs preliminary action by automatically generating access control policies based on pre-defined templates and regulatory requirements. When a new user or data type is added, the system automatically applies relevant policies without requiring manual configuration, thus maintaining precision while reducing the burden on IT managers.
2Quantity of substance
If the number of storage resources and client computers increases, then data storage capacity and network coverage are improved, but the complexity of managing access control across all resources increases
Solution Approach 1:
The system implements universal access control policies that can be applied across multiple storage resources and client computers simultaneously. A single policy definition can govern access to numerous data types, repositories, and locations, allowing the system to scale storage capacity without proportionally increasing management complexity.
Solution Approach 2:
The system introduces policy templates and automated rule engines as intermediaries between administrators and the growing number of storage resources. These intermediaries automatically interpret and apply access control rules across the expanded infrastructure, reducing the direct management burden on IT staff as the system scales.
3Reliability
If multiple repositories at multiple locations are used for data archiving, then data protection and compliance with retention requirements are improved, but the complexity of tracking and managing access across locations increases
Solution Approach 1:
The system merges access control management across multiple repository locations into a unified policy framework. Access control decisions are made centrally based on user roles and data classifications, while the actual data may be distributed across multiple locations. This combining approach maintains strong data protection across all locations without requiring separate tracking mechanisms for each site.
Data Source
AI summary
User access to a data storage system including one or more nodes providing a plurality of data storage resources is controlled, the plurality of data storage resources storing one or more user-accessible primary data structures and one or more user-accessible secondary data structures, each secondary data structures being stored on the basis of a respective associated primary data structure, wherein the data storage system stores, for each secondary data structure, data structure metadata which is indicative of a parent data storage resource and an owner data storage resource of the respective secondary data structure. Upon receiving a user request to access a certain secondary data structure of the one or more secondary data structures stored on a respective parent data storage resource, based on data structure metadata stored for the certain secondary data structure, the respective owner data storage resource of the certain secondary data structure is determined.


