Role-Based Storage Configuration Mediator

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data storage systems require users to perform complex configuration tasks, which can lead to improper configurations due to varying customer proficiency levels, and lack flexible security and licensing provisions to manage access and operations effectively.

Innovation Solution

A method and system that determine user proficiency levels to tailor data storage configuration requests, using a role-based security model with access control lists and licensing provisions to manage permitted operations across multiple service providers, ensuring secure and appropriate access and operations based on user roles and interaction levels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If users are allowed to perform data storage configuration tasks directly, then customization and control are improved, but configuration accuracy deteriorates due to varying customer proficiency levels

Engineering Contradiction:
Improveconfiguration customizationVSAvoidconfiguration accuracy
Core Design Contradiction:
Adaptability or versatilityVSManufacturing precision

Solution Approach 1:

The patent introduces service providers as intermediary components between users and the data storage system. These service providers assess user proficiency levels and automatically perform configuration tasks at appropriate abstraction levels, mediating between user requests and system operations to ensure accurate configuration regardless of user expertise

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system dynamically changes the parameter of abstraction level based on assessed user proficiency. Users with lower proficiency are presented with higher-level abstracted interfaces where service providers handle detailed configuration, while more proficient users can access lower-level detailed controls, adapting the interface complexity to match user capability

Inventive Principle:
Principle #35Parameter changes

2Reliability

If multiple user levels with different access rights are implemented, then security is improved, but system complexity increases due to multiple service providers and access control layers

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The service provider component is designed to be universal and multi-functional, handling both security authentication and configuration execution across all user levels. This single multi-functional component manages access control lists, proficiency assessment, and task execution, reducing the need for separate specialized components for each security level

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system implements a nested structure where service providers operate at multiple abstraction levels within a hierarchical framework. Lower-level detailed service providers are nested within higher-level abstracted service providers, allowing the system to manage complexity through nested layers of increasing abstraction while maintaining unified security control

Inventive Principle:
Principle #7Nested doll (Nesting)

3Adaptability or versatility

If service providers make calls to other service providers, then operational flexibility is improved, but operation time increases due to multiple determination steps

Engineering Contradiction:
Improveoperational flexibilityVSAvoidoperation time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

Service providers perform preliminary actions by pre-assessing user proficiency levels and pre-determining the appropriate abstraction level for task execution. Access control lists and service capabilities are pre-configured and cached, allowing subsequent service provider calls to execute more quickly without repeating full authentication and assessment sequences

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8302201B1Security and licensing with application aware storage
Publication Date: 2012.10.30 EMC IP HLDG CO LLC
  • US8302201B1 patent drawing
  • US8302201B1 patent drawing
  • US8302201B1 patent drawing

AI summary

Described are techniques for processing a data storage configuration request for an application. The data storage configuration request is received from a requester. A first user level of a plurality of user levels at which the data storage configuration request is made by the requester is determined. Each user level is associated with a different level of abstraction with respect to processing performed in the data storage system for implementing the data storage configuration request. The data storage configuration request is serviced. Servicing the request includes determining whether to perform the data storage configuration request in accordance with security criteria defining, for each of the plurality of user levels, permitted operations that may be performed for different requesters in connection with the data storage configuration request.