Object Addressable Storage Security Content Units
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing storage systems, particularly block I/O systems, face challenges in managing access to content units as location changes require updates in access requests, whereas object addressable storage systems lack efficient mechanisms for user authentication and access control, especially in large-scale systems like My World information brokerage concepts.
Innovation Solution
Implementing a method within object addressable storage systems to store security information in security content units, associate them with object identifiers, and use these identifiers for access control, allowing users to grant access privileges to other users and manage content units within virtual pools, thereby enhancing authentication and access management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If object addressable storage systems use object identifiers for content access, then location independence and flexibility are improved, but authentication and access control mechanisms become insufficient
Solution Approach 1:
The patent introduces security content units as intermediary objects that store authentication information and access control data. These security content units act as mediators between users and the actual content units, enabling robust authentication and access control mechanisms while preserving the location independence benefits of object identifiers. The security content units contain user credentials, permissions, and access policies that are retrieved and processed independently of content storage locations.
Solution Approach 2:
The patent segments the storage system into distinct functional components: content units for storing actual data and security content units for storing authentication and access control information. This segmentation allows the system to maintain location independence for content while implementing comprehensive security mechanisms in dedicated security objects, resolving the contradiction between flexibility and authentication reliability.
2Reliability
If block I/O storage systems use logical volume and block addresses for data access, then access control mechanisms are well-established, but location changes require updates in access requests
Solution Approach 1:
The patent adopts the access control methodology from block I/O systems and applies it to object addressable storage by copying the security management concepts into the object model. Security content units replicate the access control functionality of block I/O systems, using similar permission structures and authentication mechanisms, but adapted to work with object identifiers instead of block addresses. This allows proven access control methods to be used without requiring complex location tracking.
3Reliability
If object addressable storage systems store security information externally, then authentication capability is improved, but system complexity and access overhead increase
Solution Approach 1:
The patent merges security information storage with the existing object addressable storage architecture by storing security content units in the same storage system as regular content units. Both content units and security content units use the same object identifier-based access mechanism, eliminating the need for separate external authentication systems. This integration reduces system complexity while maintaining strong authentication capabilities, as the storage system itself handles both content and security information uniformly.
Data Source
AI summary
Aspects of the invention relate to sharing content stored on an object addressable storage (OAS) system among a plurality of users of the OAS system and authenticating users to an OAS system. In some embodiments, a user may store content units on the OAS system and control access by other users to these content units. In some embodiments, when a user grants one or more other users access to a content unit stored on the OAS system, the OAS system may send a notification of grant of access to the other user(s).


