Access Model for NTFS Permission Correction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current file system permission management in network environments is decentralized and manual, leading to inefficiencies, errors, and security risks due to the lack of centralized management, making it time-consuming and arduous to grant, revoke, or modify access rights across multiple shared folders without disrupting existing access.

Innovation Solution

A method and system for generating an access model that simulates transformation of existing NTFS permissions, creating permission groups, and updating permissions in a centralized manner, allowing for automated and self-service access changes while ensuring seamless transitions and improved security by removing inactive users and high-risk trustees.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If permissions are applied directly to folders and files on file servers with no centralized management, then each shared folder can have its own security applied independently, but this results in a highly distributed set of shared folders with manual management that is time-consuming and error-prone

Engineering Contradiction:
ImproveIndependent security configurationVSAvoidTime to grant, revoke, or modify access rights
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent introduces an access model as an intermediary layer between users and shared folders. This access model contains permission templates that define access rights, which are then applied to shared folders through the model rather than configuring each folder individually. The access model acts as a mediator that simplifies permission management while maintaining the ability to apply security independently to different folders.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The access model serves multiple functions: it stores permission templates, manages user access rights, and applies permissions across multiple shared folders. By creating a universal access model that can be applied to various folders, the system reduces manual management time while preserving the ability to configure security independently for each folder type or purpose.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If permissions are manually managed across multiple shared folders, then each folder can be secured individually, but this decentralized approach leads to inefficiencies and errors due to the lack of centralized management

Engineering Contradiction:
ImproveSecurity configuration accuracyVSAvoidPermission management efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The access model serves as a centralized intermediary that manages permissions across multiple shared folders. By storing permission templates in the access model and applying them systematically, the system improves reliability through centralized control while maintaining the ability to configure security accurately for each folder. The intermediary layer ensures consistent and error-free permission application.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If access rights are modified across multiple shared folders, then security can be updated, but this process is arduous and time-consuming without automated management

Engineering Contradiction:
ImproveSecurity update consistencyVSAvoidPermission modification complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The access model provides a universal mechanism for managing permissions across multiple shared folders. When security updates are needed, the access model can be modified once and the changes automatically applied to all relevant folders, ensuring consistency while dramatically reducing the complexity and time required for permission modifications.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The access model allows permission templates to be predefined and prepared in advance. Before applying permissions to shared folders, the desired access rights are configured in the access model, making the actual permission application process simple and automated. This preliminary configuration reduces the complexity of modifying access rights across multiple folders.

Inventive Principle:
Principle #10Preliminary action

4Extent of automation

If a centralized access model is implemented to manage permissions, then automated and self-service access changes can be enabled, but this requires transformation of existing NTFS permissions which must be done without breaking existing access

Engineering Contradiction:
ImproveAutomated permission managementVSAvoidPermission transformation complexity
Core Design Contradiction:
Extent of automationVSDevice complexity

Solution Approach 1:

The access model serves as an intermediary layer between the existing NTFS permission system and the desired automated management system. By introducing this intermediate access model, the patent enables automated permission management while systematically transforming existing NTFS permissions without disrupting current access. The intermediary handles the complexity of transformation, allowing automation to be implemented gradually.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The access model allows permission templates to be predefined and prepared in advance. Before applying permissions to shared folders, the desired access rights are configured in the access model, making the actual permission application process simple and automated. This preliminary configuration reduces the complexity of modifying access rights across multiple folders.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11063951B1Systems and methods for correcting file system permissions
Publication Date: 2021.07.13 STEALTHBITS TECHNOLOGIES LLC
  • US11063951B1 patent drawing
  • US11063951B1 patent drawing
  • US11063951B1 patent drawing

AI summary

A method is described. The method includes generating an access model that simulates a transformation of existing new technology file system (NTFS) permissions for a plurality of shared folders. The method also includes creating permission groups for the plurality of shared folders based on the access model. The method further includes updating the NTFS permissions of the shared folders based on the access model and permission groups.