Autonomous Storage Device Dynamic Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing media devices struggle to securely store both user files and protected files efficiently, as current solutions either require a software administrator for permission enforcement or divide the device into static zones, leading to limitations such as confusing memory availability and inability to use the hidden zone for user files or secure data storage.

Innovation Solution

An autonomous data storage device with an external file interface allowing sector-level access, featuring an internal sector policy management unit and a file management system that dynamically enforces access policies, supports standard operating file system calls, and includes encryption for secure file management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the device is divided into two static zones (hidden DRM zone and user zone), then security protection for copyrighted content is improved, but memory management flexibility deteriorates and user confusion arises regarding available memory

Engineering Contradiction:
Improvesecurity protectionVSAvoidmemory management flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent transforms the static zone division into a dynamic system where the boundary between secure and user zones can change. The secure zone is not fixed but dynamically defined by policy rules that can be modified at runtime. The file management system can dynamically allocate sectors between secure and user access based on current needs, allowing the secure zone to expand or contract without physical reconfiguration.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent segments the storage device at the sector level rather than creating fixed zones. Each sector can be independently assigned to different access policies, allowing fine-grained control where individual sectors can be secure or user-accessible. This sector-level segmentation enables flexible composition of secure and user zones without requiring large fixed partitions.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If a software permission policy is enforced by the host computer, then multi-user permission control is improved, but security weaknesses increase due to administrator bypass capabilities

Engineering Contradiction:
Improvepermission controlVSAvoidsecurity strength
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an intermediary file management system embedded in the storage device that acts as a mediator between the host computer and the stored files. This intermediate layer enforces access policies independently of the host's software permission system, creating a security boundary that cannot be bypassed by host administrators. The file management system translates host file operations into controlled device operations, filtering requests according to embedded policies.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The storage device performs self-service security enforcement through its embedded file management system and policy rules. Rather than relying on external host computer software for permission control, the device autonomously manages its own security policies, access control lists, and permission enforcement. This self-contained approach eliminates the security weaknesses of host-based permission systems.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If sector level access is allowed to support standard file system calls, then device compatibility and usability are improved, but unauthorized access risk increases

Engineering Contradiction:
Improvedevice compatibilityVSAvoidunauthorized access risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The file management system serves as an intermediary layer between sector-level access interfaces and physical data storage. It accepts standard file system calls and sector-level operations from the host but filters and controls actual data access according to embedded policies. This intermediary layer maintains compatibility with standard interfaces while preventing unauthorized access to secure sectors.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent applies different access control qualities to different sectors. User sectors allow full sector-level access for compatibility, while secure sectors enforce restricted access policies. The system maintains local quality control where each sector's access permissions are independently configured, allowing standard file operations in user areas while protecting secure areas from unauthorized access.

Inventive Principle:
Principle #3Local quality

4Reliability

If the hidden zone is made inaccessible to users, then security protection is improved, but user awareness and control of stored content deteriorates

Engineering Contradiction:
Improvesecurity protectionVSAvoiduser awareness of content
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The file management system provides feedback to users about secure content through policy rules and access control lists. Users can query the system to learn which files are protected and under what policies, maintaining awareness without compromising security. The system reports on secure file locations and access restrictions, allowing users to understand what content is protected and why.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent applies different visibility qualities to different files. Secure files maintain their security properties while still being cataloged and describable in the file system. Users can see file names, locations, and policy associations for secure files, providing awareness feedback, but cannot access the actual content without proper authorization. This maintains local quality control where each file's visibility and accessibility are independently managed.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS8302178B2System and method for a dynamic policies enforced file system for a data storage device
Publication Date: 2012.10.30 NYTELL SOFTWARE LLC
  • US8302178B2 patent drawing
  • US8302178B2 patent drawing
  • US8302178B2 patent drawing

AI summary

An autonomous data storage device for storing data files via an external file interface, the external file interface being controllable from an external device, the device comprising: a physical file storage for homogenous storage of files; the external file interface configured to allow sector level access to at least part of the physical file storage to support standard operating file system calls; an internal sector policy management unit located in between the external file interface and the physical file storage for sector level policy enforcement of the physical file storage, for one or more of the sector level managed sectors, the unit having an input for receiving instructions from the external file interface for sector oriented operations, and being configured to carry out sector policy management operations in accordance with.