Autonomous Storage Device Dynamic Policy Enforcement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing media devices struggle to securely store both user files and protected files efficiently, as current solutions either require a software administrator for permission enforcement or divide the device into static zones, leading to limitations such as confusing memory availability and inability to use the hidden zone for user files or secure data storage.
Innovation Solution
An autonomous data storage device with an external file interface allowing sector-level access, featuring an internal sector policy management unit and a file management system that dynamically enforces access policies, supports standard operating file system calls, and includes encryption for secure file management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the device is divided into two static zones (hidden DRM zone and user zone), then security protection for copyrighted content is improved, but memory management flexibility deteriorates and user confusion arises regarding available memory
Solution Approach 1:
The patent transforms the static zone division into a dynamic system where the boundary between secure and user zones can change. The secure zone is not fixed but dynamically defined by policy rules that can be modified at runtime. The file management system can dynamically allocate sectors between secure and user access based on current needs, allowing the secure zone to expand or contract without physical reconfiguration.
Solution Approach 2:
The patent segments the storage device at the sector level rather than creating fixed zones. Each sector can be independently assigned to different access policies, allowing fine-grained control where individual sectors can be secure or user-accessible. This sector-level segmentation enables flexible composition of secure and user zones without requiring large fixed partitions.
2Ease of operation
If a software permission policy is enforced by the host computer, then multi-user permission control is improved, but security weaknesses increase due to administrator bypass capabilities
Solution Approach 1:
The patent introduces an intermediary file management system embedded in the storage device that acts as a mediator between the host computer and the stored files. This intermediate layer enforces access policies independently of the host's software permission system, creating a security boundary that cannot be bypassed by host administrators. The file management system translates host file operations into controlled device operations, filtering requests according to embedded policies.
Solution Approach 2:
The storage device performs self-service security enforcement through its embedded file management system and policy rules. Rather than relying on external host computer software for permission control, the device autonomously manages its own security policies, access control lists, and permission enforcement. This self-contained approach eliminates the security weaknesses of host-based permission systems.
3Adaptability or versatility
If sector level access is allowed to support standard file system calls, then device compatibility and usability are improved, but unauthorized access risk increases
Solution Approach 1:
The file management system serves as an intermediary layer between sector-level access interfaces and physical data storage. It accepts standard file system calls and sector-level operations from the host but filters and controls actual data access according to embedded policies. This intermediary layer maintains compatibility with standard interfaces while preventing unauthorized access to secure sectors.
Solution Approach 2:
The patent applies different access control qualities to different sectors. User sectors allow full sector-level access for compatibility, while secure sectors enforce restricted access policies. The system maintains local quality control where each sector's access permissions are independently configured, allowing standard file operations in user areas while protecting secure areas from unauthorized access.
4Reliability
If the hidden zone is made inaccessible to users, then security protection is improved, but user awareness and control of stored content deteriorates
Solution Approach 1:
The file management system provides feedback to users about secure content through policy rules and access control lists. Users can query the system to learn which files are protected and under what policies, maintaining awareness without compromising security. The system reports on secure file locations and access restrictions, allowing users to understand what content is protected and why.
Solution Approach 2:
The patent applies different visibility qualities to different files. Secure files maintain their security properties while still being cataloged and describable in the file system. Users can see file names, locations, and policy associations for secure files, providing awareness feedback, but cannot access the actual content without proper authorization. This maintains local quality control where each file's visibility and accessibility are independently managed.
Data Source
AI summary
An autonomous data storage device for storing data files via an external file interface, the external file interface being controllable from an external device, the device comprising: a physical file storage for homogenous storage of files; the external file interface configured to allow sector level access to at least part of the physical file storage to support standard operating file system calls; an internal sector policy management unit located in between the external file interface and the physical file storage for sector level policy enforcement of the physical file storage, for one or more of the sector level managed sectors, the unit having an input for receiving instructions from the external file interface for sector oriented operations, and being configured to carry out sector policy management operations in accordance with.


