Backup Authentication Agent for Unified File System Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data backup and restore methods face inefficiencies due to separate credentials for network attached storage and file systems, leading to complexity and increased labor for IT personnel in managing access permissions across different administrative and usage domains.

Innovation Solution

Implementing a backup authentication agent that processes backup data based on file system authentication, using encrypted authentication information to determine permission levels and manage access, thereby extending existing network access credentials to network attached storage, allowing unified access and reducing complexity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate credentials are used for network attached storage and file systems, then access control security is maintained, but IT personnel management complexity and labor increase

Engineering Contradiction:
Improveaccess control securityVSAvoidIT personnel management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the authentication systems for network attached storage and file systems by having the backup authentication agent use the same credentials that users employ to access files on the file system. This consolidation eliminates the need for separate credential management while maintaining security boundaries through the agent's mediation role.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The backup authentication agent serves multiple functions: it authenticates users using their existing file system credentials, determines permission levels, and controls backup data access. This multi-functional approach allows a single credential system to serve both file system access and backup operations, reducing management complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If separate credentials are used for network attached storage and file systems, then security domains are maintained, but labor for managing access permissions increases

Engineering Contradiction:
Improvesecurity domain separationVSAvoidlabor for managing access permissions
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system enables self-service authentication where users automatically use their existing file system credentials to access backup data without requiring separate credential provisioning. The backup authentication agent autonomously handles the authentication and permission determination, eliminating manual credential management labor.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The backup authentication agent acts as an intermediary that translates file system authentication into backup data access permissions. It mediates between the user's existing credentials and the backup storage system, maintaining security domain separation while simplifying the user experience and reducing administrative labor.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If backup data is accessed through separate credentials, then security is maintained, but end user access efficiency decreases

Engineering Contradiction:
ImprovesecurityVSAvoidend user access efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

Users can directly access their backup data using their existing file system credentials without requiring IT personnel intervention for credential provisioning. The backup authentication agent automatically processes the authentication and permission checks, enabling efficient self-service access while maintaining security.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9977912B1Processing backup data based on file system authentication
Publication Date: 2018.05.22 EMC IP HLDG CO LLC
  • US9977912B1 patent drawing
  • US9977912B1 patent drawing
  • US9977912B1 patent drawing

AI summary

Processing backup data based on file system authentication is described. A system request authentication information from an application in response to a receipt of a request from the application to process backup data. The system receives encrypted authentication information associated with an authentication system corresponding to a file system. The system requests a permission level from the authentication system based on the encrypted authentication information. The system receives the permission level from the authentication system. The system determines whether the permission level permits the request from the application to process the backup data. The system processes the backup data for the application in response to a determination that the permission level permits the request from the application to process the backup data.