File System Consent-Based Access Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems lack an integrated solution for enforcing privacy legal frameworks in file systems, requiring manual and software-based approaches to manage access, storage, and compliance with regulations like GDPR, HIPPA, and PIPEDA, which is inefficient and prone to errors.

Innovation Solution

A file system infrastructure that enforces a consent-based access policy by associating metadata with files, including owner information, access rights, and purpose-specific access permissions, ensuring compliance with privacy laws through automated processing and encryption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If manual and software-based approaches are used to manage access and compliance with privacy regulations, then flexibility in managing access rights is maintained, but efficiency is reduced and errors are more likely to occur

Engineering Contradiction:
Improveefficiency of access managementVSAvoidcomplexity of access control system
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The file system automatically enforces access policies by checking metadata associated with each file access request. The system self-manages compliance with privacy regulations through automated policy evaluation and enforcement mechanisms embedded in the file system, eliminating the need for manual intervention while maintaining complex policy rules.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Access policies and metadata are pre-configured and associated with files before access requests occur. The file system prepares enforcement rules in advance, storing them as metadata that automatically guide access decisions, thereby improving efficiency without requiring complex real-time processing during access operations.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If automated processing and encryption are implemented to ensure compliance with privacy laws, then data protection is enhanced and manual errors are reduced, but system complexity increases

Engineering Contradiction:
Improvecompliance with privacy regulationsVSAvoidcomplexity of file system infrastructure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple functions including access control, encryption management, and compliance enforcement into a unified file system infrastructure. By merging these previously separate functions into the file system itself, the system achieves high reliability for privacy compliance while avoiding the additional complexity that would result from separate external systems.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The file system is designed to perform multiple functions simultaneously: it manages file access, enforces privacy policies, handles encryption, and ensures regulatory compliance all through a single integrated infrastructure. This multi-functionality improves reliability by ensuring consistent enforcement across all operations without proportionally increasing system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If metadata is associated with files containing owner information, access rights, and purpose-specific permissions, then access control precision is improved, but storage overhead increases

Engineering Contradiction:
Improveprecision of access controlVSAvoidstorage overhead for metadata
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent associates detailed access control metadata only with specific files that require enhanced privacy protection, rather than uniformly applying metadata to all files. This local quality approach allows precise access control where needed while minimizing storage overhead by avoiding unnecessary metadata on files that do not require such controls.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11443056B2File access restrictions enforcement
Publication Date: 2022.09.13 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11443056B2 patent drawing
  • US11443056B2 patent drawing
  • US11443056B2 patent drawing

AI summary

An approach is disclosed that enforces restrictions to data in a filesystem based on metadata for a file including a name for an attribute, a type, and a location in the file for the type. A file specific metadata includes an owner, contact information, access rights including an owner consent-based access policy, users of the system who can access the file and the type of access allowed by the users based on a purpose for the access. The operating system (OS) enforces an access to attribute entries of the file based on the purpose and selected metadata in the associated metadata. The restrictions for file access are driven by the file structure metadata which identifies types of information, where in the file each type of information is located, and consent information which specifies what type of information is accessible to a requestor retrieving data for a specific purpose.