Ledger-Based Security for Shared Files

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cloud file management systems, different security tools and systems accessing shared files may have varying levels of security analysis and updates, leading to inconsistent identification of threats and vulnerabilities, as each tool may recognize only a subset of issues and may not be updated to address the latest vulnerabilities.

Innovation Solution

A method involving a network storage system that generates a ledger for shared files based on scan data from multiple user devices, authenticates scanners, and determines the relative confidence value of the file's security by weighting scan data from different scanners, ensuring that only valid files with updated scanners are granted access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple different security tools and systems are used to analyze shared files, then the coverage of security issues recognized increases, but the consistency and reliability of threat identification decreases due to varying update levels and analysis capabilities

Engineering Contradiction:
Improvesecurity issue coverageVSAvoidthreat identification consistency
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent combines scan results from multiple different security tools and systems into a unified security assessment. The network storage system aggregates vulnerability footprints from various scanners, each with different update levels and capabilities, and merges them to create a comprehensive security evaluation that leverages the diverse coverage while maintaining consistent reliability through systematic combination methods.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates a universal security analysis framework that works across multiple different security tools and systems. The system is designed to handle scan results from various scanners with different capabilities and update levels, providing a unified interface and consistent evaluation methodology that accommodates diverse security analysis approaches while maintaining reliable threat identification.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Measurement precision

If security tools are updated frequently to address latest vulnerabilities, then the detection capability improves, but the complexity of maintaining distributed security systems increases

Engineering Contradiction:
Improvevulnerability detection capabilityVSAvoiddistributed security system maintenance
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent implements self-service mechanisms where the network storage system automatically manages security updates and scanner synchronization. The system autonomously updates vulnerability footprints and scanner configurations, reducing the manual intervention required to maintain distributed security tools. This self-updating capability ensures detection capability improves through frequent updates while minimizing the complexity burden on administrators.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent incorporates feedback loops where scan results and security analysis data are continuously monitored and used to trigger automatic updates. The system receives feedback from scanning operations about emerging threats and automatically adjusts its vulnerability database and scanner configurations, maintaining high detection capability while simplifying maintenance through automated response to security conditions.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3837626B1Distributed security analysis for shared content
Publication Date: 2024.03.20 CITRIX SYSTEMS INC
  • EP3837626B1 patent drawingFigure 1
  • EP3837626B1 patent drawingFigure 2
  • EP3837626B1 patent drawingFigure 3

AI summary

Methods and systems for providing a cost effective and robust security solution for shared files stored by file sharing software solutions are described herein. The methods and systems for generating a ledger associated with shared files, which may include scanning data received from applications associated with a number of client devices and from a cloud based scanner. An access manager may control file permissions granted to users based on requests for scan data from each user device requesting access to a shared file. A plurality of different scanning applications may provide data that is collected for each shared file to provide a diverse analysis of a shared file to increase user confidence in a file security status.