Logical Block Analysis Engine for File System Volume Classification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data protection systems face performance issues due to the complexity of data analysis, which impacts user experience and efficiency, as they typically analyze data at the file level, requiring significant compute time and effort, and re-analysis is necessary upon changes in classification rules or file contents.

Innovation Solution

The system performs analysis at the file system logical block level, allowing for discrete sub-analyses and incremental classification, decoupling analysis from user interface experience, and enabling analysis at arbitrary times, with minimal performance impact, using a Logical Block Analysis Engine (LBA) that processes logical blocks in queues with prioritization and iterative analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data analysis is performed at the file level with comprehensive classification, then data protection effectiveness is improved, but system performance and user experience deteriorate due to significant compute time requirements

Engineering Contradiction:
Improvedata protection effectivenessVSAvoidsystem performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the file system into logical blocks as the fundamental unit of analysis, rather than analyzing entire files. This segmentation allows the system to analyze smaller, discrete units independently, reducing the compute time required for each analysis operation while maintaining comprehensive data protection coverage across the entire file system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary classification of logical blocks and caches the classification results. When data protection operations are needed, the system can retrieve pre-computed classification information from the cache, avoiding the need to perform comprehensive re-analysis and thus maintaining both effectiveness and performance.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If comprehensive data classification analysis is performed, then classification accuracy is improved, but analysis time and compute resources worsen

Engineering Contradiction:
Improveclassification accuracyVSAvoidanalysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

By segmenting files into logical blocks and analyzing blocks independently, the system can achieve comprehensive classification accuracy across the entire file system without requiring sequential analysis of entire files. This parallelizable approach significantly reduces total analysis time while maintaining precision.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs classification on logical blocks rather than waiting for complete file analysis. This partial action approach allows data protection decisions to be made based on block-level classification, reducing analysis time while the classification accuracy remains sufficient for protection purposes.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If file-level data analysis is performed to ensure data protection, then protection coverage is improved, but user experience and operational speed deteriorate

Engineering Contradiction:
Improveprotection coverageVSAvoidoperational speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent implements segmentation at the logical block level, allowing the system to provide comprehensive protection coverage across the entire file system while operating on small, independent units. This enables parallel processing and caching strategies that dramatically improve operational speed without sacrificing coverage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system creates and maintains a cached copy of logical block classification information. This cached copy allows rapid data protection operations by retrieving pre-analyzed classification data, thereby improving operational speed while the underlying comprehensive analysis ensures full protection coverage.

Inventive Principle:
Principle #26Copying

4Adaptability or versatility

If incremental classification with multiple passes is implemented, then adaptability to rule changes is improved, but system complexity worsens

Engineering Contradiction:
Improveadaptability to classification rule changesVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system's segmentation into logical blocks with individual classification states enables incremental updates. When classification rules change, only the affected logical blocks need to be re-analyzed rather than the entire file system, improving adaptability while the modular block structure keeps the implementation complexity manageable.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements dynamic, multi-pass classification where logical blocks can be re-analyzed incrementally based on rule changes or data modifications. This dynamic approach allows the system to adapt to changing classification requirements efficiently, and the incremental nature of updates prevents the system from becoming overly complex.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12045202B2Logical blocks analysis in an electronic file system volume
Publication Date: 2024.07.23 CROWDSTRIKE
  • US12045202B2 patent drawing
  • US12045202B2 patent drawing
  • US12045202B2 patent drawing

AI summary

One or more identifiers respectively corresponding to a one or more logical blocks in an electronic file system volume is selected. One or more logical blocks respectively corresponding to the selected one or more identifiers is analyzed according to one or more criteria. A value is assigned to one or more indicators associated with each of the one or more logical blocks and corresponding to the one or more criteria, in response to the analyses of the corresponding one or more logical blocks. A representation of the one or more indicators, and their respective assigned values, associated with each of the one or more logical blocks that was analyzed according to the one or more criteria, is generated. In some embodiments, an action to be performed on or with an electronic file mapped to the logical blocks is controlled based on one or more of the values assigned to the one or more indicators associated with the one or more logical blocks.