Policy-Aware Unified File System Branch Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing unification file systems do not effectively merge separate file systems while preserving individual security policies, leading to potential security breaches and inconsistent access control.
Innovation Solution
A policy-aware unified file system that creates virtual files and applies branch and unification policies to ensure secure access, maintaining the security requirements of each branch and unification policy, and maps files to their origins within the unified system.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If separate file systems are unified into a single coherent file system, then ease of operation and file management are improved, but security policies and access control consistency deteriorate
Solution Approach 1:
The patent segments the unified file system into multiple branches, where each branch represents a separate file system with its own security policies. The system evaluates access requests against the security policies of each specific branch, ensuring that unification does not compromise individual branch security requirements. This segmentation allows the system to maintain both the convenience of a unified view and the integrity of individual security policies.
2Productivity
If files from separate file systems are merged into a unified file system, then productivity and file accessibility are improved, but security breaches and access control inconsistencies increase
Solution Approach 1:
The patent introduces an intermediary access evaluation mechanism that sits between the unified file system view and the actual file access. When an application requests access to a file, the system evaluates the request against the security policies of the specific branch containing the file, rather than applying a uniform security model. This intermediary layer enables high file accessibility while preventing security breaches by enforcing branch-specific policies.
3Device complexity
If a unified file system is created without policy awareness, then device complexity is reduced, but security and access control reliability deteriorate
Solution Approach 1:
The patent applies local quality by making the unified file system policy-aware at the branch level rather than requiring a completely new complex security architecture. Each branch maintains its own security policies and access control rules, allowing the system to preserve access control reliability without imposing excessive complexity on the overall file system structure. The policy awareness is localized to where it is needed - at the branch interface.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A system and method for operating a policy aware unification file system within a computer system that takes into account the security requirements of each file system as each file system is unified into the unified file system. As the invention is compatible with existing run time policies of files and directories within each file system that is to be unified, the invention supports the enforcement of security policies or requirements of each file and/or directory that has been unified into the unified file system.