Restricted Resource Classes for Storage Volume Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional operating systems are vulnerable to malware that gains administrative privileges, allowing it to bypass security measures and cause significant damage by modifying security settings, which existing detection, prevention, and mitigation techniques are often ineffective in addressing.
Innovation Solution
Implementing a restricted resource class system that categorizes storage volumes and other system resources, limiting access to only authorized software programs with proper entitlements, using an access control list or metadata to ensure that even malware with high privileges cannot access protected resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional security measures are used, then system operation is maintained, but malware with administrative privileges can bypass security and cause significant damage
Solution Approach 1:
The invention segments access rights by introducing restricted resource classes that divide system resources into different protection levels. Storage volumes are assigned to specific resource classes (e.g., restricted storage volume class) that limit access based on the application's entitlements, preventing malware from accessing protected resources even with administrative privileges.
Solution Approach 2:
The invention applies local quality by assigning different access control characteristics to different storage volumes based on their sensitivity and requirements. Each storage volume can be individually categorized into restricted resource classes with specific access rules, allowing fine-grained control over which applications can access which volumes.
2Reliability
If access control lists are implemented to limit storage volume access, then malware access is prevented, but system complexity increases
Solution Approach 1:
The restricted resource class framework provides a universal mechanism that can be applied across different storage volumes and resource types. The same access control principles and entitlement verification process work for all protected resources, simplifying the overall system architecture compared to implementing separate access control mechanisms for each resource.
Solution Approach 2:
The invention changes the parameter of resource classification by introducing restricted resource classes as a new dimension for organizing system resources. This parameter change allows the system to maintain existing access control mechanisms while adding an additional layer of protection through resource class assignment and entitlement verification.
Data Source
AI summary
Techniques for restricting access to a storage volume attached to a data processing system are described. In one embodiment, a storage management and access control logic in the data processing system can receive a message indicating the attachment of a storage volume. The logic can apply access restrictions to the storage volume by creating an association between a restricted resource class and the storage volume to limit programmatic access to the storage volume. An evaluation of the storage volume can be requested and based on the result of the evaluation the access restrictions can be removed or retained on the storage volume.


