Restricted Resource Classes for Storage Volume Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional operating systems are vulnerable to malware that gains administrative privileges, allowing it to bypass security measures and cause significant damage by modifying security settings, which existing detection, prevention, and mitigation techniques are often ineffective in addressing.

Innovation Solution

Implementing a restricted resource class system that categorizes storage volumes and other system resources, limiting access to only authorized software programs with proper entitlements, using an access control list or metadata to ensure that even malware with high privileges cannot access protected resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional security measures are used, then system operation is maintained, but malware with administrative privileges can bypass security and cause significant damage

Engineering Contradiction:
Improvesystem securityVSAvoidmalware damage
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The invention segments access rights by introducing restricted resource classes that divide system resources into different protection levels. Storage volumes are assigned to specific resource classes (e.g., restricted storage volume class) that limit access based on the application's entitlements, preventing malware from accessing protected resources even with administrative privileges.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The invention applies local quality by assigning different access control characteristics to different storage volumes based on their sensitivity and requirements. Each storage volume can be individually categorized into restricted resource classes with specific access rules, allowing fine-grained control over which applications can access which volumes.

Inventive Principle:
Principle #3Local quality

2Reliability

If access control lists are implemented to limit storage volume access, then malware access is prevented, but system complexity increases

Engineering Contradiction:
Improvestorage volume protectionVSAvoidaccess control system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The restricted resource class framework provides a universal mechanism that can be applied across different storage volumes and resource types. The same access control principles and entitlement verification process work for all protected resources, simplifying the overall system architecture compared to implementing separate access control mechanisms for each resource.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The invention changes the parameter of resource classification by introducing restricted resource classes as a new dimension for organizing system resources. This parameter change allows the system to maintain existing access control mechanisms while adding an additional layer of protection through resource class assignment and entitlement verification.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10032041B2Storage volume protection using restricted resource classes
Publication Date: 2018.07.24 APPLE INC
  • US10032041B2 patent drawing
  • US10032041B2 patent drawing
  • US10032041B2 patent drawing

AI summary

Techniques for restricting access to a storage volume attached to a data processing system are described. In one embodiment, a storage management and access control logic in the data processing system can receive a message indicating the attachment of a storage volume. The logic can apply access restrictions to the storage volume by creating an association between a restricted resource class and the storage volume to limit programmatic access to the storage volume. An evaluation of the storage volume can be requested and based on the result of the evaluation the access restrictions can be removed or retained on the storage volume.