Root-Level File Configuration via Policy-Based Context Menus
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional computing systems require administrator-level privileges for managing application installation and uninstallation, posing security risks and inefficiencies, especially in managed environments where non-administrator users need access to applications and files.
Innovation Solution
An agent on the computing device applies policies to determine allowable actions for files and folders, providing visual indications through badges and context menus, allowing users to perform actions without elevated privileges, and coordinating with a policy server to manage privileges and update policies across multiple devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If administrator-level privileges are required to manage application installation and uninstallation, then system security is improved, but ease of operation deteriorates as non-administrator users cannot access applications without cumbersome privilege elevation processes
Solution Approach 1:
The patent segments the application management functionality by creating separate privilege levels: standard user actions for routine operations and administrator actions for system-critical operations. The context menu is divided into standard items visible to all users and administrator items that require elevated privileges, allowing non-administrator users to perform common tasks without cumbersome privilege elevation while maintaining security for sensitive operations.
Solution Approach 2:
The patent introduces an intermediary mechanism (the privilege evaluation system and context menu framework) that mediates between user actions and system resources. This intermediary evaluates required privileges, presents appropriate options to users, and handles privilege elevation transparently when necessary, eliminating the need for users to manually manage privilege levels while maintaining security boundaries.
2Ease of operation
If administrator privileges are provided to non-administrator users to access restricted resources, then ease of operation is improved, but system security deteriorates due to security risks
Solution Approach 1:
The patent implements dynamic privilege assignment where the available actions in the context menu change based on the user's current privilege level and the specific resource being accessed. Non-administrator users see only actions appropriate for their privilege level, while administrator actions are either hidden or presented with explicit privilege requirements. This dynamic adaptation allows ease of operation for permitted actions while maintaining security by preventing unauthorized access to restricted functions.
3Adaptability or versatility
If executable actions for files are changed in response to administrative decisions and policies, then adaptability is improved, but device complexity increases as each individual computing device must be updated
Solution Approach 1:
The patent creates a universal policy framework that can be deployed across multiple computing devices simultaneously. Administrative decisions and policy changes are formulated once and can be enforced across the entire organization's device fleet through centralized management. The context menu system and privilege evaluation mechanism work universally across different devices and scenarios, eliminating the need to update each individual device separately while maintaining adaptability to administrative decisions.
4Ease of operation
If a user is provided with administrator credentials to perform privileged actions, then ease of operation is improved, but system security deteriorates due to security risks
Solution Approach 1:
The patent implements a self-service mechanism where the system automatically manages privilege elevation when needed. Instead of providing users with administrator credentials, the system detects when privileged actions are required, transparently elevates privileges through secure authentication mechanisms, and then de-escalates back to standard user privileges. This self-service approach maintains ease of operation for users while preserving security by minimizing the time and scope of elevated privilege exposure.
Data Source
AI summary
Systems and methods for root-level application selective configuration for managing performance of actions on files in a file system including an agent executed on a computing device. The agent can determine a plurality of files stored in a particular folder. The agent can receive a selection of a particular file of the plurality of files. The agent can determine whether to include an action for the particular file in a context menu based on a first policy determination. The agent can render the context menu comprising a plurality of menu entries. The plurality of menu entries can include an additional menu entry that corresponds to the action. The agent can determine whether to perform the action based on a second policy determination. The agent can cause the at least one action to be performed.


