Secure File Browser with Isolated Access for Third-Party Apps

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional file selection methods fail to provide adequate security measures, allowing third-party applications to potentially access sensitive data unrelated to their intended use, while also limiting the ability to utilize the full features of the application when accessing specific files.

Innovation Solution

A method that enables a software application to perform operations on a file within a secure file browser by using a file provider daemon to establish a sandboxed environment, allowing authorized access and direct communication between the application and file access services, while maintaining data integrity and security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If conventional file selection methods are used to allow third-party applications to access files, then the application can perform operations on selected files, but the application may also access sensitive data unrelated to its intended use

Engineering Contradiction:
Improvefile access capabilityVSAvoiddata security risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the file system into multiple isolated file systems, each accessible only to specific applications. This segmentation prevents third-party applications from accessing sensitive data in other file systems while still allowing them to perform operations on files within their designated file system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a file system manager as an intermediary component that controls and mediates access between third-party applications and the file system. The file system manager enforces security policies, validates access requests, and prevents applications from accessing unauthorized data while facilitating legitimate file operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If all files on the file system are exposed to a third-party application during file selection, then the application can select any file for operation, but the application gains potential access to sensitive data completely unrelated to the application

Engineering Contradiction:
Improvefile selection flexibilityVSAvoiddata protection integrity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent divides the file system into multiple isolated file systems with restricted access permissions. Each third-party application is assigned to a specific file system it can access, maintaining ease of file selection within that scope while preventing access to sensitive data in other file systems through security policies.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different access permissions and security characteristics to different file systems. Each file system has localized security properties that determine which applications can access it, allowing flexible file selection within permitted boundaries while protecting sensitive areas through differentiated access control.

Inventive Principle:
Principle #3Local quality

3Object-affected harmful factors

If security measures are imposed on third-party applications to prevent access to sensitive data, then data security is improved, but the ability to make full use of application features when accessing files is limited

Engineering Contradiction:
Improveunauthorized data accessVSAvoidapplication feature utilization
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The patent segments the file system into multiple isolated file systems, each with specific access permissions. This segmentation enables third-party applications to fully utilize features relevant to their designated file system while security measures prevent access to sensitive data in other file systems, thus maintaining both security and functionality.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The file system manager acts as an intermediary that enables applications to use full features within their authorized scope while enforcing security boundaries. It facilitates legitimate file operations and application functionality while preventing unauthorized access to sensitive data through policy enforcement.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10902137B2Techniques for enabling a software application to perform an operation on a file stored on a file system while enforcing privacy measures
Publication Date: 2021.01.26 APPLE INC
  • US10902137B2 patent drawing
  • US10902137B2 patent drawing
  • US10902137B2 patent drawing

AI summary

This application relates to a technique that enables a software application to perform an operation on a file stored on a file system, while enforcing privacy measures. The technique includes receiving, from a file browser, a selection of file made accessible by a file access service. The file access service is associated with the file system storing the file. The file browser executes in a mode that prevents the software application from identifying content displayed within the file browser. The technique also includes, provided the software application is authorized to access the file, communicating a first list of operations for receipt by the software application, in which the software application selects a first subset of operations, to perform on the file. Furthermore, the technique includes establishing, to perform the first subset of operations on the file, a first direct communication link between the software application and the file access service.