Unified Access Control for Device Files Across Multiple Routes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

UNIX and LINUX operating systems face vulnerabilities due to inconsistencies in access rules when processes access devices through different routes, leading to potential execution issues and reduced security.

Innovation Solution

An access control system and method that generates device files for each access route, sets and unifies access rules across multiple device files corresponding to a common device, and controls access using a unified access rule to ensure consistent and secure access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple device files are generated for different access routes to a common device, then access flexibility and route-specific control are improved, but access rule inconsistencies and security vulnerabilities occur

Engineering Contradiction:
Improveaccess route flexibilityVSAvoidaccess rule consistency
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent merges access rules from multiple device files into a single unified access rule for each common device. The access control device extracts access rules from multiple device files corresponding to different access routes, derives a unified access rule that combines these rules, and applies it consistently across all device files. This resolves the contradiction by maintaining route-specific device files while ensuring consistent access control through unification.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The unified access rule serves as a universal control mechanism that applies to all device files accessing the same common device, regardless of the access route. This multi-functional approach allows the system to maintain multiple access routes with different device files while applying a single consistent security policy, thereby achieving both flexibility and consistency.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If access rules are set independently for each device file, then route-specific access control is improved, but security vulnerabilities due to rule inconsistencies arise

Engineering Contradiction:
Improveroute-specific access controlVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary unification of access rules before access control is applied. By extracting rules from multiple device files, deriving a unified rule, and applying it to all device files in advance, the system prevents security vulnerabilities that would arise from inconsistent rules. This preliminary action ensures that no security gaps exist when processes access devices through different routes.

Inventive Principle:
Principle #9Preliminary anti-action

3Manufacturing precision

If device files are generated for each access route, then access control precision is improved, but system complexity increases

Engineering Contradiction:
Improveaccess control precisionVSAvoidsystem structure complexity
Core Design Contradiction:
Manufacturing precisionVSDevice complexity

Solution Approach 1:

The patent extracts the access rule management complexity from individual device files and centralizes it in a unified access rule. By separating the access rule derivation and unification functions from the device file structure, the system maintains precise route-specific control through device files while reducing overall system complexity through centralized rule management.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS7330976B2Access control system and method
Publication Date: 2008.02.12 GOOGLE LLC
  • US7330976B2 patent drawing
  • US7330976B2 patent drawing
  • US7330976B2 patent drawing

AI summary

Device files are disposed on respective routes through which a process accesses the same device, and access rules for those device files are unified. Foe example, where there exist two routes by which a certain process accesses a device, two device files are disposed on each of the routes. Access rules that are set for all directories that access the two device files are unified so as to permit only reading so that the device file can be accessed according to the same access rule by the two routes.