Unified Access Control for Device Files Across Multiple Routes
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
UNIX and LINUX operating systems face vulnerabilities due to inconsistencies in access rules when processes access devices through different routes, leading to potential execution issues and reduced security.
Innovation Solution
An access control system and method that generates device files for each access route, sets and unifies access rules across multiple device files corresponding to a common device, and controls access using a unified access rule to ensure consistent and secure access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple device files are generated for different access routes to a common device, then access flexibility and route-specific control are improved, but access rule inconsistencies and security vulnerabilities occur
Solution Approach 1:
The patent merges access rules from multiple device files into a single unified access rule for each common device. The access control device extracts access rules from multiple device files corresponding to different access routes, derives a unified access rule that combines these rules, and applies it consistently across all device files. This resolves the contradiction by maintaining route-specific device files while ensuring consistent access control through unification.
Solution Approach 2:
The unified access rule serves as a universal control mechanism that applies to all device files accessing the same common device, regardless of the access route. This multi-functional approach allows the system to maintain multiple access routes with different device files while applying a single consistent security policy, thereby achieving both flexibility and consistency.
2Ease of operation
If access rules are set independently for each device file, then route-specific access control is improved, but security vulnerabilities due to rule inconsistencies arise
Solution Approach 1:
The system performs preliminary unification of access rules before access control is applied. By extracting rules from multiple device files, deriving a unified rule, and applying it to all device files in advance, the system prevents security vulnerabilities that would arise from inconsistent rules. This preliminary action ensures that no security gaps exist when processes access devices through different routes.
3Manufacturing precision
If device files are generated for each access route, then access control precision is improved, but system complexity increases
Solution Approach 1:
The patent extracts the access rule management complexity from individual device files and centralizes it in a unified access rule. By separating the access rule derivation and unification functions from the device file structure, the system maintains precise route-specific control through device files while reducing overall system complexity through centralized rule management.
Data Source
AI summary
Device files are disposed on respective routes through which a process accesses the same device, and access rules for those device files are unified. Foe example, where there exist two routes by which a certain process accesses a device, two device files are disposed on each of the routes. Access rules that are set for all directories that access the two device files are unified so as to permit only reading so that the device file can be accessed according to the same access rule by the two routes.


