Unified Permission Semantics for Heterogeneous File Storage Analytics

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud-based file storage systems face inefficiencies and costs due to storing large numbers of permissions from multiple storage systems with differing semantics, complicating data analytics.

Innovation Solution

A system and method for consolidating and simplifying permissions across multiple heterogeneous file storage systems by converting and unifying permissions semantics, performing data analytics on unified permissions, and analyzing user access and behavior.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If permissions data from multiple heterogeneous storage systems is stored in a centralized system, then cross-system data analytics capability is improved, but storage computational cost and complexity increase

Engineering Contradiction:
Improvecross-system data analytics capabilityVSAvoidstorage computational cost and complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent transforms permissions data from multiple heterogeneous storage systems into a unified permission representation with standardized parameters. Each storage system's permissions are converted to a common format using mapping tables that translate system-specific permission fields into unified fields (e.g., converting Windows ACLs, Unix permissions, and S3 policies into a common permission structure), thereby reducing computational complexity while enabling cross-system analytics

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces a permissions service as an intermediary layer between multiple heterogeneous storage systems and the centralized analytics system. This service collects permissions data from various storage systems, normalizes them into a unified representation, and stores them in a centralized database. The intermediary handles the complexity of different permission formats, allowing the centralized system to perform analytics without directly managing the complexity of multiple storage systems

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If large numbers of permissions from multiple storage systems are stored, then comprehensive access control is improved, but data analytics complexity increases

Engineering Contradiction:
Improveaccess controlVSAvoiddata analytics complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent simplifies complex permissions data by transforming it into a standardized unified permission representation. The system identifies and extracts only the essential permission attributes (read, write, execute, delete rights) and stores them in a normalized format, reducing the dimensionality of the data while preserving access control information needed for comprehensive security monitoring

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent extracts only the critical permission information from the full permissions data of multiple storage systems. Instead of storing all permission metadata, the system extracts and stores only the essential access control attributes in the unified representation, reducing data volume and analytics complexity while maintaining sufficient information for security monitoring and analysis

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS12462055B2Storage agnostic large scale permissions and access analytics
Publication Date: 2025.11.04 EGNYTE
  • US12462055B2 patent drawing
  • US12462055B2 patent drawing
  • US12462055B2 patent drawing

AI summary

Systems and methods for simplifying and consolidating permission sets from multiple heterogeneous file storage systems are disclosed. An example method includes acquiring from the first file storage system a first set of file system permissions having a first set of permission semantics, and acquiring from a second file storage system a second set of file system permissions having a second set of permission semantics that are different from the first set of permission semantics. The first set of file system permissions and the second set of file system permissions are converted to a unified set of file system permissions having unified permission semantics that are different from the first set of permission semantics and the second set of permission semantics. The unified set of file system permissions can be analyzed to make a determination regarding security levels of the first file storage system and of the second file storage system.