Unified Permission Analytics for Heterogeneous Storage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud-based file storage systems face inefficiencies and costs due to storing large numbers of permissions from multiple disparate systems with differing semantics, complicating data analytics and security management.

Innovation Solution

A centralized system that connects to multiple file storage systems, converts and unifies permissions with distinct semantics into a unified set, allowing for centralized storage and analysis, including mapping, reorganizing, and periodically updating permissions based on user access and threat levels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If permissions data from multiple disparate storage systems is stored on a remote file storage system, then access control and security management are enabled, but computational efficiency deteriorates and costs increase

Engineering Contradiction:
Improveaccess controlVSAvoidcomputational efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments permissions data by extracting and isolating permission metadata from the actual file storage systems. Instead of storing all permissions data centrally, the system extracts only the necessary permission information (user, group, permissions) and stores it separately in a centralized analytics system, separating the storage function from the analytics function to improve computational efficiency.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a centralized analytics system as an intermediary between the remote file storage systems and the permission data. This intermediary extracts, normalizes, and stores permission data in a unified format, acting as a mediator that enables security management without requiring direct storage of all permissions data on the remote systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If permissions data from multiple storage systems is consolidated on a remote file storage system, then security management is simplified, but data analytics complexity increases

Engineering Contradiction:
Improvesecurity managementVSAvoiddata analytics complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent applies parameter changes by transforming permissions data from multiple storage systems with different permission models into a unified permission representation. The system normalizes permissions into a common schema (user, group, permissions fields) and stores them in a centralized analytics system, changing the data parameters to enable consistent analysis across heterogeneous systems.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent creates a universal permission representation that can handle multiple storage system types (SMB, NFS, CIFS, AFP, WebDAV) through a single unified data model. The centralized analytics system can process permissions from any storage system using the same analysis tools and methods, providing multi-functionality that simplifies data analytics.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If multiple storage systems with different permission semantics are supported, then system versatility is improved, but permission processing complexity increases

Engineering Contradiction:
Improvestorage system compatibilityVSAvoidpermission processing complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent creates a simplified copy or representation of permissions data in a centralized analytics system. Instead of processing the original complex permissions data from multiple storage systems directly, the system extracts and creates a normalized copy that captures the essential permission information in a unified format, reducing processing complexity while maintaining versatility.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The centralized analytics system serves as an intermediary that handles the complexity of different permission semantics. It receives permissions data from various storage systems, normalizes them into a unified representation, and processes them using consistent methods, shielding the rest of the system from the complexity of heterogeneous permission models.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12039066B1Storage agnostic large scale permissions and access analytics
Publication Date: 2024.07.16 EGNYTE
  • US12039066B1 patent drawing
  • US12039066B1 patent drawing
  • US12039066B1 patent drawing

AI summary

Systems and methods for simplifying and consolidating permission sets from multiple heterogeneous file storage systems are disclosed. An example method includes acquiring from the first file storage system a first set of file system permissions having a first set of permission semantics, and acquiring from a second file storage system a second set of file system permissions having a second set of permission semantics that are different from the first set of permission semantics. The first set of file system permissions and the second set of file system permissions are converted to a unified set of file system permissions having unified permission semantics that are different from the first set of permission semantics and the second set of permission semantics. The unified set of file system permissions can be analyzed to make a determination regarding security levels of the first file storage system and of the second file storage system.