Unified Permission Analytics for Heterogeneous Storage
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cloud-based file storage systems face inefficiencies and costs due to storing large numbers of permissions from multiple disparate systems with differing semantics, complicating data analytics and security management.
Innovation Solution
A centralized system that connects to multiple file storage systems, converts and unifies permissions with distinct semantics into a unified set, allowing for centralized storage and analysis, including mapping, reorganizing, and periodically updating permissions based on user access and threat levels.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If permissions data from multiple disparate storage systems is stored on a remote file storage system, then access control and security management are enabled, but computational efficiency deteriorates and costs increase
Solution Approach 1:
The patent segments permissions data by extracting and isolating permission metadata from the actual file storage systems. Instead of storing all permissions data centrally, the system extracts only the necessary permission information (user, group, permissions) and stores it separately in a centralized analytics system, separating the storage function from the analytics function to improve computational efficiency.
Solution Approach 2:
The patent introduces a centralized analytics system as an intermediary between the remote file storage systems and the permission data. This intermediary extracts, normalizes, and stores permission data in a unified format, acting as a mediator that enables security management without requiring direct storage of all permissions data on the remote systems.
2Ease of operation
If permissions data from multiple storage systems is consolidated on a remote file storage system, then security management is simplified, but data analytics complexity increases
Solution Approach 1:
The patent applies parameter changes by transforming permissions data from multiple storage systems with different permission models into a unified permission representation. The system normalizes permissions into a common schema (user, group, permissions fields) and stores them in a centralized analytics system, changing the data parameters to enable consistent analysis across heterogeneous systems.
Solution Approach 2:
The patent creates a universal permission representation that can handle multiple storage system types (SMB, NFS, CIFS, AFP, WebDAV) through a single unified data model. The centralized analytics system can process permissions from any storage system using the same analysis tools and methods, providing multi-functionality that simplifies data analytics.
3Adaptability or versatility
If multiple storage systems with different permission semantics are supported, then system versatility is improved, but permission processing complexity increases
Solution Approach 1:
The patent creates a simplified copy or representation of permissions data in a centralized analytics system. Instead of processing the original complex permissions data from multiple storage systems directly, the system extracts and creates a normalized copy that captures the essential permission information in a unified format, reducing processing complexity while maintaining versatility.
Solution Approach 2:
The centralized analytics system serves as an intermediary that handles the complexity of different permission semantics. It receives permissions data from various storage systems, normalizes them into a unified representation, and processes them using consistent methods, shielding the rest of the system from the complexity of heterogeneous permission models.
Data Source
AI summary
Systems and methods for simplifying and consolidating permission sets from multiple heterogeneous file storage systems are disclosed. An example method includes acquiring from the first file storage system a first set of file system permissions having a first set of permission semantics, and acquiring from a second file storage system a second set of file system permissions having a second set of permission semantics that are different from the first set of permission semantics. The first set of file system permissions and the second set of file system permissions are converted to a unified set of file system permissions having unified permission semantics that are different from the first set of permission semantics and the second set of permission semantics. The unified set of file system permissions can be analyzed to make a determination regarding security levels of the first file storage system and of the second file storage system.


