Virtual File System Access Manager for Cross-Device Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing enterprise management software is limited in controlling access to files across devices both within and external to the enterprise's network, leading to potential unauthorized access and data security risks when files are copied or transferred to other devices or locations.
Innovation Solution
A virtual local file system managed by an access manager that interacts with the host operating system to control file access permissions, using a file attributes repository to dynamically manage access rights based on user permissions, time, location, and device attributes, ensuring secure access to files across all connected devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If enterprise management software is used to control access to files on network drives, then access control within the enterprise network is improved, but the system cannot manage access to files when they are copied to other devices or locations outside the network
Solution Approach 1:
The patent introduces a file container as an intermediary that wraps the original file and carries embedded access control rules. This container travels with the file wherever it is copied or transferred, enabling the access control system to maintain authority over the file even when it moves outside the enterprise network to personal devices, cloud storage, or other locations.
Solution Approach 2:
The patent applies access control rules and embeds them within the file container before the file is copied or transferred. By pre-configuring the access control metadata and rules in advance, the system ensures that authorization checks are already in place and can be enforced immediately when the file is accessed on any device, without requiring real-time network connection or additional setup.
2Ease of operation
If files are copied to removable storage or external devices for business purposes, then file accessibility and mobility are improved, but the risk of unauthorized access increases when devices are lost or stolen
Solution Approach 1:
The patent applies different access control rules to different portions or aspects of the file based on location and context. The access control metadata within the file container can specify different authorization levels for different devices, locations, or users, allowing the system to maintain high mobility while enforcing appropriate security restrictions at each access point.
Solution Approach 2:
The patent pre-empts potential unauthorized access by embedding access control rules that automatically enforce authorization checks before any file access occurs. The system proactively prevents unauthorized access by verifying credentials and applying rules before the file can be opened or viewed, rather than reacting after a security breach occurs.
3Reliability
If traditional enterprise management software is used, then access control on managed devices is maintained, but access control is lost when files are transferred to unmanaged devices outside the network
Solution Approach 1:
The patent creates a universal file container format that can carry access control rules across different operating systems, devices, and network environments. The file container structure and embedded metadata are designed to be platform-independent, allowing the same access control mechanism to function whether the file is accessed on Windows, macOS, Linux, mobile devices, or cloud storage services.
Data Source
AI summary
A virtual local file system for managing file access, such as read, write and execute, of files on local media is disclosed. An access manager, executable by the host operating system, is stored on each host device. The access manager interacts with the local file system to control file access permissions and how processes of the host operating system execute, view or modify files accessible to the local file system. The access manager may also dynamically control file access to files on the host operating system using a file attributes repository, which may be stored locally or remotely from the host device. Exemplary attributes for defining permission to access a file include but not are limited to, specific users, a time of day, a number of copies of a file, an allowed process, an IP address range, and a MAC address.


